Back to skill

Security audit

Eo Ability Rag

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent RAG knowledge-sharing helper, but it automatically creates persistent cross-project knowledge indexes without enough user control or privacy boundaries.

Review this before installing in any workspace that may contain confidential, customer, personal, regulated, or secret data. Use it only if automatic indexing and cross-project knowledge sharing are acceptable, or add controls for opt-in indexing, project isolation, exclusions, retention, and deletion.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly promotes automatic indexing of expert experience, best practices, and cross-project knowledge sharing, but it does not warn users that project content may include confidential, regulated, or customer data. In a RAG system, silent ingestion across project boundaries can cause unintended data disclosure, scope creep, and reuse of sensitive information in unrelated contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The usage section states that indexing is 'automatically triggered by EO' without telling users that their content may be ingested into a searchable knowledge base. That creates a real risk of users exposing internal documents or project artifacts without informed consent, especially because automation reduces the chance that operators notice or review what is being indexed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document advertises cross-session persistence, vector indexing, and semantic search but omits any retention, confidentiality, or access-control warning. Persistent storage materially increases the blast radius of accidental ingestion because sensitive data can remain searchable over time and be surfaced to future sessions or other projects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.