Back to skill

Security audit

Publish 3d Flag

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Aavegotchi renderer, but direct render requests can delete or overwrite arbitrary writable files, so it should be reviewed before installation.

Install only in an isolated, low-privilege workspace and avoid feeding untrusted request JSON directly to the hosted or Unity runners. Prefer the main wrapper until output paths are generated internally or restricted to a dedicated render directory, and pin the Unity SDK dependency to a reviewed immutable revision.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run-unity-render.sh:22
Finding

Arbitrary File Deletion and Overwrite Through Unvalidated Output Paths

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
unity/GotchiCustomRenderer/Packages/manifest.json:5
Finding

Unity SDK Dependency Tracks a Mutable Remote Branch

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill renders custom Aavegotchi 3D images from arbitrary trait and wearable combinations for user outfit/appearance preview requests. The supplied code does not do any rendering, image generation, or preview creation. Instead, it reads JSON from a file or stdin, applies default values, requires specific fields (collateral, eye_shape, eye_color), validates integer fields for haunt_id, skin_id, and wearable slots, rejects unknown wearable slots, and prints a normalized JSON payload. This is a config validator/normalizer, which is materially different from the declared primary purpose of rendering custom 3D images.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
- main wrapper: `scripts/render-custom-gotchi.sh`

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises execution paths that read local files and access hosted resources, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, missing scope metadata can cause over-broad tool access, make policy enforcement ambiguous, and increase the risk of unintended file exposure or network use if the skill is routed automatically.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The default prompt strongly instructs the agent to invoke this skill whenever a user describes a custom Aavegotchi look in plain language, with broad examples and little gating. That can cause over-triggering on ambiguous descriptive requests, leading the agent to route users into this skill when another tool or a clarification step would be more appropriate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script deletes a path taken from untrusted input via MANIFEST_JSON="$(jq -r '.output.manifest_json' "$INPUT_JSON")" and then rm -f "$MANIFEST_JSON" ... without validating that the path is within an expected output directory. An attacker who can influence the input JSON can cause deletion of arbitrary files accessible to the current user, and the skill context makes this more dangerous because the renderer is explicitly designed to consume arbitrary user-supplied request files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code creates parent directories and writes PNG and manifest files to paths taken directly from untrusted JSON input, with no restriction to a safe output directory. In a CLI/editor context, an attacker who can control the request file can overwrite arbitrary files writable by the current user or CI agent, which is especially risky because this skill accepts synthetic requests rather than fixed on-chain assets.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency uses a caret range (^7.0.0), which allows automatic installation of newer compatible releases rather than a single fixed version. This increases supply-chain risk because builds are not fully reproducible and a compromised or faulty upstream release could be pulled in without an explicit review. In this skill, the risk is somewhat limited because the file only declares a common image-processing library and does not itself contain suspicious install hooks or scripts.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"description": "Custom Aavegotchi 3D renderer with hosted official-style output and Unity fallback.",
  "type": "module",
  "dependencies": {
    "pngjs": "^7.0.0"
  }
}

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file documents that the skill writes PNG and JSON artifacts to a local temporary directory, which affects the user's filesystem. Under the markdown-specific warning criterion, the description should disclose this behavior more explicitly as a user-impacting side effect rather than only mentioning it as an implementation detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This script writes image output to the user-specified path, which can overwrite or create files, but the code provides no confirmation prompt, warning message, or explanatory comment about this side effect. For a code file, file-writing behavior is safety-relevant and should include some disclosure unless the warning is provided elsewhere.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The command accepts --input and reads the referenced JSON file directly from disk, which is a filesystem access operation driven by external input. The existing trace log is not a meaningful user disclosure, and there is no comment or documentation in this file warning that the skill consumes local file contents from the provided path.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

During rendering, the skill scans project assets and reads material files from disk, including direct File.ReadAllLines on asset paths to hydrate fallback materials. These filesystem reads are not surfaced to the user through a visible warning, confirmation, or explanatory documentation in the file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.