Back to skill

Security audit

Positioning Mapper

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate positioning tool, but its manifest understates that it may use web connectors and persistent memory writes.

Review this skill as needing network and scoped write permissions, not as a purely inline/read-only helper. Install only if you are comfortable with competitor queries going through the host's Firecrawl/Tavily connectors and with approved positioning, claim, and launch-stage data being stored in the named memory locations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
distribution-manifest.json:2
Finding

Skill behavior exceeds the capabilities declared in the distribution manifest

Content
View full analysis

Vulnerability Details

File Location: distribution-manifest.json:2-6; SKILL.md:40-41, 52, 58-60, 69
Vulnerability Type: Capability-boundary mismatch permitting undeclared network access and persistent writes
Risk Level: Medium

Vulnerable Code Snippets

distribution-manifest.json:2-6 declares only inline delivery and canonical-state reading:

json
"capabilities": [
  "inline-delivery",
  "canonical-state-read"
],
"capability_ceiling": "lite",

However, SKILL.md:40-41 instructs the agent to use network connectors and write persistent records:

markdown
- **Reads**: product facts and capability list (User-provided); win-loss reasons and user-interview notes (User-provided); [competitor-analysis](../../../seo-geo/survey/competitor-analysis/SKILL.md) findings from `memory/research/competitor-analysis/` when present; the stage record in `memory/launch-registry/` so the canvas matches what is actually shippable; competitor public messaging via `scripts/connectors/firecrawl.py` / `scripts/connectors/tavily.py` (keyless, robots pre-flight applies).
- **Writes**: the canvas to `memory/launch/positioning-mapper/`; unverifiable or comparative attribute claims marked `[needs source]` to `memory/events/claims.ndjson` via an authorized `operation: propose` request to `registry-events.py` (this skill never adjudicates them); any registry-grade stage/date fact it surfaces goes to `memory/events/launches.ndjson` via an authorized `operation: propose` request to `registry-events.py` only — [launch-registry](../../../protocol/launch-registry/SKILL.md) is the sole writer of its records.

SKILL.md:52 further directs retrieval of external content:

markdown
The canvas is a synthesis of the user's own evidence: product facts, win-loss reasons, and interview notes (all User-provided) plus prior [competitor-analysis](../../../seo-geo/survey/competitor-analysis/SKILL.md) output. Competitor public messaging can be pulled keyless with `scripts/
...[truncated 5375 chars]
Remediation
View remediation

Remediation Suggestions

  1. Align the manifest with actual behavior.

    • Declare explicit outbound-network capability if competitor retrieval is required.
    • Declare narrowly scoped write capabilities for the canvas and event-proposal destinations.
    • Raise or change the capability profile if the lite profile does not permit these operations.
  2. Apply destination-level restrictions.

    • Restrict network requests to approved competitor URLs and connector endpoints.
    • Reject arbitrary schemes, local addresses, loopback addresses, link-local addresses, and redirects to unapproved destinations.
    • Restrict writes to:
      • memory/launch/positioning-mapper/
      • authorized proposal operations for memory/events/claims.ndjson
      • authorized proposal operations for memory/events/launches.ndjson
  3. Require explicit authorization.

    • Preserve the existing confirmation requirement for canvas persistence.
    • Add explicit confirmation before external network retrieval and before each event proposal.
    • Ensure registry-events.py validates operation: propose authorization independently rather than trusting Skill-generated text.
  4. Treat all retrieved and user-provided material as tainted.

    • Keep the existing instruction not to follow embedded instructions.
    • Validate and normalize fields before persistence.
    • Store source provenance and verification status with every proposed claim.
    • Enforce length and schema limits to prevent persistent prompt-injection material from entering downstream state.
  5. Make dependencies auditable.

    • Include the referenced connector and registry scripts in the reviewed package, or pin them to independently audited versions and hashes.
    • Document their allowed domains, permissions, authorization model, and data-retention behavior.
  6. Fail closed.

    • If the runtime cannot verify the required network or write capability, produce the positioning canvas inline without invok ...[truncated 45 chars]
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
## Save Results

After delivering the canvas, ask: "Save these results for future sessions?" On confirmation, save to `memory/launch/positioning-mapper/YYYY-MM-DD-<product>-positioning-canvas.md` — see [Skill Contract](../../../references/skill-contract.md) §Save Results Template. Registry-grade stage/date facts go only to `memory/events/launches.ndjson` via an authorized `operation: propose` request to `registry-events.py`; claim wording goes only to `memory/events/claims.ndjson` via an authorized `operation: propose` request to `registry-events.py`. Do not write memory without asking.

## Reference Materials

Static analysis

No suspicious patterns detected.