Back to skill

Security audit

Agent自动研究循环

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its autonomous experiment purpose, but it needs review because it can repeatedly run commands, modify code indefinitely, and use destructive git resets that may erase work.

Install only if you are comfortable with an agent repeatedly editing code and running commands. Use it in a clean, disposable branch or worktree, set explicit experiment/time/cost limits, review any autoresearch.config.md before running, and avoid repositories with uncommitted work or accessible secrets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:218
Finding

Unbounded autonomous execution through instruction hijacking

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:159
Finding

Destructive Git rollback may erase unrelated repository changes

Content
View full analysis
(: vs best )" ELIF crashed or timed out: → CRASH: git reset --hard HEAD~1 → Log: "CRASH: (error: )" ``` ### Technical Analysis `git reset --hard HEAD~1` moves the branch reference to the parent commit and forces both the index and tracked working-tree files to match that commit. It is broader than reverting only the experiment's intended changes. The procedure does not require the repository to have a clean working tree before setup or before each rollback. It also does not require execution inside a dedicated Git worktree. Consequently, tracked modifications created outside the experiment can be overwritten when a trial is discarded or crashes. The operation also assumes that `HEAD` is always the experiment commit. Concurrent commits or unexpected repository state can cause the wrong commit to be removed. ### Attack Path 1. A user or another process has valuable tracked changes in the working tree. 2. The Skill starts an experiment without enforcing a clean-tree check or creating an isolated worktree. 3. The experiment creates and commits a change. 4. Additional tracked modifications exist when the benchmark crashes or fails to improve the metric. 5. The prescribed `git reset --hard HEAD~1` is executed. 6. Git rewrites the index and tracked working tree, deleting modifications not represented in the target commit. 7. If those changes were never committe ...[truncated 674 chars]
Remediation
View remediation
` when preserving history is acceptable. 6. If an uncommitted experiment must be discarded, restore only explicitly authorized target paths instead of resetting the entire working tree. 7. Before any destructive operation: - Verify the active repository and branch. - Verify that `HEAD` equals the recorded experiment commit. - Check for new or unrelated modifications. - Create a recovery reference or backup. 8. Abort rollback if concurrent repository changes are detected. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:6
Finding

Overly broad tool permissions and repeated unrestricted command execution

Content
View full analysis
> run.log 2>&1 ``` ### Technical Analysis Shell execution is reasonably required for benchmark-driven experimentation. However, the Skill grants a broad `exec` capability and an additional `sessions_spawn` capability that is not used by the documented protocol. The latter therefore exceeds the minimum privileges necessary for the declared functionality. The run command is persisted in `autoresearch.config.md` and executed repeatedly. The protocol does not require validation, an executable allowlist, argument separation, shell-metacharacter filtering, or renewed confirmation before execution. A maliciously prepared or mistakenly edited configuration could therefore cause arbitrary commands to run repeatedly with the agent's permissions. Because the command is interpolated into a shell-oriented execution pattern with output redirection, shell operators included in the configured value may be interpreted as additional commands, depending on the host tool's execution semantics. ### Attack Path 1. A repository contains a pre-existing `autoresearch.config.md`, or an unsafe command is entered during setup. 2. The user invokes `/autoresearch run`. 3. The Skill reads the configured run command without validating its executable, arguments, or shell syntax. 4. The agent executes the command through the `exec` tool. 5. The autonomous loop repeats the command for subsequent experiments. 6. Any malicious comm ...[truncated 1113 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill begins autonomous experimentation with shell execution, file edits, git branch creation, and destructive rollback behavior, but does not prominently warn about these actions in the user-facing description or setup flow. This omission is dangerous because users may invoke it without understanding that it can repeatedly execute commands and discard local changes via hard resets.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The instruction to use git reset --hard HEAD~1 after crashes introduces a destructive operation that can permanently discard working tree and index changes, including unrelated user work if repository state is not perfectly isolated. In an autonomous loop, repeated hard resets amplify the risk of accidental data loss and make recovery difficult.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

If the run crashed or timed out:

- Read the error from run.log

- Record as crash in results.tsv

- Revert: git reset --hard HEAD~1

- Diagnose and try a different approach

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Using git reset --hard HEAD~1 for non-improving experiments is a destructive rollback pattern that can erase changes beyond the intended experiment if the repository contains concurrent edits or the commit boundary does not fully isolate the modification. Because the skill is designed to run indefinitely, this creates sustained risk of repeated accidental loss of user data.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
→ Log: "KEEP: <description> (<metric>: <old> → <new>)"

ELIF metric equal or worse:
    → DISCARD: git reset --hard HEAD~1
    → Log: "DISCARD: <description> (<metric>: <value> vs best <best>)"

ELIF crashed or timed out:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The crash-handling path again mandates git reset --hard HEAD~1, which is especially risky during failure scenarios because repository state may already be inconsistent or partially modified. Performing a hard reset under those conditions can destroy evidence needed for debugging and wipe unrelated local work.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

→ Log: "DISCARD: (: vs best )"

ELIF crashed or timed out: → CRASH: git reset --hard HEAD~1 → Log: "CRASH: (error: )"

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list includes broad terms like "optimize" and "run experiments," which can cause this skill to activate in many ordinary contexts where the user did not intend autonomous code modification and command execution. Because the skill is user-invocable and grants exec/write/git capabilities, overbroad triggering materially increases the chance of unsafe invocation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.