Back to skill

Security audit

Co2 Tank Monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill is not deceptive or exfiltrative, but its CO2 depletion monitor is unreliable enough for a safety-adjacent lab workflow that users should review it carefully before use.

Use this only as an advisory training or prototype tool unless the calculation model, units, capacity handling, and input validation are fixed and independently validated. Do not rely on it as the only unattended incubator gas monitor, and do not connect it to cron or paging workflows without separate sensor validation, failure alerts, backup alarms, and manual checks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:27
Finding

Unvalidated Non-Finite Numeric Values Can Terminate Scheduled Monitoring

Content
View full analysis
float: """Calculate remaining days""" if daily_consumption <= 0: return float('inf') return pressure / daily_consumption def calculate_depletion_time(remaining_days: float) -> datetime: """Calculate estimated depletion time""" return get_current_time() + timedelta(days=remaining_days) ``` The affected values originate from command-line arguments and are passed directly into the calculation: ```python pressure = args.pressure capacity = args.capacity daily_consumption = args.daily_consumption remaining_days = calculate_remaining_days(pressure, daily_consumption) depletion_time = calculate_depletion_time(remaining_days) ``` ### Technical Analysis The application accepts arbitrary floating-point values for pressure and daily consumption without checking whether they are finite or within physically realistic ranges. When `daily_consumption` is zero or negative, `calculate_remaining_days()` deliberately returns positive infinity. That value is then passed to `timedelta(days=remaining_days)`, which cannot represent infinity and raises an exception. Inputs such as `nan`, `inf`, or sufficiently large finite numbers can produce the same outcome. Because no exception handler surrounds the calculation, the process terminates before producing a status code or monitoring report. This is particularly significant when the command is run through the documented cron integration: the failed invocation may suppress the expected depletion alert. ### Attack Path 1. An attacker, malfunctioning sensor integration, or incorrectly configured scheduled task supplies a ma ...[truncated 1716 chars]
Remediation
View remediation
None: if not math.isfinite(pressure) or pressure < 0 or pressure > 20: raise ValueError("Pressure must be a finite value between 0 and 20 MPa") if ( not math.isfinite(daily_consumption) or daily_consumption <= 0 or daily_consumption > 10 ): raise ValueError( "Daily consumption must be a finite positive value no greater than 10 MPa/day" ) if alert_days < 0 or alert_days > 365: raise ValueError("Alert days must be between 0 and 365") ``` 2. Do not represent invalid or unknown consumption as infinite remaining life. Treat zero, negative, missing, and non-finite consumption as sensor or configuration failures. 3. Catch validation and arithmetic errors in `main()` and return a separate operational-error exit code: ```python try: validate_inputs(pressure, daily_consumption, args.alert_days) remaining_days = calculate_remaining_days( pressure, daily_consumption ) depletion_time = calculate_depletion_time(remaining_days) except (ValueError, OverflowError) as exc: print(f"Monitoring input error: {exc}", file=sys.stderr) sys.exit(3) ``` 4. Configure alert automation to escalate exit code `3` as a monitoring-system failure rather than treating it as a normal result. 5. Add automated tests for zero, negative, `nan`, positive and negative infinity, and extreme finite values. ]]>

other

Error
Location
scripts/main.py:148
Finding

Cylinder Capacity Is Ignored, Allowing Materially Incorrect Depletion Predictions

Content
View full analysis
float: """Calculate remaining days""" if daily_consumption <= 0: return float('inf') return pressure / daily_consumption ``` ### Technical Analysis The Skill advertises support for both 10 L and 40 L cylinders, but the selected capacity does not affect the depletion estimate. Two cylinders with identical pressure and `daily_consumption` inputs therefore receive identical remaining-life estimates even though the documented capacity difference is fourfold. This can be correct only if `daily_consumption` is a pressure-decay rate measured independently for the specific installed cylinder. The documentation, however, presents capacity as a calculation parameter and repeatedly claims capacity-based multi-cylinder support. This creates an unsafe interface contract: operators can reasonably expect the selected capacity to adjust the prediction when it does not. The report reinforces the misleading result by displaying the chosen capacity alongside the capacity-independent estimate. ...[truncated 1800 chars]
Remediation
View remediation
float: available_pressure_l = pressure_mpa * cylinder_volume_l return available_pressure_l / gas_consumption_l_per_day ``` This example must not be adopted without domain validation because compressed-gas behavior, residual pressure, regulator limits, temperature, and safety reserves may require a more complete model. 5. Add consistency checks that reject a capacity/consumption configuration not calibrated for the selected cylinder. 6. Add regression tests demonstrating the intended relationship between 10 L and 40 L cylinders and compare predictions against observed depletion data. 7. Update `SKILL.md` so the documented formula, units, command-line behavior, and multi-cylinder claims exactly match t ...[truncated 222 chars]
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly says it should not be used for real-time IoT sensor integration, but later provides code and cron patterns that read sensor logs and trigger automated execution. This contradiction can cause operators to deploy the skill in a production-like sensor-driven setting without appropriate hardening, validation, authentication, or failure handling, increasing the chance of unsafe automation or misuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is described as an IoT monitoring simulation that predicts cylinder depletion and generates alerts, but the documented code also launches a separate Python process via subprocess.run. Spawning subprocesses is a broader execution capability than needed for simple pressure calculations and alert evaluation, and it is not part of the stated monitoring purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README uses Chinese terms ("上游", "下游") in user-facing documentation while the rest of the skill is in English, and it does not indicate that multilingual output is optional or user-selectable. This can conflict with a language/locale policy that requires consistent language unless the user has opted in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.