Back to skill

Security audit

InspirAI Skill Audit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a mostly coherent audit helper, but it can change installed command/plugin state and contains contradictory, unsafe instructions for doing so.

Review carefully before installing. Use the scan/status parts as inventory aids, but treat resolve as a configuration-changing operation. Prefer dry-run first, avoid direct plugin registry edits, and make a backup of ~/.claude/commands and ~/.claude/plugins/installed_plugins.json before allowing it to disable anything.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:123
Finding

Untrusted Skill Content Is Embedded in an AI Analysis Prompt

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:423
Finding

Unsafe Plugin Registry Rewrite Uses Interpolated jq Source and a Predictable Temporary File

Content
View full analysis
tmp && mv tmp "$PLUGINS_FILE" ``` The procedure also conflicts with the safety statement at line 475, which says plugin disablement is recorded in the cache and does not directly modify `installed_plugins.json`. ### Technical Analysis The command has two independent unsafe behaviors: 1. **jq program injection:** `${PLUGIN_KEY}` is interpolated directly into jq program source. It is not supplied as data through `jq --arg`. A plugin key containing quotes, backslashes, or jq syntax can break out of the intended property expression and alter the filter's behavior. 2. **Predictable temporary file:** Output is written to the relative path `tmp`. This is not unique, is not guaranteed to be in the same protected directory as the destination, and can collide with an existing file or symbolic link. Concurrent executions can overwrite each other's output. The operation also assumes an undocumented JSON structure and attempts to append an array containing a `disabled` object to the selected plugin entry. If the entry has a different type, the operation may fail or produce an invalid registry structure. Although the document later recommends using the official plugin uninstall command and claims the registry will not be modified directly, the executable example explicitly performs the direct mutation. Agents following the concrete code may select the unsafe implementation. ### Attack Path A plugin-key exploitation path is: 1. An attacker supplies a plugin whose identifier contains characters that are meaningful inside a jq string or expression. 2. The identifier is recorded as `${PLUGIN_KEY}` during scan or resolution processing. 3 ...[truncated 1373 chars]
Remediation
View remediation
"$tmp_file" || exit 1 jq empty "$tmp_file" || exit 1 chmod --reference="$PLUGINS_FILE" "$tmp_file" 2>/dev/null || chmod 600 "$tmp_file" mv -- "$tmp_file" "$PLUGINS_FILE" trap - EXIT ``` 7. Create a verified backup before mutation and restore it if validation or replacement fails. 8. Add locking to prevent concurrent resolution operations from racing. 9. Record sufficient original plugin metadata for reliable rollback rather than relying only on a textual disabled identifier. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The safety rules state that plugin handling should not directly modify installed_plugins.json, but the implementation shows direct jq-based mutation of that file. Directly editing installation state can corrupt plugin configuration, disable capabilities unexpectedly, or create inconsistent state that is hard to recover.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger phrase '精简配置' is a general phrase that may overlap with everyday requests to simplify configuration, not specifically skill auditing. Unintended activation is more concerning here because the skill can inventory user-installed tooling and propose or perform disablement actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger phrase '精简配置' is a general phrase that may overlap with everyday requests to simplify configuration, not specifically skill auditing. Unintended activation is more concerning here because the skill can inventory user-installed tooling and propose or perform disablement actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger phrase '精简配置' is a general phrase that may overlap with everyday requests to simplify configuration, not specifically skill auditing. Unintended activation is more concerning here because the skill can inventory user-installed tooling and propose or perform disablement actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation claims scanning is completely read-only, yet the scan flow writes an audit cache file under the user's home directory. Even if the write is low risk, inaccurate claims about side effects undermine informed consent and can bypass expectations or policies that permit only non-mutating actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as an audit/analysis tool, but its resolve workflow performs state-changing actions such as moving command files and potentially altering plugin state. This mismatch can mislead users or downstream systems into granting broader trust or invoking it in contexts where only read-only analysis was expected.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This skill mixes some English command tokens with predominantly Chinese instructions and descriptions, but does not state that Chinese is optional or provide a user language choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.