Back to skill

Security audit

InspirAI Evo

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but it persistently logs workflow context across projects and stores it under the user's home directory without clear opt-in, retention, or deletion controls.

Review this skill before installing if you work on sensitive repositories. It may create docs/evo-reports, .evo-state.json, and ~/.claude/evo-stats entries containing workflow context, project names, timestamps, patterns, and pending improvement details. Keep generated files out of version control unless intended, and use --continue only after reviewing proposed changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest description is written as a Chinese-only skill description and the document consistently presents the skill interface and prompts in Chinese, without offering a language choice or stating that the skill is region-specific. This can violate language/locale policy when a skill implicitly constrains interaction language without user opt-in.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The report-generation step instructs the agent to collect and persist workflow context, timestamps, patterns, and related skill names into project-local reports. Even if intended for process improvement, this creates durable logs of session and user activity that may contain sensitive operational details and may later be committed to version control.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill’s stated purpose is per-project workflow analysis, but it copies project state into a shared home-directory statistics area and contemplates aggregated cross-project summaries. This expands data collection beyond the minimum needed and can expose patterns, project names, and workflow context across otherwise separate repositories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The global statistics sync persists project state under the user’s home directory but does not present a clear privacy notice or consent step before collecting and retaining cross-project data. Users may not realize that session-derived context and project metadata are being stored outside the repository and reused later.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Copying .evo-state.json into a shared home-directory statistics directory creates persistent cross-project retention of contextual workflow data. This increases exposure scope because information from one repository can be correlated with others, and users may not expect repository-derived state to be centralized outside the project.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

The skill establishes persistent session-derived storage in ~/.claude/evo-stats and copies project state there, enabling retention beyond the immediate task or repository. Persistent cross-session storage is risky because it can accumulate sensitive operational context and create unintended data reuse across future interactions.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

bash
GLOBAL_DIR="$HOME/.claude/evo-stats"
mkdir -p "$GLOBAL_DIR/projects"

# 更新项目统计
PROJECT_NAME=$(basename $(pwd))

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is presented as an analysis/reporting aid, but its --continue mode explicitly escalates into proposing and then executing repository modifications after user confirmation. That broadens the capability from passive analysis to active code/config changes, increasing the chance of unsafe or over-privileged behavior if the generated recommendations are wrong or manipulated by noisy workflow data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automatic monitoring section instructs continuous detection and recording of workflow incidents, including contextual instances appended to a persistent state file. This effectively implements ongoing behavioral logging across sessions, which can capture sensitive user intent, debugging activity, and project context without strong disclosure or minimization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.