Back to skill

Security audit

Anomaly Watcher

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real local security-monitoring skill, but it records broad agent activity continuously and can write monitoring files to caller-chosen locations without enough controls.

Install only if you are comfortable with local, persistent recording of agent prompts, tool activity, skill activity, baselines, and anomaly events. Use it in a private workspace, avoid shared or sensitive directories, review or restrict the input.path behavior, and plan how .security logs will be rotated or deleted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:62
Finding

Caller-Controlled Storage Root Enables Unauthorized Filesystem Writes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:20
Finding

Anomaly Detection Logic Permits False Negatives and Unreachable Severity Classification

Content
View full analysis
3σ } ``` The critical test occurs before the anomalous test, making `ANOMALOUS` unreachable: ```js let classification = 'NORMAL'; if (sigma > this.config.thresholds.critical) classification = 'CRITICAL'; else if (sigma > this.config.thresholds.anomalous) classification = 'ANOMALOUS'; else if (sigma > this.config.thresholds.elevated) classification = 'ELEVATED'; ``` Historical entries are not aggregated by hour even though an hourly key is constructed: ```js // Group by metric type and hour const hourlyData = {}; for (const line of lines) { const entry = JSON.parse(line); const key = `${entry.type}:${entry.hour}`; if (!hourlyData[entry.type]) { hourlyData[entry.type] = []; } hourlyData[entry.type].push(entry.value); } ``` Current values, in contrast, are aggregated into hourly totals: ```js // Aggregate current hour for (const line of lines) { const entry = JSON.parse(line); if (entry.hour === currentHour) { currentMetrics[entry.type] = (currentMetrics[entry.type] || 0) + entry.value; } } ``` Several documented signature conditions are omitted from the implemented checks: ```js // SIG-001: Reconnaissance Pattern if (current.file_read > (baseline.file_read?.average || 10) * 3 && current.unique_paths > 50) { hits.push(this.signatures[0]); } // SIG-002: Potential Exfiltration if (current.network_request > (baseline.network_request?.average || 0) * 2 && current.new_domains > 0) { hits.push(this.signatures[1]); } // SIG-003: Supply Chain Risk if (current.skill_install > 5) { hits.push(this.signatures[2]); } // SIG-004: Persistence Attempt if (current.memory_wri ...[truncated 3085 chars]
Remediation
View remediation
3) classification = 'CRITICAL'; else if (sigma > 2) classification = 'ANOMALOUS'; else if (sigma > 1) classification = 'ELEVATED'; else classification = 'NORMAL'; ``` 2. Aggregate historical records by metric type and hour before calculating averages and standard deviations: ```js const hourlyTotals = {}; for (const line of lines) { const entry = JSON.parse(line); const key = `${entry.type}:${entry.hour}`; hourlyTotals[key] = (hourlyTotals[key] || 0) + entry.value; } ``` 3. Calculate statistics from the resulting hourly totals so historical and current values use the same units. 4. Filter historical records to the configured rolling seven-day window. 5. Implement every documented signature condition, including: - Scattered file-read patterns. - Exfiltration data volume. - Skill-install time windows. - Encoded-content detection for memory writes. 6. If a condition cannot be reliably measured, remove it from the advertised signature rather than reporting unsupported coverage. 7. Handle zero standard deviation explicitly. A current value above a constant baseline should not automatically receive a sigma of zero. 8. Add unit tests for exact threshold boundaries, zero-variance baselines, hourly aggregation, seven-day filtering, missing metrics, and each complete signature predicate. 9. Add adversarial tests that distribute activity across time windows and verify that documented attacks cannot bypass detection through omitted conditions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly logs every user prompt, tool invocation, and skill result to local files, but it does not provide a clear warning about the collection and retention of potentially sensitive user input and system activity. This creates a privacy and data-handling risk because secrets, personal data, file paths, and operational details may be captured in persistent logs without informed user awareness or minimization.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill persistently records behavioral metrics to disk without any notice, consent flow, or documented retention controls. Even though the feature is aligned with anomaly detection, undisclosed telemetry can collect sensitive usage patterns, paths, and session details, creating privacy and surveillance risk if the data is later accessed, misused, or retained too broadly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Persistent anomaly logs can expose potentially sensitive security events, behavioral deviations, and correlated activity data without the user's awareness. In the context of a monitoring skill, the logging is expected functionally, but silent persistence increases privacy risk and creates a useful intelligence source for anyone who can read the log files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

Writing derived baseline statistics to disk is less sensitive than raw event logging, but it still creates persistent monitoring artifacts without disclosure. Those artifacts can reveal behavioral norms and operational patterns that may be sensitive in some environments, especially if stored in shared workspaces or with weak access controls.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.