T09 · Insecure Skill Coding Practices
- Location
index.js:99- Finding
Inter-Agent Attack Surface Is Silently Omitted from Coverage Analysis
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed security-reporting helper that reads local security logs and writes local coverage reports, with some reporting-accuracy bugs but no evidence of hidden, destructive, or exfiltrating behavior.
Install only if you are comfortable letting the skill read local `.security/` red-team, firewall, anomaly, and audit artifacts and write reports under `.security/surface-map`. Treat its output as advisory until the inter-agent mapping and detection-status bugs are fixed, because it may underreport or misclassify some coverage gaps.
index.js:99Inter-Agent Attack Surface Is Silently Omitted from Coverage Analysis
index.js:61Boolean Detection Results Produce Contradictory Coverage Status
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).
},
/**
* List all known attack surfaces
*/
listAttackSurfaces() {
return [
'CHANNELS',
'SKILLS',
'TOOLS',
'MODELS',
'MEMORY',
'INTER-AGENT',
'SUPPLY_CHAIN'
];
},
/**
* Get attack vectors for a given surface
*/
getAttackVectorsForSurface(surface) {
switch (surface) {
case 'CHANNELS': return ['prompt-injection', 'social-engineering', 'phishing'];
case 'SKILLS': return ['malicious-instructions', 'data-theft', 'privilege-escalation'];
case 'TOOLS': return ['command-injection', 'path-traversal', 'ssrf', 'rce'];
case 'MODELS': return ['prompt-injection', 'model-confusion', 'jailbreak'];
case 'MEMORY': return ['memory-poisoning', 'persistence', 'false-context'];
case 'INTER_AGENT': return ['agent-to-agent-attack', 'lateral-movement'];
case 'SUPPLY_CHAIN': return ['typosquatting', 'compromised-package', 'repo-takeover'];
default: return [];
}
},
/**
* Loa
The skill lists the surface as 'INTER-AGENT' but handles it in getAttackVectorsForSurface() as 'INTER_AGENT', so that attack surface receives no vectors and is silently excluded from coverage analysis. This creates a blind spot in a security mapping tool, causing underreporting of inter-agent attack paths and potentially misleading defenders into believing coverage is complete when it is not.
No suspicious patterns detected.