Back to skill

Security audit

Attack Surface Mapper

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed security-reporting helper that reads local security logs and writes local coverage reports, with some reporting-accuracy bugs but no evidence of hidden, destructive, or exfiltrating behavior.

Install only if you are comfortable letting the skill read local `.security/` red-team, firewall, anomaly, and audit artifacts and write reports under `.security/surface-map`. Treat its output as advisory until the inter-agent mapping and detection-status bugs are fixed, because it may underreport or misclassify some coverage gaps.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:99
Finding

Inter-Agent Attack Surface Is Silently Omitted from Coverage Analysis

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:61
Finding

Boolean Detection Results Produce Contradictory Coverage Status

Content
View full analysis
d.action?.message?.includes('Prompt injection')); } // Simplified: Check anomaly logs for 'data-theft' if (vector === 'data-theft') { return blueTeamDetections.some(d => d.metric === 'data_volume' && d.classification === 'CRITICAL'); } // Simplified: Check if config-hardener audit report exists for 'config-security' if (vector === 'config-security') { return auditReports.some(r => r.includes('config-hardener')); } return null; // Default to not detected }, /** * Determine coverage status */ getCoverageStatus(redTested, blueDetected) { if (redTested && blueDetected) return 'COVERED'; if (redTested && !blueDetected) return 'GAP'; if (!redTested && blueDetected) return 'PARTIAL'; // Blue detected, but no formal red test yet return 'GAP'; // No red test, no blue detection }, ``` ### Technical Analysis `Array.prototype.some()` returns a primitive boolean. When a detection exists, `blueDetected` is therefore `true`. The coverage-status function treats that value as a successful detection and may return `COVERED`. The presentation logic separately evaluates `blueDetected.full`. A primitive boolean has no meaningful `full` property, so this exp ...[truncated 1725 chars]
Remediation
View remediation
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · index.js (reported line 113)May include surrounding context.

js
},

  /**
   * List all known attack surfaces
   */
  listAttackSurfaces() {
    return [
      'CHANNELS',
      'SKILLS',
      'TOOLS',
      'MODELS',
      'MEMORY',
      'INTER-AGENT',
      'SUPPLY_CHAIN'
    ];
  },

  /**
   * Get attack vectors for a given surface
   */
  getAttackVectorsForSurface(surface) {
    switch (surface) {
      case 'CHANNELS': return ['prompt-injection', 'social-engineering', 'phishing'];
      case 'SKILLS': return ['malicious-instructions', 'data-theft', 'privilege-escalation'];
      case 'TOOLS': return ['command-injection', 'path-traversal', 'ssrf', 'rce'];
      case 'MODELS': return ['prompt-injection', 'model-confusion', 'jailbreak'];
      case 'MEMORY': return ['memory-poisoning', 'persistence', 'false-context'];
      case 'INTER_AGENT': return ['agent-to-agent-attack', 'lateral-movement'];
      case 'SUPPLY_CHAIN': return ['typosquatting', 'compromised-package', 'repo-takeover'];
      default: return [];
    }
  },

  /**
   * Loa

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill lists the surface as 'INTER-AGENT' but handles it in getAttackVectorsForSurface() as 'INTER_AGENT', so that attack surface receives no vectors and is silently excluded from coverage analysis. This creates a blind spot in a security mapping tool, causing underreporting of inter-agent attack paths and potentially misleading defenders into believing coverage is complete when it is not.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.