Back to skill

Security audit

HomeNetworkSecurityAgent

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent home-network scanner, but it needs Review because it can actively scan local or public targets without strong scope checks or clear warnings.

Install only if you are comfortable running active nmap scans from this machine and will use it only on networks and public IPs you own or are authorized to test. Review the scanner before use, avoid deep scans by default, and consider adding target validation, explicit confirmation, an allowlist, and disclosure or opt-out for the public-IP lookup.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scanner.py:43
Finding

Unvalidated Scan Target Permits Nmap Option Injection

Content
View full analysis
' ``` 3. `scanner.py` places the crafted value directly in the Nmap argument array. 4. If the value begins with `-`, Nmap may parse it as one of its own command-line options instead of as an IP address. 5. Nmap performs unintended behavior under the per ...[truncated 1100 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill exposes shell and network-capable operations but does not declare any explicit tool scope or permission boundaries. That increases the chance an agent platform will run active scanning behavior without clear user consent, policy gating, or least-privilege enforcement, which is risky for a network-auditing skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill invites active LAN discovery and external-facing scans, including deep vulnerability scanning of a router, but does not warn users that these actions may disrupt fragile devices, trigger IDS/ISP abuse controls, or violate acceptable-use policies. In a home-network context, the behavior is expected functionally, but the missing warning still makes misuse and unintended harm more likely.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

Setup

Ensure nmap is installed on the host system:

bash
sudo apt install nmap

User Instructions

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scanner.py (reported line 10)May include surrounding context.

python
def get_network_topology():
    try:
        # Extract default gateway using ip route
        route_out = subprocess.run(['ip', 'route'], capture_output=True, text=True).stdout
        gateway_match = re.search(r'default via ([0-9\.]+)', route_out)
        gateway = gateway_match.group(1) if gateway_match else "Unknown"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill contacts an external service to determine the public IP without any disclosure, consent, or privacy notice. This leaks network-identifying metadata to a third party and may violate user expectations or organizational policy, especially in a security-auditing tool operating on local infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code performs an active LAN sweep with nmap automatically and without any user-facing warning or confirmation. Active scanning can trigger IDS/IPS alerts, disrupt sensitive devices, and violate acceptable-use rules if run in unmanaged or third-party environments.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scanner.py (reported line 31)May include surrounding context.

python
subnet = f"{parts[0]}.{parts[1]}.{parts[2]}.0/24"
        
        # Run nmap ping sweep
        result = subprocess.run(['nmap', '-sn', subnet], capture_output=True, text=True)
        
        hosts = []
        for line in result.stdout.split('\n'):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill allows port and service scanning of user-supplied targets with no warning, authorization check, or restriction on scope. In context, this is more dangerous because the skill is explicitly a network security agent, making it a ready-made reconnaissance capability that can be repurposed against arbitrary internal or external targets from the host running it.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
90% confidence
Finding

The code passes a user-supplied target directly into nmap, enabling arbitrary host scanning from the environment where this skill runs. Although shell injection is mitigated by argument-list invocation, this still creates a scanning primitive that can be abused for unauthorized reconnaissance against internal or external systems.

Content

Scanner excerpt · scanner.py (reported line 51)May include surrounding context.

python
else:
            cmd = ['nmap', '-F', '-sV', ip_address]
            
        result = subprocess.run(cmd, capture_output=True, text=True)
        
        open_ports = []
        for line in result.stdout.split('\n'):

Static analysis

No suspicious patterns detected.