Back to skill

Security audit

project-init

Security checks for vulnerabilities and agentic risk

Overview

This project scaffolding skill is mostly transparent, but it can run repository-controlled Makefile and pytest code without enough scoping or user approval.

Install only if you are comfortable with a scaffolding skill that can create or overwrite project tooling. In existing or untrusted repositories, review any Makefile, pytest configuration, tests, and hooks before allowing the agent to run make or pytest commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:114
Finding

Execution of Project-Controlled Makefile Targets

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:114-127; modules/template-rendering.md:166-173
Vulnerability Type: Execution of untrusted project-defined build commands
Risk Level: High

Vulnerable Code

From SKILL.md:

bash
# Check Makefile targets
make help

# List created files
git status

The subsequent workflow also advises executing additional project-defined targets:

bash
# Install dependencies and hooks
make dev-setup

# Run tests to verify setup
make test

# See all available commands
make help

From modules/template-rendering.md:

bash
# Check Makefile works
make help

# Check git status
git status

# Verify directory structure
tree -L 2

Technical Analysis

The skill supports updating existing projects and instructs the agent or user to execute targets from the Makefile in the current working directory. Make targets are executable shell recipes, and target names such as help, test, or dev-setup do not provide any security guarantee.

An attacker-controlled repository can define a malicious help target or use Makefile features that execute commands while the file is parsed. Relevant mechanisms include target recipes, included Makefiles, shell expansion, and GNU Make functions such as $(shell ...). Consequently, even a target presented as validation can execute arbitrary commands with the privileges of the account running the skill.

The workflow discusses conflict handling for existing files, but it does not require security inspection of the existing Makefile, its included files, or the exact recipes before execution. It also does not require isolation, network restrictions, or removal of credentials from the execution environment.

Attack Path

  1. An attacker prepares a repository containing a malicious Makefile.
  2. The victim opens or clones the repository and invokes the project initialization skill.
  3. The ex ...[truncated 1155 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not automatically execute Makefile targets in existing or untrusted projects.
  • Inspect the Makefile and every recursively included Makefile before execution.
  • Display the exact target recipes and require explicit, informed user approval.
  • Treat make help as executable code rather than as a read-only inspection command.
  • Prefer non-executing inspection where possible, such as displaying the generated file or validating expected text structurally.
  • Distinguish newly generated, trusted files from pre-existing files and refuse to execute preserved project files by default.
  • Run approved build targets inside an ephemeral sandbox or container with:
    • No mounted credentials or sensitive home-directory content.
    • Read-only access outside the project workspace.
    • Network access disabled unless explicitly required.
    • Minimal environment variables.
    • Non-root privileges and resource limits.
  • Record whether each executable file was generated during the current run, preserved from the repository, or modified during conflict resolution.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:128
Finding

Unsafe Execution of Repository-Controlled Pytest Hooks and Test Modules

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:128
Vulnerability Type: Execution of untrusted test collection and plugin code
Risk Level: High

Vulnerable Code

bash
pytest -v

Technical Analysis

Pytest is not a passive validation utility. During startup and test collection, it may load and execute repository-controlled Python code, including:

  • conftest.py files.
  • Test modules and their import-time code.
  • Local or configured pytest plugins.
  • Hooks registered through pytest configuration.
  • Package initialization code imported by the tests.

Because the skill is intended to operate on existing projects, the repository may contain code that was not generated or reviewed by the skill. Running pytest -v against such a repository can therefore execute arbitrary attacker-controlled Python code before any tests actually run.

The instruction does not require reviewing pytest configuration, conftest.py, plugin declarations, or imported modules. It also does not require an isolated environment or protection of credentials and sensitive files.

Attack Path

  1. An attacker creates or modifies a project to include a malicious conftest.py, pytest plugin, or test module.
  2. The victim obtains the project and invokes the project initialization skill.
  3. The workflow follows the verification instruction and runs pytest -v.
  4. Pytest discovers and imports the attacker-controlled hook, plugin, or test module.
  5. Malicious import-time or hook code executes during startup or collection.
  6. The payload operates with the current user's permissions, potentially before any test result is displayed.

Impact Assessment

Exploitation results in arbitrary Python and operating-system command execution under the account running pytest. The attacker may be able to:

  • Read project files and other files accessible to the current user.
  • Extract environment variables, API tokens, SSH con ...[truncated 420 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not run pytest automatically for existing or untrusted projects.
  • Clearly warn that pytest collection executes repository-controlled Python code.
  • Require explicit user approval immediately before test execution.
  • Review conftest.py, pytest configuration, plugin declarations, and test imports before running tests.
  • Execute tests in a disposable container or sandbox using an unprivileged account.
  • Disable outbound network access unless it is explicitly necessary.
  • Do not expose host credentials, SSH agents, cloud tokens, package registry credentials, or sensitive environment variables to the test process.
  • Mount only the required project directory and make unrelated host paths inaccessible.
  • Consider making verification opt-in and provide non-executing structural validation as the default.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list is malformed and overly broad: splitting 'starting a new Python, Rust, or TypeScript project from scratch' into separate items like 'Rust' and 'or TypeScript project from scratch' can cause the skill to activate in unintended contexts. Because this skill performs filesystem and git setup actions, accidental invocation could lead to confusing or destructive changes in the wrong repository or directory.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The edge-case instruction says to default to Python when no source files exist. This imposes a specific language choice rather than preserving neutrality or asking the user, which conflicts with the policy against forcing a language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file describes reading git config user.name and git config user.email, which accesses personal identifying metadata from the user's environment. The document includes examples and prompts, but it does not explicitly warn that the skill will inspect local git configuration to prefill personal data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.