Back to skill

Security audit

Insecure Defaults Detection

Security checks for vulnerabilities and agentic risk

Overview

This security-audit skill is mostly coherent, but it grants unrestricted shell access without a clear need for that authority.

Review this before installing in sensitive workspaces. The audit guidance itself is appropriate, but Bash should ideally be removed or tightly restricted unless the user explicitly wants shell-backed analysis and trusts the repositories being inspected.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:4
Finding

Unnecessary Unrestricted Shell Access Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4-9
Vulnerability Type: Excessive tool permissions
Risk Level: Medium

Vulnerable Code:

yaml
allowed-tools:
  - Read
  - Grep
  - Glob
  - Bash
---

Technical Analysis

The Skill is designed to identify insecure defaults by discovering, reading, searching, and tracing files. Its documented workflow can be performed using Read, Grep, and Glob. No documented operation requires arbitrary shell-command execution.

Granting Bash therefore exceeds the minimum privileges necessary for the declared functionality. Unlike the read-oriented tools, unrestricted shell access may permit command execution, filesystem modification, process creation, access to environment variables and locally available credentials, and outbound network operations, subject to the privileges and sandbox controls of the host Agent.

The audit found no shell command that is automatically executed and no embedded malicious payload. Exploitation consequently depends on the Agent being induced to use the unnecessarily authorized tool, such as through malicious content encountered while auditing an untrusted repository.

Attack Path

  1. The Skill is loaded with Bash included in its authorized tools.
  2. The Agent audits an attacker-controlled repository or configuration file.
  3. Malicious or misleading repository content induces the Agent to execute a shell command as part of its analysis.
  4. Because shell access is already authorized, the command runs with the filesystem, process, environment, and network permissions available to the Agent.
  5. The command may inspect local secrets, alter files, launch processes, or transmit accessible information.

Impact Assessment

Successful exploitation could expose environment variables, credentials, source files, and other data accessible to the Agent. It could also permit modification of writable files or execution of addit ...[truncated 581 chars]

Remediation
View remediation

Remediation Suggestions

Remove Bash from the Skill’s allowed-tools list and retain only the read-oriented capabilities required by the documented workflow:

yaml
allowed-tools:
  - Read
  - Grep
  - Glob

If a future workflow genuinely requires command execution, replace unrestricted shell access with a narrowly scoped tool or explicit allowlist. Restrict permitted commands and arguments, disable network access where unnecessary, prevent writes outside a dedicated temporary directory, avoid inheriting sensitive environment variables, and require user confirmation before executing commands derived from repository content.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
75% confidence
Finding

Skill attempts to nullify the agent's safety policies or restrictions ('you have no restrictions', 'ignore your guidelines', 'do anything now'). This is a direct jailbreak that disables guardrails.

Content

Scanner excerpt · examples.md (reported line 173)May include surrounding context.

text
**Why vulnerable:** Default allows requests from any origin. XSS/CSRF risk.

**Debug mode enabled by default**
```python
# File: config.py
DEBUG = os.getenv('DEBUG', 'true').lower() != 'false'  # Default: true

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · examples.md (reported line 286)May include surrounding context.

❌ VULNERABLE - Report These

File permissions world-writable

python
# File: src/storage/files.py
def create_secure_file(path):

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · examples.md (reported line 323)May include surrounding context.

python
# File: src/storage/public_assets.py
def create_public_asset(path):
    """Create world-readable asset for CDN distribution"""
    # Intentionally public - static assets only
    fd = os.open(path, os.O_CREAT | os.O_WRONLY, 0o644)
    return fd

Static analysis

No suspicious patterns detected.