Back to skill

Security audit

Text Tools Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward text-processing skill with ordinary file read/write behavior and no evidence of hidden execution, persistence, exfiltration, or privilege escalation.

Before installing, treat it as a local text-file utility: use explicit input and output paths, avoid overwriting important files, and be careful when extracting emails or phone numbers from sensitive documents. I found no evidence that it sends data elsewhere or modifies the system persistently.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises file-reading and file-writing workflows through its commands, but it does not declare any explicit tool scope, permissions, or allowed-tools boundaries. That creates an authorization and least-privilege gap: an agent may infer broad file access is acceptable and perform unintended reads or overwrites without clear policy constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description uses broad activation wording like 'use when users need to process, format, clean, or analyze text content,' which can cause the skill to trigger for a very wide set of routine user requests. Overbroad invocation increases the chance the agent applies file-modifying or extraction behaviors in situations where the user did not intend to delegate those actions to this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The overview presents the skill as a general-purpose, everyday text toolkit without clear invocation limits or safety boundaries. In context, that ambiguity is more concerning because the documented features include regex replacement, file output, and data extraction, which can change user data or surface sensitive content if invoked too freely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage examples show output-writing and text-modifying operations, but the markdown does not warn that these commands may overwrite existing files or alter data. Without an explicit caution, users or agents may run destructive operations on important files, leading to accidental data loss or corruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill explicitly supports extracting URLs, emails, and phone numbers from text, but it provides no privacy notice or handling guidance for potentially sensitive data. In a broad-use skill, that omission can normalize bulk extraction of personal information without prompting the user to consider consent, minimization, or downstream exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.