Back to skill

Security audit

tool-call-retry

Security checks for vulnerabilities and agentic risk

Overview

This retry helper is not malicious, but it can automatically repeat or modify high-impact tool calls while overstating its idempotency protection.

Install only if you will use it for idempotent or carefully controlled operations. Do not wrap payments, writes, deletes, public posting, or database mutation unless the downstream system enforces real idempotency keys, the cache is scoped per user/tool/arguments with expiry, and repaired commands are reviewed before execution.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
index.ts:45
Finding

Retry Logic Can Duplicate Side-Effecting Operations

Content
View full analysis
setTimeout(resolve, delay)); } } ``` ### Technical Analysis The wrapper caches a result only after `toolFn` returns and `validatorFn` accepts the response. The supplied `idempotencyKey` is not passed to the downstream tool, and the wrapper does not atomically reserve the key before execution. A side-effecting operation may therefore complete successfully but subsequently throw, time out, lose its response, or fail local result validation. In each case, the wrapper treats the attempt as failed and invokes the operation again. The in-memory result cache cannot prevent this because no cache entry exists until a validated response has been receive ...[truncated 1204 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.ts:17
Finding

Process-Global Idempotency Cache Is Not Scoped Between Callers or Tools

Content
View full analysis
(); ``` ```typescript // 幂等性检查 if (idempotencyKey && idempotencyCache.has(idempotencyKey)) { return { success: true, data: idempotencyCache.get(idempotencyKey), attempts: 0, fromCache: true, error: null }; } ``` ```typescript // 缓存幂等性结果 if (idempotencyKey) { idempotencyCache.set(idempotencyKey, result); } ``` ### Technical Analysis The module-global cache stores arbitrary tool results under a caller-provided string. Retrieval requires only possession or reuse of that string. Cache entries are not bound to: - An authenticated user or tenant - The identity of `toolFn` - The supplied arguments - A canonical request hash - An expiration time - A maximum cache size In a shared long-lived runtime, two unrelated requests using the same key access the same entry. The second request receives the cached result without executing its requested callback or confirming that its tool and arguments match those associated with the original operation. Consequently, a predictable, reused, or accidentally colliding key can produce cross-request data disclosure or integrity failures. The lack of expiration and capacity controls also permits process memory consumption through many unique keys. ### Attack Path 1. A victim invokes the wrapper in a shared process with an idempotency key and receives a successful result. 2. The wrapper stores that potentially sensitive result in the process-global map. 3. Another caller guesses, learns, reuses, or accidentally selects the same key. 4. The wrapper finds the existing entry before invoking the second caller's `toolFn`. 5. The wrapper returns the victim's cached data to the second caller, regardless of differences ...[truncated 878 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes automatic retries for all external API/tool calls and highlights a 90%+ success boost, but it does not warn that retries can repeat side-effecting operations such as purchases, writes, deletions, or job submissions. In an agent context, this omission is security-relevant because users may wrap non-idempotent tools and unintentionally trigger duplicate actions, especially if they assume the retry wrapper is broadly safe.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

基础用法(零配置)

typescript
const fetchWeather = async (params: { city: string }) => {
  const res = await fetch(`https://api.weather.com/${params.city}`);
  return res.json();
};

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

基础用法(零配置)

typescript
const fetchWeather = async (params: { city: string }) => {
  const res = await fetch(`https://api.weather.com/${params.city}`);
  return res.json();
};

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README includes an example that automatically repairs SQL using an LLM and then retries database execution, without any warning about query drift, privilege abuse, or unintended modification of the original operation. In practice, this can turn a transient syntax error into execution of a semantically different query, which is especially dangerous when an autonomous agent is allowed to modify and rerun database commands.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The natural-language content from the title onward is presented only in Chinese, which effectively forces a specific language for users. The policy allows locale constraints only when the skill offers opt-in or clearly documents a justified region-specific limitation, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains user-facing natural-language content in comments and the skill description exclusively in Chinese, including the identifying description of the skill. The policy requires flagging language or locale constraints when the skill forces a specific language without offering user choice or documenting a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file presents all user-facing documentation in Chinese and does not indicate that language selection is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the stated policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.