Back to skill

Security audit

FullStack Developer

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only full-stack development guidance skill whose broad app-building and deployment advice is disclosed and aligned with its stated purpose.

This skill is reasonable to install if you want broad full-stack application guidance. Expect it to influence stack choices, app structure, CI/CD, auth, and production-readiness recommendations; review any generated deployment workflows, secrets handling, and production automation before running or merging them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s trigger text is intentionally very broad, covering generic requests like building apps, websites, tools, APIs, and end-to-end systems. That can cause over-invocation of a powerful development skill in situations where a narrower or more specialized skill would be safer or more appropriate, increasing the chance of unnecessary code generation, scope overreach, or bypass of more constrained workflows.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api-design.md (reported line 33)May include surrounding context.

POST /users # create GET /users/{id} # read one PATCH /users/{id} # partial update DELETE /users/{id} # delete

GET /users/{id}/orders # sub-resource list

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/authentication.md (reported line 92)May include surrounding context.

md
- Short `Max-Age` for session cookies; rotate on privilege changes

### Refresh tokens
Access token (short-lived, 5–15 min) + refresh token (long-lived, 30–90 days).
- Store refresh tokens server-side so you can revoke them.
- Rotate refresh tokens on use (one-time-use) — detects token theft.
- On detected reuse, revoke the whole session family.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/authentication.md (reported line 78)May include surrounding context.

md
- [ ] Login failures return a generic error ("invalid credentials"), not "user not found."
- [ ] Rate limit on login, signup, password reset, and any other auth-adjacent endpoint.
- [ ] MFA available for accounts (TOTP minimum); required for admin accounts.
- [ ] Sessions expire. Long sessions via refresh tokens, not long-lived access tokens.
- [ ] Logout actually invalidates the server-side session.
- [ ] Force logout on password change, email change, and role change.
- [ ] Suspicious-login notifications (new device/IP) sent to user.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/security-checklist.md (reported line 10)May include surrounding context.

md
- [ ] Login failures return a generic error ("invalid credentials"), not "user not found."
- [ ] Rate limit on login, signup, password reset, and any other auth-adjacent endpoint.
- [ ] MFA available for accounts (TOTP minimum); required for admin accounts.
- [ ] Sessions expire. Long sessions via refresh tokens, not long-lived access tokens.
- [ ] Logout actually invalidates the server-side session.
- [ ] Force logout on password change, email change, and role change.
- [ ] Suspicious-login notifications (new device/IP) sent to user.

Cloud Metadata Access

High
Category
Server-Side Request Forgery
Confidence
90% confidence
Finding

Code accesses a cloud instance metadata endpoint (e.g. 169.254.169.254). A single request can return temporary IAM credentials, making this a high-value SSRF target for credential theft.

Content

Scanner excerpt · references/security-checklist.md (reported line 27)May include surrounding context.

md
- [ ] All DB queries use parameterized queries / ORM. No string-concatenated SQL. Ever.
- [ ] HTML output is escaped by default (React/Vue/Svelte do this; `dangerouslySetInnerHTML` is audited).
- [ ] File uploads: validate MIME and extension, cap size, scan for malware for user-facing files, store outside the webroot (e.g., S3), serve via signed URLs or a handler that enforces access.
- [ ] User-supplied URLs (avatars, embeds) fetched from the server go through SSRF protection — block RFC1918 IPs, cloud metadata endpoints (169.254.169.254), localhost.
- [ ] Command execution or `eval`-adjacent functions do NOT take user input. If they must, whitelist with extreme prejudice.

## Secrets management

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/deployment-cicd.md (reported line 3)May include surrounding context.

md
# Deployment & CI/CD

How to get the app from "works on my machine" to "running in production, auto-deployed, observable."

## Choosing a deployment target

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/deployment-cicd.md (reported line 160)May include surrounding context.

md
# Deployment & CI/CD

How to get the app from "works on my machine" to "running in production, auto-deployed, observable."

## Choosing a deployment target

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/deployment-cicd.md (reported line 160)May include surrounding context.

md
## CD: deployment strategies

### Continuous deployment to staging
Every merge to `main` → auto-deploy to staging. No approval. Fast feedback, confidence from seeing it run.

### Production deployment
Pick one:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/deployment-cicd.md (reported line 164)May include surrounding context.

md
### Production deployment
Pick one:
- **Auto-deploy `main` to prod** — fine for small teams and mature test coverage.
- **Tag to deploy** — merge to `main` goes to staging; creating a git tag triggers prod. Forces a human to "press the button."
- **Manual approval** — GitHub Actions environments support required reviewers.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This is a natural-language policy concern because it imposes a specific standard as the default rather than presenting it as context-dependent guidance. The rule allows documented and justified constraints, but this line states a default broadly for anything public-facing without clarifying whether exceptions or user choice exist.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.