Back to skill

Security audit

summarize

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent summarization CLI wrapper, but users should be aware it relies on an external Homebrew-installed tool and may send submitted content to configured model or extraction providers.

Install this only if you are comfortable with Homebrew installing the third-party summarize CLI and with submitted content being processed by the configured model provider and optional extraction services. Avoid using it on sensitive local files or private URLs unless you have reviewed the provider settings and exposed only the API keys you intend to use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Third-Party Homebrew Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes summarizing URLs and local files but does not warn users that content may be transmitted to external providers and that provider API keys are required. This lack of transparency can lead users to expose sensitive local documents or private URLs without informed consent, particularly since optional fallbacks like Firecrawl and Apify may introduce additional third-party sharing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough to match ordinary requests like asking what a link or video is about, which can cause the skill to activate in situations the user did not explicitly intend. Because this skill can process external URLs and local files through a CLI backed by third-party model providers, overbroad activation raises the risk of unintentional data disclosure or unnecessary external network access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.