Back to skill

Security audit

Fullstack Developer

Security checks for vulnerabilities and agentic risk

Overview

This is a broad full-stack development guidance skill with no executable code, persistence, credential access, or hidden runtime behavior.

Before installing, consider that this skill is intentionally broad and may influence most web-application development tasks. Its guidance is conventional and disclosed, but users who prefer narrower task routing may want a more specialized skill for specific frameworks or domains.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description explicitly says to use this skill for 'ANY web application' and for broad actions like build, fix, review, architect, or debug. That trigger scope is so broad that it can activate on a large fraction of normal developer requests, increasing the chance the skill overrides more specific safety-reviewed skills or captures unrelated tasks with higher-risk tool usage.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
GET    /api/v1/users/:id      → Get single user
PUT    /api/v1/users/:id      → Full update
PATCH  /api/v1/users/:id      → Partial update
DELETE /api/v1/users/:id      → Soft delete (set deleted_at)

Always version your APIs: /api/v1/...
Always return consistent response shape:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 354)May include surrounding context.

│ ├── services/ # Business logic (not React-specific) │ └── types/ # TypeScript types ├── prisma/schema.prisma ├── .env.local └── docker-compose.yml

text

Static analysis

No suspicious patterns detected.