Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md node scripts/fieldfix.js machines
Security audit
Security checks for vulnerabilities and agentic risk
The skill is not malicious, but it should be reviewed because it can immediately change fleet service, expense, and hour-meter records using your FieldFix API key.
Install only if you trust FieldFix with this API key and are comfortable with an agent being able to create or update fleet records. Prefer a limited-scope API key if FieldFix supports one, and require the agent to preview and get explicit confirmation before running log-service, log-expense, or update-hours.
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
Referenced artifact was not completely inspected
node scripts/fieldfix.js machines
The skill advertises use of an API key via environment variable and remote API access, but it declares no explicit tool scope or permission boundaries. That makes it easier for an agent runtime to grant broader-than-necessary access to environment data and network actions, increasing the risk of secret exposure or unintended outbound requests if the skill or its implementation is ever misused.
The documentation includes state-changing operations like logging service, logging expenses, and updating hour meters, but provides no warning, confirmation, or approval guidance before performing those actions. In an agent setting, this can lead to unauthorized or mistaken record changes, corrupt maintenance history, or fraudulent expense entries if the model acts on ambiguous user input.
The CLI includes state-changing operations (log-service, log-expense, and update-hours) that execute immediately with the user's API key and no confirmation, dry-run, or explicit warning. In an agent or automation context, a mistaken invocation, prompt-influenced action, or malformed parameter can silently modify fleet records, maintenance logs, expenses, or hour meters, causing integrity and operational issues.
This manifest file says the skill can 'Query and manage your heavy equipment fleet' but does not specify what phrases, contexts, or constraints should activate the skill. In a manifest, such broad capability language can contribute to ambiguous invocation scope if used by a dispatcher or router.
Detected: suspicious.env_credential_access