Back to skill

Security audit

Debug Framework

Security checks for vulnerabilities and agentic risk

Overview

This frontend debugging skill is coherent and not malicious, but it asks agents to collect and save potentially sensitive diagnostic data without clear redaction or user-control safeguards.

Review this skill before installing if your frontend work involves production traffic, customer data, private APIs, or secrets in headers and environment variables. Use it only with sanitized logs and reports, and redact Authorization, Cookie, API keys, tokens, PII, internal URLs, and sensitive payloads before saving or sharing diagnostic output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 10)May include surrounding context.

md
- ID: `fec-debug-framework`
- Category: `review-quality`
- Version: `2.9.0`
- Source: `skills/fec-debug-framework/SKILL.md`

## Description

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invocation description uses very broad terms such as 'debugging', 'troubleshooting', and 'error reporting', which can cause the skill to activate in many ordinary conversations unrelated to this specific framework. Over-broad triggers increase the chance of unintended invocation, exposing users to unnecessary guidance, workflow hijacking, or misrouting of tasks to this skill when a narrower tool would be more appropriate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to use the skill for a very wide range of issues and includes generic trigger terms like "debugging," "debug," "troubleshooting," and "error reporting." These phrases are common in everyday developer conversation and the file does not provide exclusion conditions or negative examples to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The API debugging steps instruct collection of request URLs, headers, bodies, response data, and cached state, which commonly contain secrets, tokens, session identifiers, PII, or business-sensitive payloads. Without explicit minimization, redaction, or user warning, the skill can lead to unnecessary exposure of sensitive data during debugging and downstream handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description says to use the skill for a wide range of situations and includes generic trigger terms such as "debugging," "debug," "troubleshooting," and "error reporting." These terms are broad enough to match ordinary conversation and the file does not provide explicit constraints or negative examples to narrow when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description uses very broad activation phrases such as debugging, troubleshooting, runtime errors, request failures, and exceptions, which are common across many normal support interactions. In an agent-skill ecosystem, this can cause over-triggering and unintended invocation, expanding the skill's opportunity to influence workflows beyond narrowly intended frontend debugging scenarios.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The template explicitly encourages collecting and persisting diagnostic artifacts such as environment variables and status snapshots, which commonly contain secrets, tokens, internal URLs, or user data. Because the report is then saved to a predictable file path, sensitive information may be unnecessarily retained, shared, or committed without redaction guidance.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

md
## Purpose

Use an evidence-driven triage, collection, hypothesis, verification, and remediation process to locate front-end faults and avoid relying on intuition to expand the scope of changes.

## Procedure

Scope Creep

Low
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 150)May include surrounding context.

md
## Purpose

Use an evidence-driven triage, collection, hypothesis, verification, and remediation process to locate front-end faults and avoid relying on intuition to expand the scope of changes.

## Procedure

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Requiring a diagnostic report to be saved to disk creates a persistence risk because the report may include logs, stack traces, requests, responses, or state snapshots gathered earlier in the process. If sensitive evidence is written unsanitized to local storage, repositories, shared workspaces, or tickets, it increases the chance of credential leakage, privacy exposure, and long-term retention beyond the immediate debugging need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
72% confidence
Finding

The manifest explicitly states that Chinese triggers are included, but it does not indicate that language selection is optional or user-driven. That can be a locale/language policy concern because the skill defines language-specific activation behavior without documenting user choice or a region-specific reason.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.