Back to skill

Security audit

Safe Change

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but its verification script runs project-defined commands while claiming read-only behavior.

Install only if you are comfortable with a coding skill that can run your repository's typecheck, lint, test, and build scripts. Use it in a workspace without secrets or untrusted package scripts, and review verify-gate.sh before allowing it to run.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a blast-radius analysis tool, but it also instructs the agent to execute verify-gate.sh, which in turn runs tsc, lint, tests, and build commands from the target repository. That behavior materially expands from passive analysis into active execution of project-defined commands, which can trigger arbitrary code in scripts, test hooks, build steps, or package tooling, creating a meaningful code-execution and supply-chain risk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
| About to edit a shared service | → Run `scan-impact.mjs` on the target file first |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
| About to edit a shared service | → Run `scan-impact.mjs` on the target file first |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
| About to edit a shared service | → Run `scan-impact.mjs` on the target file first |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
| About to edit a shared service | → Run `scan-impact.mjs` on the target file first |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
| About to edit a shared service | → Run `scan-impact.mjs` on the target file first |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/banner.svg (reported line 13)May include surrounding context.

text
</linearGradient>
  </defs>

  <!-- Background -->
  <rect width="1200" height="630" fill="url(#bg)"/>

  <!-- Subtle grid -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · assets/banner.svg (reported line 49)May include surrounding context.

text
<!-- Accent line -->
  <rect x="480" y="330" width="240" height="4" rx="2" fill="url(#accent)"/>

  <!-- Subtitle -->
  <text x="600" y="390" text-anchor="middle" font-family="-apple-system, BlinkMacSystemFont, 'Segoe UI', sans-serif" font-size="24" fill="#94a3b8">Map blast radius before you ship</text>

  <!-- Tags -->

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/example-impact-report.md (reported line 115)May include surrounding context.

md
- SMTP_USER — update to Resend API key (username format differs)
- SMTP_PASS — update to Resend API key value

All three ENV vars must be rotated in Railway (production) and .env.local
before deploying.

### Recent Migrations (last 7 days)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's implemented behavior is a verification gate that runs project commands, which does not align with the advertised skill purpose of mapping blast radius and impact surfaces. This mismatch is dangerous because users may invoke the skill expecting passive analysis, but instead trigger active command execution in an untrusted repository.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script executes repository-controlled commands such as npm run lint, npm test, and npm run build, and does so through eval, which expands shell metacharacters and increases execution risk. In the context of a supposedly 'safe-change' mapping skill, this enables arbitrary code execution from package.json scripts or local toolchain wrappers in an untrusted project.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs the agent to inspect package.json, scan source files for process.env references, and run shell scripts, but it declares no explicit tool scope or allowed-tools boundary. Without a declared permission model, an agent may over-broaden what it reads or executes, increasing the chance of unintended access to environment-related data or unsafe command execution during normal use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment states the script is read-only, but the script runs build, test, lint, and compiler commands that may write files, run hooks, contact the network, or execute arbitrary lifecycle logic. This misleading safety claim increases the chance that users will run the script in environments where they would otherwise avoid code execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code mixes German-only explanatory comments and English-only CLI help/output text, which reflects a fixed language choice rather than offering a user-selectable locale. The policy explicitly calls for flagging language or locale constraints when they are imposed without user opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file contains natural-language comments in German ('Fuehrt tsc → lint → test → build in Reihenfolge aus', 'Stoppt beim ersten Fehler') while the rest of the interface/help text is largely English. This imposes a mixed but partially fixed language choice without any opt-in or explanation of a region-specific requirement, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.