Back to skill

Security audit

Platonic Coding

Security checks for vulnerabilities and agentic risk

Overview

This looks like a legitimate spec-driven coding workflow, but it should be reviewed because repository configuration can steer file-writing workflows without clear path confinement.

Review `.platonic.yml` before using this skill, especially the specs, impl, and drafts paths. Keep those paths relative to the project, avoid running write-capable modes on untrusted repositories without checking the plan, and only use auto-mode or "no confirmations" when you are comfortable with the proposed file changes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/WORKFLOW/workflow-overview.md:33
Finding

Configuration-Derived Paths Are Not Confined to the Project Root

Content
View full analysis
/.platonic.yml` 4. **Skip if file already exists** (read existing config instead) ### Step 3: Create Specs Directory 1. Create `/` directory 2. Read and process RFC infrastructure templates from `assets/templates/`: - `template-rfc-standard.md` → `rfc-st ...[truncated 6237 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The skill allows confirmation gates to be bypassed with a 'no confirmations' override while supporting implementation actions that generate guides, code, and tests. Because this is an orchestrator with auto-detection and write capabilities, reducing human approval can enable autonomous code and file modifications that the user did not adequately review, especially if the user's request is ambiguous or prompt-injected through surrounding context.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
### IMPL Mode
Translate RFCs to guides and code. Operations: `impl-full` (default), `impl-create-guide`, `impl-code`, `impl-validate-guide`, `impl-update-guide`.

**Confirmation Gates**: Pauses after impl guide and coding plan. Override with "no confirmations".

**Examples**: `impl-full for RFC-042`, `impl-code from IG-001`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill explicitly states it has read/write access to project directories, but it does not prominently warn users that invoking the skill may create or modify files across the repository. In a workflow orchestration skill that can scaffold, recover, implement, and update artifacts, this omission can lead to unexpected filesystem changes and increases the risk of accidental destructive edits or silent workspace modification.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill allows confirmation gates to be skipped via auto-mode or "no confirmations," enabling the agent to move from design into planning and implementation without a human approval checkpoint. In a coding skill that can alter code and tests, this increases the chance of autonomous, potentially incorrect or overbroad modifications to a live repository.

Content

Scanner excerpt · references/IMPL/impl-full.md (reported line 35)May include surrounding context.

md
### Step 2: Impl Guide Design
Create implementation guide (follow `create-guide.md`). Output: module structure, type definitions, interface signatures, error handling, testing strategy.

**Confirmation Gate**: Present summary (module structure, key types, design decisions). Skip if auto-mode or "no confirmations".

### Step 3: Coding Plan
Break into ordered tasks: one file per task, dependency order, test pairing. Use `assets/coding-plan-template.md`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This workflow explicitly proceeds to generate source code and tests, but it does not clearly warn that running the step may modify repository files. In an agentic context, that omission can cause users to trigger write operations without informed consent, increasing the risk of unintended code changes, test artifacts, or disruptive edits to an existing codebase.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/IMPL/impl-update-guide.md (reported line 75)May include surrounding context.

Step 5: Document Changes

Add entry to guide's revision history (if present) or create one:

markdown
## Revision History

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The phrase 'say "no confirmations" to skip' encourages autonomous progression past an interaction gate, reducing human oversight over subsequent workflow decisions. Because this skill is an intelligent orchestrator for initialization, recovery, specification, implementation, and review, bypassing confirmations can let the system choose and continue impactful operations with insufficient user validation.

Content

Scanner excerpt · references/REFERENCE.md (reported line 143)May include surrounding context.

md
| Specs not in index | Check `RFC-NNN-<name>.md` naming, run `specs-generate-index` |
| Missing terminology | Check term format in RFCs, run `specs-generate-namings` |
| Missing code refs in review | Use specific search terms, check naming conventions |
| Workflow stops at gate | Expected—say "no confirmations" to skip |

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly tells the operator to use a phrase to bypass a workflow gate ('no confirmations') without explaining what protections are being skipped or requiring any authorization check. In an orchestration skill that auto-detects state and routes multi-step project operations, this lowers safety barriers and can cause the agent to proceed with actions the user did not meaningfully confirm.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to update multiple files (rfc-history.md, rfc-index.md, and rfc-namings.md) but does not clearly warn the user at the point of use that this operation is file-modifying. In an agent workflow, implicit write behavior can lead to unintended repository changes, especially when invoked as part of a larger orchestration flow where the user may expect validation-only behavior from earlier steps.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This markdown file describes the skill's purpose and behavior but does not specify when it should be invoked versus when similar document-review tasks should not use it. Under SQP-1, markdown files should avoid ambiguous activation scope, and the absence of explicit trigger boundaries can lead to unintended use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill instructs updating multiple project tracking documents after generating the draft RFC, but it does not require an explicit warning or confirmation that several files will be modified. In an agent workflow, this can lead to unexpected repository changes outside the user's immediate intent, especially when the user only asked to review or draft a spec.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

L25 says version numbers come from filenames ending in a '', but the file's own examples use numeric version suffixes such as RFC-001-world-view-001.md at L16 and version 001 at L75. This is an internal intent/documentation contradiction that could cause an implementer to parse the wrong version format.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file explicitly instructs the skill to update rfc-history.md, replace a document section, and update metadata fields. While it says to preserve other sections, it does not warn the user that running the skill will rewrite file contents and could overwrite manually maintained history within the targeted section.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

L57 defines versioned RFCs as RFC-NNN-<name>-<letter>.md, but the earlier examples at L16 and output example at L75 use numeric suffixes like -001.md. This is an active contradiction in the skill documentation about what files should be treated as versioned RFCs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.