Back to skill

Security audit

The Synthetic Context Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent developer context tool, but users should treat its web search and local-file indexing as data-sharing risks they control.

Install only if you are comfortable with a CLI that may query StackOverflow from your task wording and may read source, Markdown, and JSON files from paths you provide. Use --no-web for private work, pass the narrowest --context path you can, avoid indexing folders with secrets or proprietary material you do not want surfaced, and review generated context before handing it to an autonomous coding agent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
src/sources/contextComposer.js:41
Finding

Untrusted Local and Remote Content Is Inserted into AI Context Without Prompt-Injection Controls

Content
View full analysis
50 ? '🔥' : w.score > 10 ? '⭐' : '📗'; const answered = w.isAnswered ? '✅' : '❓'; sections.push(`\n${votes} ${answered} [${w.title}](${w.url})`); sections.push(` Score: ${w.score} | Answers: ${w.answerCount} | Tags: ${w.tags?.slice(0, 3).join(', ')}`); } sections.push(''); } ``` The untrusted values originate from local project files and Stack Overflow: ```javascript const content = fs.readFileSync(fullPath, 'utf-8'); ``` ```javascript const soResponse = await fetch(`${STACKOVERFLOW_API}?${soParams}`); const soData = await soResponse.json(); ``` ### Technical Analysis SCG generates context intended for consumption by an AI coding assistant. Local file contents and remote Stack Overflow metadata are attacker-controllable, but they are inserted into the generated context without sanitization, trust-boundary labels, instruction filtering, or a structured separation between instructions and reference data. Markdown code fences do not constitute a dependable security boundary for language models. A model may interpret natural-language instructions contained in source comments, Markdown files, JSON values, filenames, or remote question titles as ...[truncated 2034 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrases are very broad and map to ordinary user requests such as 'create...' or 'implement...', making unintended activation likely. Because this skill can pull web content and local project context, accidental invocation could expose private code or send sensitive task context to external sources without the user clearly intending to use this skill.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
92% confidence
Finding

The lockfile pins brace-expansion to 2.0.2, and the finding indicates multiple published denial-of-service advisories against that exact version. Because brace-expansion is used transitively by minimatch/glob for pattern handling, attacker-controlled or untrusted glob-style input could trigger excessive CPU or memory consumption and crash or hang the CLI process.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/sources/knowledgeBase.js (reported line 664)May include surrounding context.

js
throw new Error('API_KEY is required');
}

// ✅ Use .env file (add to .gitignore)
// .env:
// API_KEY=sk_live_123456789
// DB_PASSWORD=secret

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README promotes indexing local projects, performing web searches, and learning from user-supplied files, but it does not warn users that sensitive source code, secrets, proprietary data, or personal information may be processed and potentially transmitted to third-party services. In a tool explicitly designed to gather and compose context, this omission increases the risk of accidental data exposure because users may assume all processing is local or privacy-preserving.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says the tool returns StackOverflow solutions and local project context, but it does not clearly warn users that external web search and local data access may occur. This creates a privacy and data exposure risk because users may provide sensitive prompts or run the skill in a proprietary repository without understanding what information may be collected, transmitted, or surfaced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The spec explicitly describes external search against third-party services and a learning mode that ingests error logs and failures, but it provides no warning, consent flow, redaction guidance, or data-handling boundaries. In a context-brokering tool, users may unknowingly transmit source code, secrets, internal paths, or sensitive operational data to external APIs or persist them locally, creating a real privacy and data-leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The CLI sends parsed goal content to a web search source by default unless the user explicitly disables it with --no-web. Goals may contain sensitive internal project details, credentials, incident context, or proprietary information, so default external transmission can cause unintended data disclosure, especially in a tool designed to assemble context from developer tasks.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · src/sources/knowledgeBase.js (reported line 338)May include surrounding context.

js
languages: ['bash'],
    category: 'common-pitfalls',
    title: "DON'T: Run containers as root",
    content: `# ❌ NEVER run as root in production
FROM node:20
WORKDIR /app
COPY . .

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code recursively reads and indexes local project files, including source, markdown, and JSON content, without any consent, disclosure, or scope confirmation at the point of collection. In an agent skill context, that increases the risk of unintentionally exposing sensitive local data such as secrets, proprietary code, credentials in config files, or personal information through later search results or downstream model use.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function claims to auto-index on first use, but it calls the asynchronous indexProject() without awaiting it. Because searchLocal() immediately checks fuse afterward, it can return an empty result set before indexing completes, creating a race condition and unreliable behavior. In a security-sensitive workflow, this can cause missed detections or incomplete local-context retrieval.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/sources/webSearch.js (reported line 6)May include surrounding context.

js
*/

// StackExchange API (no key needed for basic search)
const STACKOVERFLOW_API = 'https://api.stackexchange.com/2.3/search/advanced';

export async function searchWeb(parsed) {
  const results = [];

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The spec includes a hard-coded English-language documentation URL (/en/advanced/...) as the example output, which can imply an English-only default. There is no accompanying language choice, opt-in, or justification for restricting documentation language.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"test": "echo \"No tests yet\" && exit 0"
  },
  "dependencies": {
    "commander": "^11.1.0",
    "fuse.js": "^7.0.0",
    "tiktoken": "^1.0.14",
    "glob": "^10.3.10",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 15)May include surrounding context.

json
},
  "dependencies": {
    "commander": "^11.1.0",
    "fuse.js": "^7.0.0",
    "tiktoken": "^1.0.14",
    "glob": "^10.3.10",
    "dotenv": "^16.3.1"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 16)May include surrounding context.

json
"dependencies": {
    "commander": "^11.1.0",
    "fuse.js": "^7.0.0",
    "tiktoken": "^1.0.14",
    "glob": "^10.3.10",
    "dotenv": "^16.3.1"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 17)May include surrounding context.

json
"commander": "^11.1.0",
    "fuse.js": "^7.0.0",
    "tiktoken": "^1.0.14",
    "glob": "^10.3.10",
    "dotenv": "^16.3.1"
  },
  "keywords": ["ai", "context", "coding", "developer-tools"],

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 18)May include surrounding context.

json
"fuse.js": "^7.0.0",
    "tiktoken": "^1.0.14",
    "glob": "^10.3.10",
    "dotenv": "^16.3.1"
  },
  "keywords": ["ai", "context", "coding", "developer-tools"],
  "license": "MIT"

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code defines goal as a positional argument at L19 and does not register any --goal option, yet the help text printed on missing input says scg --goal "fix auth bug" --context ./myproject. This is an active contradiction between the inline user-facing documentation and the actual behavior of the CLI.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The formatter labels knowledge-base content as either 'python' or 'javascript' based solely on whether the item's languages include Python, defaulting to JavaScript otherwise. This imposes a language choice in generated context rather than offering a neutral or user-selected option, which can violate a language/locale choice policy when content may belong to other languages.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This line repeats the same behavior for recommended-pattern entries, assigning a JavaScript label unless Python is explicitly present. That hardcoded default can misrepresent content and enforces a language assumption without documented opt-in or justification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The comment says the code defaults to 'write' only if no intent is detected. However, because line L10 adds 'write' for broad terms like 'add' or 'make', many non-write requests can still be labeled with 'write' alongside other intents, making the documented behavior misleading about how intent classification actually works.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution, suspicious.env_credential_access, suspicious.exposed_secret_literal

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/sources/knowledgeBase.js:42

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/sources/knowledgeBase.js:131

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/sources/knowledgeBase.js:653