Back to skill

Security audit

visitor-identification

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent, disclosed website visitor identification integration with consent and deploy approval controls, but users should understand the third-party tracking and usage-based billing before installing.

Install only if you intend to add company-level visitor tracking to a Cargo-hosted site. Before deploy, confirm the privacy disclosure, legal/consent requirements, Snitcher pricing, current credit balance, and the generated Cargo plan; remove the env token or companies model later to stop collection or billing as documented.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
5. **Plan, then stop.** `node --import tsx evals/contract.mjs` from this skill's folder, then

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
5. **Plan, then stop.** `node --import tsx evals/contract.mjs` from this skill's folder, then

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
5. **Plan, then stop.** `node --import tsx evals/contract.mjs` from this skill's folder, then

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
- **Nothing loads before an explicit accept.** (`site/components/visitor-consent.tsx`) Snitcher's

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill references capabilities that can access environment-derived configuration and operational state, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an implicit trust boundary: an agent following the skill could invoke CLI commands that read sensitive workspace metadata, connection details, or env-backed tokens without the user having granted narrowly scoped access.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
**Derive before you ask.** An input with a lookup is looked up, not asked.

| Input                                                    | Kind    | How it is answered                                                                                         | Why it matters                                                                                                          |
| -------------------------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| site URL (`infra/models/companies.ts`)                   | derived | the website app's `site.json` `canonicalUrl`, which must be HTTPS and the site `ready`                     | Snitcher provisions a workspace for this exact origin, and the gate only runs on it. Changing it later starts over.    |
| Snitcher connection (`infra/connectors/snitcher.ts`)     | derived | `cargo-ai connection connector list`: the workspace's default Snitcher connection, on Cargo's credits      | The managed path provisions the tracker. A workspace's own Snitcher key provisions nothing and needs a different setup. |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
**Derive before you ask.** An input with a lookup is looked up, not asked.

| Input                                                    | Kind    | How it is answered                                                                                         | Why it matters                                                                                                          |
| -------------------------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| site URL (`infra/models/companies.ts`)                   | derived | the website app's `site.json` `canonicalUrl`, which must be HTTPS and the site `ready`                     | Snitcher provisions a workspace for this exact origin, and the gate only runs on it. Changing it later starts over.    |
| Snitcher connection (`infra/connectors/snitcher.ts`)     | derived | `cargo-ai connection connector list`: the workspace's default Snitcher connection, on Cargo's credits      | The managed path provisions the tracker. A workspace's own Snitcher key provisions nothing and needs a different setup. |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
**Derive before you ask.** An input with a lookup is looked up, not asked.

| Input                                                    | Kind    | How it is answered                                                                                         | Why it matters                                                                                                          |
| -------------------------------------------------------- | ------- | ---------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- |
| site URL (`infra/models/companies.ts`)                   | derived | the website app's `site.json` `canonicalUrl`, which must be HTTPS and the site `ready`                     | Snitcher provisions a workspace for this exact origin, and the gate only runs on it. Changing it later starts over.    |
| Snitcher connection (`infra/connectors/snitcher.ts`)     | derived | `cargo-ai connection connector list`: the workspace's default Snitcher connection, on Cargo's credits      | The managed path provisions the tracker. A workspace's own Snitcher key provisions nothing and needs a different setup. |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
The code is a worked example. These reshapes are expected, and the agent offers them rather than
waiting to be asked. Every one costs something.

| Variation         | When it is right                                          | How                                                                                                                   | What it costs                                                                                         |
| ----------------- | --------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| `existing-cmp`    | The site already runs a consent management platform       | Call `loadSnitcher` from the CMP's grant event and its deny path from revocation, instead of rendering the gate      | The same behaviour has to be re-tested against the CMP's events, including withdrawal.                |
| `scoring-input`   | Visits should move an account's score                     | Read the companies model from `account-scoring` and weight recency and pages read                                     | A score that leans on visits favours companies with more staff online, not more intent.               |

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · site/lib/visitors.ts (reported line 11)May include surrounding context.

ts
privacyPolicyUrl: string;
};

// Read at build time by app/layout.tsx. `null` renders no consent gate, so a
// draft site, a preview, or a build without the snippet loads nothing: there
// is no profile ID in the export to load it with.
//

Static analysis

No suspicious patterns detected.