Back to skill

Security audit

Autoscaling Policy Designer

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent autoscaling design guide, but it includes live cloud scaling mutation commands without clear safety gates or warnings.

Review this skill before installing if your agent can run cloud or Kubernetes commands. Use it for analysis and configuration drafting, but require explicit approval before any aws autoscaling put-* command, replace plaintext broker credentials with Kubernetes Secrets or KEDA TriggerAuthentication, and confirm the target account, cluster, namespace, and rollback plan before applying changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

bash
# Kubernetes: Get CPU/memory utilization over 7 days from Prometheus
curl -s "$PROMETHEUS_URL/api/v1/query_range" \
  --data-urlencode 'query=avg(rate(container_cpu_usage_seconds_total{namespace="production",pod=~"api-.*"}[5m])) by (pod)' \
  --data-urlencode "start=$(date -d '7 days ago' +%s)" \
  --data-urlencode "end=$(date +%s)" \

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

bash
# Get requests per second over 7 days
curl -s "$PROMETHEUS_URL/api/v1/query_range" \
  --data-urlencode 'query=sum(rate(http_requests_total{namespace="production",service="api"}[5m]))' \
  --data-urlencode "start=$(date -d '7 days ago' +%s)" \
  --data-urlencode "end=$(date +%s)" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

bash
# Kubernetes: Get CPU/memory utilization over 7 days from Prometheus
curl -s "$PROMETHEUS_URL/api/v1/query_range" \
  --data-urlencode 'query=avg(rate(container_cpu_usage_seconds_total{namespace="production",pod=~"api-.*"}[5m])) by (pod)' \
  --data-urlencode "start=$(date -d '7 days ago' +%s)" \
  --data-urlencode "end=$(date +%s)" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

bash
# Get requests per second over 7 days
curl -s "$PROMETHEUS_URL/api/v1/query_range" \
  --data-urlencode 'query=sum(rate(http_requests_total{namespace="production",service="api"}[5m]))' \
  --data-urlencode "start=$(date -d '7 days ago' +%s)" \
  --data-urlencode "end=$(date +%s)" \

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The KEDA RabbitMQ trigger example embeds plaintext credentials directly in the AMQP URL. This encourages secret leakage into skill outputs, logs, shell history, version control, and downstream automation, and could grant direct broker access if copied into a real environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill provides AWS commands that immediately modify scaling behavior without a prominent warning that they affect live infrastructure. That omission is dangerous in an agent context because users may treat generated shell snippets as safe diagnostics and inadvertently alter production capacity or availability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as a policy design aid, but it includes AWS CLI commands that directly create and modify live autoscaling and scheduled scaling policies. In an agent setting, this scope expansion is risky because a user may expect advisory output while the agent performs infrastructure mutations against production resources.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The AWS autoscaling commands mutate cloud configuration by writing scaling policies and scheduled actions, which exceeds a pure design function. In agent workflows, blending recommendation and execution increases the chance of unintended production changes, especially if run with elevated cloud credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown skill instructs the agent to collect historical utilization data from Prometheus and CloudWatch, which can expose service names, namespace details, and production workload telemetry. The document does not include any warning or disclosure that these commands query live production observability systems or may surface sensitive operational information.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest frames the skill as a policy designer based on traffic patterns, costs, and SLOs. While some metrics collection is expected, these commands directly query Kubernetes cluster APIs and operational state to validate deployed infrastructure, moving beyond pure policy design into live environment inspection and readiness checking.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.