Back to skill

Security audit

Tech Debt Scanner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward technical-debt scanner with some disclosure gaps around dependency checks that may contact package registries.

Before installing, understand that dependency checks may reveal package names or environment package information to package registries if those commands are run. Use a scoped subdirectory for large or sensitive repositories, and avoid the dependency command in offline or restricted-network environments unless that access is acceptable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The deps command says it will show 'Packages with known vulnerabilities (npm audit / pip-audit if available),' but the provided Step 5 implementation only runs npm outdated, scans package.json for a hardcoded deprecated-package list, prints requirements.txt, runs pip list --outdated, and counts lines in go.sum. No vulnerability audit command is actually present. This is an active mismatch between declared behavior and documented implementation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill claims it 'does not execute code or install dependencies — static analysis only,' but Step 5 runs commands like npm outdated and pip list --outdated, which can contact package indexes and inspect the live environment. This mismatch is dangerous because operators may run the skill in sensitive or offline environments believing it is purely local/static, causing unintended network access, metadata leakage, or policy violations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.