Back to skill

Security audit

shrimpcard

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent card generator, but it needs Review because it asks agents to mine broad private memory/history for public output and embeds card data into executable HTML unsafely.

Use this only with explicit, user-approved evidence sources. Do not let it scan unrelated memory, past conversations, tool traces, or owner contact details without consent, and review every public field before sharing. Avoid rendering or hosting card JSON from untrusted sources until the HTML data embedding is fixed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/render_card_html.py:291
Finding

Stored JavaScript Injection Through Unsafe Card Data Embedding

Content
View full analysis
str: payload = json.dumps(card_data, ensure_ascii=False, indent=2) script = "\n" marker = "" if marker in template: return template.replace(marker, script) return template.replace("", script + "") ``` ### Technical Analysis The renderer serializes card data with `json.dumps()` and embeds the resulting JSON directly inside an executable HTML `` is interpreted by the HTML parser as the end of the surrounding script element, even when that sequence occurs inside a JavaScript string literal. An attacker can consequently append a new script element containing arbitrary JavaScript. The share-card schema permits general string values and does not reject HTML script terminators. Schema validation therefore does not prevent this attack. Escaping used for statically rendered fields elsewhere in the renderer does not protect the separate `window.__CARD_DATA__` assignment. Example malicious field value: ```html ``` When the card is rendered, the generated output contains the attacker-controlled script. The vulnerability becomes active when a user opens the generated HTML in a browser. ### Attack Path 1. An attacker supplies or influences a share-card JSON string field, such as `name`, `tagline`, `owner.contact`, or anothe ...[truncated 1303 chars]
Remediation
View remediation
``` Serialize the object after applying HTML-safe escaping, then parse it using: ```javascript const card = JSON.parse(document.getElementById("card-data").textContent); ``` 2. At minimum, escape characters significant to the HTML parser before embedding JSON: ```python payload = json.dumps(card_data, ensure_ascii=False, indent=2) payload = ( payload.replace("&", "\\u0026") .replace("<", "\\u003c") .replace(">", "\\u003e") ) ``` Escaping `<` prevents an attacker-controlled `` sequence from terminating the element. 3. Prefer setting visible content through `textContent` or other safe DOM APIs rather than constructing HTML from card values. 4. Add regression tests covering malicious values in every user-controlled string field. Test payloads should include: ```text

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/build_memory_search_prompt.py:23
Finding

Overbroad Collection of Private Agent Memory and Activity Traces

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (39)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The code’s behavior is narrower and materially different from the declared description. It is a post-processing utility for attaching an already-generated image to an existing share-card payload and optionally preserving the prompt text. While it does validate the resulting JSON, it does not transform evidence-backed behavior into a self-intro submission, does not build the full share-card from scratch, and does not render or output any HTML card. It also does not generate an image itself; it only embeds a provided image URL or local file as a data URL. Therefore the declared purpose overstates and misrepresents the actual functionality of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents the skill as performing the end-to-end transformation from evidence-backed behavior into validated deliverables, including JSON, HTML, and a real 8-bit image. However, this code chunk's actual purpose is narrower: it composes a prompt for an agent workflow and writes that prompt to disk. The prompt contains instructions about searching memory, validating outputs, and generating images, but the script itself does not perform those actions. This is a material description-behavior mismatch because the primary capability implemented here is prompt construction/orchestration, not artifact generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description presents a broader end-to-end card-building skill: validated self-intro submission, share-card JSON payload, and final HTML selfie card with a real 8-bit image. The actual code chunk has a narrower purpose: it takes a validated submission and emits a prompt for external image generation. It validates input and writes instructions for an artist/image model, but does not itself render an image, construct HTML, or assemble the share-card payload. Because the primary described outputs are not actually produced by this code chunk, the description materially overstates the implemented behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

There is a material description-behavior mismatch. The declared purpose describes an end-to-end content production skill that outputs finalized self-intro assets, JSON, HTML, and an image-oriented selfie card. The supplied code instead constructs a prompt file for an upstream discovery step: searching memory, extracting repeated evidence, and drafting constrained candidate phrases. The prompt explicitly states 'This step is only for searching and organizing memory' and 'Do not write the final public card yet,' which directly contradicts the declared deliverables. No code here validates a submission, emits share-card JSON, builds HTML, or produces an 8-bit image. Access to agent/owner context JSON and writing a prompt file are consistent with a preparation stage, not the declared final asset-generation behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The implemented script's primary function is prompt construction: it reads evidence JSON, checks that the input is live, composes detailed instructions, and writes those instructions to a text file. While the prompt asks a downstream model to output JSON containing fields like selfie_prompt, the script itself does not generate the final submission artifact, validate it, build HTML, or produce any image. Because the declared description promises end-product creation and validation—including HTML and a real 8-bit character image—while the code only prepares an intermediate prompt, this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a content-generation pipeline that turns evidence into multiple deliverables: a validated self-intro, share-card JSON, and HTML selfie card with an image. The supplied code does none of that. Its actual function is narrowly focused on scanning snapshot/evidence text for brand keywords (OpenClaw, Hermes, Codex) and returning policy-style guidance on whether branding may be used or whether identity should remain neutral. This is a materially different primary purpose, not just an implementation detail, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description promises an end-to-end pipeline that transforms evidence-backed behavior into multiple concrete deliverables: a validated self-intro submission, JSON payload, and HTML selfie card with an actual 8-bit image. This code chunk does not implement those outputs. Instead, it is a support module focused on static style dictionaries and helper functions for selecting role visuals and composing an English/Chinese image-generation prompt. While the prompt builder is related to the 'selfie card' concept, it does not generate HTML, JSON, validation logic, submission artifacts, or an actual image. Therefore the description materially overstates what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description promises a broader end-to-end pipeline: validated self-intro submission creation, share-card JSON generation, and final HTML selfie card creation with a real 8-bit character image. The supplied code chunk performs a narrower task. It reads an already-existing submission JSON, validates it, builds a share-card JSON from selected fields, validates that JSON against a schema, and writes it out. It does not generate the original submission, does not render HTML, and does not create any actual image asset. The presence of image_strategy: "image-gen", selfie_prompt, and placeholder image/QR fields indicates preparation for later stages rather than execution of them. Therefore the code behavior is materially narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a content-generation skill focused on producing a validated self-introduction submission, share-card JSON, and screenshot-friendly HTML with an 8-bit image. The supplied code does none of those things. It only reads local JSON and schema files, validates the JSON structure against the schema, and exits with success or failure. While 'validated' appears in the description, the code does not generate or transform submissions/cards; it merely performs schema validation. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a content-generation workflow: turning evidence-backed behavior into multiple outputs, including a validated self-intro submission, a share-card JSON payload, and final screenshot-friendly HTML with a real 8-bit character image. The code provided does not implement that workflow. Instead, it parses a supplied HTML file and validates that certain preview-only strings, internal markers, and removed UI fragments are absent, and that visible fields are not generic placeholder text. This is a narrow QA/validation utility for already-rendered HTML, not a generator or formatter for self-intros, JSON payloads, or image-backed selfie cards. While validation is mentioned in the description, the overall declared purpose is materially broader and different from the actual behavior of this code chunk.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
- `assets/card-template.html`: final card template

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt explicitly instructs the agent to inspect long-term memory, saved preferences, recent task history, tool-call traces, and owner feedback, then turn those findings into public-facing identity content. That creates a real risk of sensitive data leakage because private or incidental information from memory and traces can be surfaced externally without clear minimization, consent, or field-level filtering.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/build_agent_workflow_prompt.py (reported line 105)May include surrounding context.

python
def main():
    parser = argparse.ArgumentParser(description="Build a workflow prompt that tells an agent to search memory, generate image, and retry until validated")
    parser.add_argument("agent_context_json", help="Path to JSON containing at least agent/owner fields")
    parser.add_argument("--out", default="agent-workflow-prompt.txt", help="Output prompt path")
    parser.add_argument("--lang", choices=["zh", "en"], default="zh", help="Language for final card text")
    args = parser.parse_args()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/build_image_task_prompt.py (reported line 116)May include surrounding context.

python
def main():
    parser = argparse.ArgumentParser(description="Build a workflow prompt that tells an agent to search memory, generate image, and retry until validated")
    parser.add_argument("agent_context_json", help="Path to JSON containing at least agent/owner fields")
    parser.add_argument("--out", default="agent-workflow-prompt.txt", help="Output prompt path")
    parser.add_argument("--lang", choices=["zh", "en"], default="zh", help="Language for final card text")
    args = parser.parse_args()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/build_memory_search_prompt.py (reported line 141)May include surrounding context.

python
def main():
    parser = argparse.ArgumentParser(description="Build a workflow prompt that tells an agent to search memory, generate image, and retry until validated")
    parser.add_argument("agent_context_json", help="Path to JSON containing at least agent/owner fields")
    parser.add_argument("--out", default="agent-workflow-prompt.txt", help="Output prompt path")
    parser.add_argument("--lang", choices=["zh", "en"], default="zh", help="Language for final card text")
    args = parser.parse_args()

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/build_submission_prompt.py (reported line 118)May include surrounding context.

python
def main():
    parser = argparse.ArgumentParser(description="Build a workflow prompt that tells an agent to search memory, generate image, and retry until validated")
    parser.add_argument("agent_context_json", help="Path to JSON containing at least agent/owner fields")
    parser.add_argument("--out", default="agent-workflow-prompt.txt", help="Output prompt path")
    parser.add_argument("--lang", choices=["zh", "en"], default="zh", help="Language for final card text")
    args = parser.parse_args()

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file contains user-facing natural language exclusively in Chinese, and it does not provide any opt-in, alternative language, or justification for a locale-specific restriction. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to install dependencies and run multiple local scripts, yet it declares no tool scope or permission boundaries. In an agent environment, undeclared access to file, environment, and possible network capabilities increases the chance of over-broad execution, unintended data access, or misuse of external connectivity without clear operator consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This JSON manifest-like file describes the agent as a "self-improving autonomous agent with persistent memory and multi-platform reach" and "terminal-native agent with messaging gateway," but provides no specific invocation boundaries, trigger phrases, or negative examples. In a manifest-scope file, such broad natural-language positioning can contribute to ambiguous activation expectations and unintended invocation in common contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The evidence summaries state that the agent builds a model of the user across sessions, automatically loads project context files, and operates through messaging platforms, all of which can affect user data and privacy. In a non-code descriptive file, the absence of any warning or disclosure about retention, context ingestion, or transmission surfaces is a missing user warning under the markdown/description-style criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language fields in the identity block are written in Chinese, including role, tagline, value proposition, capabilities, and sharing text, while the surrounding manifest is otherwise in English. This creates an implicit language/locale constraint without any opt-in, alternative language option, or documented region-specific justification, which matches the policy-violation criteria for language or locale restrictions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generated instructions require all public-facing card text to be either Chinese only or English only, based solely on the provided lang parameter. This is a natural-language locale policy constraint that does not offer user choice within the prompt and may exclude other user languages without documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The language instruction hard-codes 'Chinese only' for zh and 'English only' otherwise, and the generated prompt later presents this as a mandatory language rule. This is a natural-language locale policy constraint without any in-skill user choice or opt-in mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The --lang argument defaults to 'zh', so unless an operator overrides it, the prompt will instruct the agent to write candidate phrases in Chinese only. That creates a default locale policy that is not tied to explicit user opt-in in this file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The generated instruction says to write every final public-facing field in Chinese only or English only and forbids mixed-language output. Because the skill does not present this as a user-selectable preference inside the prompt itself, it imposes a language policy that may override user needs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.