Back to skill

Security audit

Cool Agent Tools

Security checks for vulnerabilities and agentic risk

Overview

This skill is an operations command cheat sheet, but it gives agents broad destructive commands without clear confirmation or scope limits.

Install only if you want an agent to help with real system administration commands. Before use, require explicit approval for deletion, process termination, background jobs, and external network checks, and run it with the least OS permissions needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:76
Finding

Unsafe Broad-Scope Process Termination and Log Deletion Instructions

Content
View full analysis
` | Kill processes by name | | `pgrep -f ` | Find process PIDs | | `kill -9 ` | Forcefully terminate a process | | `nohup &` | Run a command in the background | ``` ```bash # Delete old logs, retaining the most recent seven days find /var/log -name "*.log" -mtime +7 -delete # Find the largest directories at depth two du -h --max-depth=2 / | sort -hr | head -20 # Kill all processes named Python pkill -f python ``` The usage guidance also maps a log-cleanup request directly to a destructive command: ```markdown - "Clean logs older than seven days" → execute `find ... -mtime +7 -delete` ``` ### Technical Analysis The Skill recommends commands that can delete files or terminate processes without requiring a preview, explicit confirmation, scope validation, privilege validation, or a recovery mechanism. `pkill -f python` matches against complete process command lines. It can therefore terminate unrelated Python applications, administrative scripts, monitoring agents, or other users' workloads rather than only the process intended by the user. The documented `kill -9` command immediately issues `SIGKILL`, preventing the target process from performing graceful shutdown, releasing resources, or flushing buffered data. The command targeting `/var/log` recursively deletes every matching `.log` file older than seven days within the invoking account's permissions. It does not restrict deletion to a specific application, verify that files are inactive, produce a reviewable manifest, or preserve security and audit records. If the Agent runs with elevated privileges, the deletion scope can include system-wide logs. `nohup &` additionally permits an arbitrary command to continue after the interac ...[truncated 2156 chars]
Remediation
View remediation
&` guidance with an allowlisted execution mechanism that records the command, PID, owner, logs, timeout, and cleanup procedure. 10. Apply least privilege so the Agent cannot alter system-wide logs or processes unless the task specifically requires that access. 11. Add guardrails requiring a dry run, affected-resource summary, scope check, and rollback or recovery plan before destructive operations. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill documents commands like file deletion and forceful process termination without warnings, dry-run guidance, or confirmation requirements. An agent using these examples could delete logs needed for forensics or kill critical services, causing outages or destroying evidence.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states it needs no special trigger and can be invoked directly during system analysis or operations tasks, which gives it extremely broad activation scope. Because the skill includes destructive and externally communicating commands, this can cause an agent to run risky actions without explicit user authorization or contextual safety checks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

Commands such as curl and ping initiate outbound network traffic, but the skill does not warn that they contact external hosts and may leak system metadata such as source IP, headers, DNS queries, or timing information. In sensitive environments, an agent could unintentionally probe external infrastructure or violate network policy.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The inclusion of nohup <cmd> & enables commands to persist after the interactive session ends, which can outlive the user's oversight and continue consuming resources or performing actions. In an agent skill with broad activation, this increases the risk of unattended long-running processes or persistence-like behavior.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
| `pkill <name>` | 按名称杀死进程 |
| `pgrep -f <name>` | 查找进程 PID |
| `kill -9 <pid>` | 强制终止进程 |
| `nohup <cmd> &` | 后台运行(断开 SSH 仍保持) |

### 🛠️ Git 操作

Static analysis

No suspicious patterns detected.