Back to skill

Security audit

Init Rules

Security checks for vulnerabilities and agentic risk

Overview

This skill has a clear purpose, but it asks the agent to run an unspecified setup script from an unpinned external dependency while changing persistent agent rules.

Review this skill before installing. It is not evidence of malware, but only use it if you trust the Skill Genie dependency, can verify which setup.sh will run, and are comfortable with persistent rules that may change future agent behavior. Prefer confirming the resolved script path and reviewing existing rules before allowing the directory replacement or setup step.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:4
Finding

Unpinned External Dependency and Unspecified Setup Script Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:4,10,63
Vulnerability Type: Unpinned third-party dependency and ambiguous external script execution
Risk Level: Medium

Complete Code Snippet

yaml
requires: "Fei2-Labs/skill-genie"
markdown
> **Requires [Skill Genie](https://github.com/Fei2-Labs/skill-genie)**. This skill generates rule files for the skill-genie `rules/` directory. Install skill-genie first, then run this skill.
markdown
Then run `setup.sh` to apply them.

Technical Analysis

The skill identifies its dependency only by a mutable GitHub repository name. It does not pin a reviewed release or immutable commit, verify the integrity of downloaded artifacts, or establish a trusted installation path.

It subsequently instructs the agent to execute setup.sh without specifying an absolute or repository-relative path. The audited project does not contain that script, so neither its contents nor its security properties can be verified from the supplied package. The effective executable may vary according to the installed dependency revision and command-resolution context.

Although installing a prerequisite and running its setup script can be legitimate, this design crosses a supply-chain execution boundary without sufficient provenance, integrity, or path controls.

Attack Path

  1. The user or agent installs or updates the mutable Fei2-Labs/skill-genie dependency.
  2. An attacker compromises the upstream repository or distribution path, or causes a malicious setup.sh to be selected from the effective working directory.
  3. The user invokes this skill.
  4. The skill follows its documented process and runs the unresolved setup.sh.
  5. The malicious script executes with the permissions of the agent or user running the skill.

This path depends on compromise or substitution of an external component; no malicious script is embedded in the audited project itself.

Impact Assessment

Successful exploitatio ...[truncated 573 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin Skill Genie to a reviewed release or immutable commit hash rather than a mutable repository reference.
  2. Verify downloaded artifacts using a trusted checksum or signature.
  3. Document the expected installation directory and invoke the script through an explicit trusted path, such as ./skill-genie/setup.sh.
  4. Confirm that the resolved script is a regular file inside the expected dependency directory and reject symlinks or paths outside that directory where appropriate.
  5. Review and disclose the script's behavior and required permissions before execution.
  6. Display the exact command and resolved path, then require explicit user approval before running it.
  7. Execute the setup process with least privilege and in a restricted environment when practical.
  8. Prefer implementing the narrowly required rule-application behavior directly through reviewed operations rather than automatically executing an unspecified external script.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
Ask the user these questions ONE AT A TIME. After each answer, move to the next. Skip questions the user says aren't relevant.

### 1. Work style
- "How should I behave? (e.g., execute without asking, ask before acting, explain reasoning, be concise)"

### 2. Tech stack
- "What's your default tech stack? (e.g., Nuxt + Appwrite, Next.js + Supabase, Rails, Swift/macOS, none)"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
Ask the user these questions ONE AT A TIME. After each answer, move to the next. Skip questions the user says aren't relevant.

### 1. Work style
- "How should I behave? (e.g., execute without asking, ask before acting, explain reasoning, be concise)"

### 2. Tech stack
- "What's your default tech stack? (e.g., Nuxt + Appwrite, Next.js + Supabase, Rails, Swift/macOS, none)"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to move the entire rules/ directory and recreate it, which is a destructive filesystem operation if interrupted, mis-targeted, or run in the wrong working directory. Because the skill provides no explicit requirement to preview affected files, confirm with the user, or validate the path first, it increases the risk of accidental data loss during normal use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to run setup.sh causes arbitrary shell script execution with no warning, inspection step, or consent gate. In a skill that writes files and operates on local directories, automatically invoking a script materially raises the risk of unintended command execution, persistence changes, or broader system modification if the script is unsafe or unexpected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.