Back to skill

Security audit

Rtk Token Saver

Security checks for vulnerabilities and agentic risk

Overview

The skill is a transparent developer-tool workflow for reducing noisy command output, with no bundled executable code or hidden install behavior.

Before using this skill, make sure the local rtk CLI itself is a trusted tool, especially before wrapping commands that may involve credentials or high-impact systems. Use native commands when exact output is needed or when handling secrets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
80% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

rtk log path/to/app.log

text

Use raw output only when full logs are required for auditing, exact reproduction, or external attachment.

## Workflow

Static analysis

No suspicious patterns detected.