Back to skill

Security audit

AetherLang

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clearly disclosed API connector that sends only user flow/query text to an external service and does not install code, request credentials, or add persistence.

Install only if you are comfortable sending the specific flow DSL and query text you provide to api.neurodoc.app. Do not include secrets, credentials, private files, personal data, or confidential business information in prompts sent through this skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill is explicitly an API connector and declares an external endpoint, meaning user-supplied flow code and query text are transmitted to a third-party service outside the local trust boundary. Even with disclosure and data-minimization language, this creates privacy and data-governance risk if users submit sensitive content or if the remote service mishandles data.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
metadata:
  skill_type: api_connector
  external_endpoints:
    - https://api.neurodoc.app/aetherlang/execute
  operator_note: "api.neurodoc.app operated by NeuroDoc Pro (same as masterswarm.net), Hetzner DE"
  privacy_policy: https://masterswarm.net
license: MIT

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The documented POST endpoint operationalizes external data transmission to api.neurodoc.app, so any invocation sends user content off-platform for processing. In this skill's context, the danger is not hidden exfiltration but the inherent confidentiality and compliance risk of forwarding prompts/DSL to a remote service that the user may not fully control.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

API Endpoint

text
POST https://api.neurodoc.app/aetherlang/execute
Content-Type: application/json

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The Chef Omega example sets language="el", which forces a specific locale in output behavior. This can violate language-choice policy because the example encourages use of a fixed language without indicating user selection or opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.