Back to skill

Security audit

Qa Gate

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible QA helper, but it says it is read-only while also directing agents to modify artifacts and write reports without clear user approval.

Review this skill carefully before installing. It is not showing evidence of malware, credential theft, network payloads, or persistence, but users should treat it as a QA-and-remediation skill rather than a read-only validator. Install only if you are comfortable with agents potentially editing reviewed artifacts and creating qa-gate report files, or revise it to require explicit approval before any file changes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:13
Finding

Read-Only Validation Scope Contradicted by Unauthorized Artifact Modification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13 and 75–76
Vulnerability Type: Scope violation and unauthorized artifact modification
Risk Level: Medium

Vulnerable Instructions

markdown
This is **not** a code review skill. It is a read-only release gate that determines whether an artifact is ready to move forward. QA Gate inspects artifacts but does not modify them.
markdown
### Step 4: If FAIL, fix and re-validate
Fix all CRITICAL and MAJOR issues. Re-run the gate. Only present to principal after PASS or PASS WITH FIXES.

Technical Analysis

The Skill explicitly establishes a read-only security boundary at line 13, telling users that it inspects artifacts without modifying them. Lines 75–76 contradict that boundary by directing the Agent to fix every issue classified as CRITICAL or MAJOR.

This instruction grants modification authority without requiring separate user consent, validating the target path, preserving a backup, generating an approval-only patch, or limiting the nature and extent of changes. Because QA classification involves model judgment, a false positive or incorrect proposed correction can cause the Agent to alter otherwise valid source code, configuration, documentation, or other reviewed artifacts.

This is classified as T05: Unauthorized Access and Privilege Escalation because the Skill expands its operational privileges from the declared inspection-only role to write access over the artifact.

Attack Path

  1. A user invokes the Skill based on its stated read-only behavior.
  2. The Agent reads an artifact and performs the six prescribed validation checks.
  3. The Agent, correctly or incorrectly, classifies a finding as CRITICAL or MAJOR.
  4. Step 4 directs the Agent to modify the artifact rather than merely report or propose the correction.
  5. The Agent writes changes without obtaining explicit authorization for that write operation.
  6. The Agent ...[truncated 1218 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the automatic remediation instruction with a report-only workflow. For example:

    markdown
    ### Step 4: If FAIL, propose fixes and request approval
    Describe proposed corrections for all CRITICAL and MAJOR findings. Do not modify the artifact unless the user explicitly authorizes the changes.
    
  2. Require explicit, separate user confirmation before performing any write operation.

  3. Present proposed changes as a patch or diff so the user can review the exact modifications before application.

  4. Restrict approved changes to the explicitly selected artifact and reject path expansion, unrelated file edits, or modifications outside the workspace.

  5. Preserve the original artifact or ensure that changes are recoverable through version control or a backup.

  6. After approved remediation, report every changed file and re-run validation against the modified version.

  7. Clarify whether report generation under qa-gate/ is the sole write operation permitted during normal read-only validation.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The trigger phrases are extremely broad, covering common requests like 'proofread this,' 'final check,' and 'validate before publish.' In systems with automatic or suggestive skill routing, this can cause the skill to activate in many contexts beyond the user's intent, exposing artifacts to unnecessary processing and side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The top-level description frames the skill as validation/QA, but the process includes remediation and writing files, which are materially different capabilities. That capability drift increases the chance of unintended actions during invocation, especially in automated environments that select skills based on description text.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly claims to be read-only and non-modifying, but later instructs the agent to fix artifacts and write an output file. This mismatch can cause operators or calling systems to grant the skill broader trust than warranted, leading to unexpected artifact modification or filesystem side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The 'When to Use' section encourages broad usage as a final step on many artifact types but does not define boundaries, exclusions, or preconditions. This ambiguity makes accidental invocation more likely and compounds the risk because the skill is not actually limited to passive inspection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to write a report file to a workspace path without warning about filesystem side effects or obtaining explicit approval. In constrained or sensitive environments, even benign file creation can violate user expectations, leak artifact names, overwrite data, or trigger downstream automation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.