Back to skill

Security audit

Skill Refiner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only reviewer for SKILL.md files that writes a local report and does not show hidden or destructive behavior.

Before installing, understand that it will scan SKILL.md files in your workspace and append a local review log. Only enable the optional curl link check if outbound HTTP requests are acceptable in your environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Self-Modification

High
Category
Rogue Agent
Content
## Safety Rules

1. **Never auto-edit skill files from a cron.** Report only. You review, you decide.
2. **Never touch SOUL.md, MEMORY.md, or AGENTS.md.** Those are off-limits.
3. **Don't chase perfection.** 22/25 is fine. Fix the ones below 16.
4. **Don't rewrite for style.** If it works and users aren't confused, leave it.
Confidence
85% confidence
Finding
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Static analysis

No suspicious patterns detected.