Back to skill

Security audit

Publish Skill

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a defensive skill scanner, but installation depends on downloading and running an externally hosted binary that was not included in the reviewed package.

Review before installing. Only run this in a constrained environment or after independently verifying the binary and source provenance; avoid scanning broad private directories, and use upload or external-engine options only when you trust the destination and understand what report data may leave the machine.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:47
Finding

Unverifiable Precompiled Binary Retrieved from an External Release Source

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47–126
Vulnerability Type: Supply-chain exposure through a remotely hosted precompiled dependency
Risk Level: High

Evidence

markdown
This tool includes a compiled Rust binary. Source code is available at:
- Gitee: https://gitee.com/random_player/cmic-skill-scanner
- All releases include SHA-256 checksums for integrity verification
- Build from source: `cargo build --release` (see repo README)
markdown
| macOS ARM64 | https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-darwin-arm64-v0.4.0.zip |
| Linux x64 | https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-linux-amd64-v0.4.0.zip |
| Linux ARM64 | https://gitee.com/random_player/cmic-skill-scanner/releases/download/v0.4.0/skillscan-wrapper-linux-arm64-v0.4.0.zip |

- darwin-arm64: `bd78d3861a545ad52e2f51b8d072efe1d7604850f4a7049d99a840387a341c6a`
- linux-amd64: `1b4997f7b2a4e4dcf9b0d7edcc65755e13a03a258d795ee1abcc35dcab3d5a86`
- linux-arm64: `071b0c404b840aeb4e4d493b3a2513390ed629e0f07e4b79a0b5bc908f1c2d1c`
bash
shasum -a 256 skillscan-wrapper
./skillscan-wrapper review /path/to/skill --format markdown

Technical Analysis

The audited package contains only SKILL.md; it does not include the referenced binary or corresponding Rust source code. The documented workflow directs users to retrieve a precompiled executable from an external Gitee repository and run it locally. Consequently, the executable's filesystem access, network behavior, upload implementation, external-engine behavior, and claimed security restrictions cannot be verified from the audited artifact.

Fixed SHA-256 values provide integrity checking only when users compare the computed value with a trustworthy expected value. The documented command merely prints the calculated digest and does not enforce comparison o ...[truncated 2006 chars]

Remediation
View remediation

Remediation Suggestions

  1. Include the complete Rust source, lockfile, build configuration, and dependency metadata in the audited package.
  2. Prefer building the executable from reviewed source in a reproducible build environment rather than directing users to run an opaque binary.
  3. Publish reproducible-build instructions and allow users to compare locally built artifacts with released binaries.
  4. Sign release archives and checksum manifests with a cryptographic signing key whose public key or fingerprint is distributed through an independent trusted channel.
  5. Replace the checksum-printing instruction with an enforced verification command that fails closed before execution, such as a platform-appropriate checksum manifest check.
  6. Host expected checksums or signature fingerprints independently from the release assets to reduce single-source compromise risk.
  7. Pin and audit all dependencies, including any external scanning engine, and document its source, version, permissions, and network behavior.
  8. Run the scanner with least privilege in a sandbox or container. Restrict filesystem access to the selected scan directory, disable network access by default, and explicitly enable only required destinations.
  9. Add automated release provenance, continuous dependency scanning, and verification tests that ensure distributed binaries correspond to the reviewed source.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
60% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
- Read your credentials, SSH keys, AWS configs, or any identity files
- Access MEMORY.md, USER.md, SOUL.md, or agent identity files
- Send data anywhere without your explicit command
- Modify system files outside your specified workspace
- Request elevated/sudo permissions

This tool **ONLY**:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
- Access MEMORY.md, USER.md, SOUL.md, or agent identity files
- Send data anywhere without your explicit command
- Modify system files outside your specified workspace
- Request elevated/sudo permissions

This tool **ONLY**:
- Reads skill files you explicitly ask it to scan

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Large portions of the README-style documentation switch to Chinese after earlier English sections, but the file does not state that the skill is Chinese-specific or let the user choose a preferred language. This can violate language or locale policy where user-facing content should not force a language without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The trigger "review skill package" is relatively generic and could match ordinary conversational requests rather than a clearly scoped invocation. The manifest does not provide negative examples or tighter constraints to distinguish when this skill should activate versus other review-oriented skills.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.