Back to skill

Security audit

DR Schedule Manager

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent scheduling playbook, but its reusable examples include a real-looking Discord recipient that could misdirect scheduled job output if copied unchanged.

Review before installing or using this skill for live jobs. Replace the Discord `target` value in all copied manifests with your intended recipient, change the timezone to your deployment timezone, and require an explicit dry run and confirmation before enabling live delivery, notifications, public posts, or production mutations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/job-manifest-template.json:18
Finding

Hard-Coded Discord Recipient in Reusable Delivery Examples

Content
View full analysis

Vulnerability Details

File Locations:

  • references/architecture-patterns.md:153-158
  • references/example-migration-daily-briefing.md:67-72
  • references/job-manifest-template.json:18-23

Vulnerability Type: Hard-coded external delivery recipient
Risk Level: Medium

Vulnerable Code

references/architecture-patterns.md:153-158:

json
{
  "delivery": {
    "channel": "discord",
    "target": "user:270548320366100480",
    "accountId": "default"
  }
}

references/example-migration-daily-briefing.md:67-72:

json
"delivery": {
  "channel": "discord",
  "target": "user:270548320366100480",
  "accountId": "default",
  "mode": "runtime-send"
},

references/job-manifest-template.json:18-23:

json
"delivery": {
  "channel": "discord",
  "target": "user:270548320366100480",
  "accountId": "default",
  "mode": "runtime-send"
},

Technical Analysis

The reusable architecture example, migration example, and job-manifest template contain the same concrete Discord user ID instead of an unmistakable placeholder. These documents are intended to be copied or adapted when configuring scheduled jobs.

Because the value is syntactically valid and is presented as the recommended provider-aware delivery format, an operator or automation agent may retain it without realizing that it identifies a specific external account. If the resulting manifest is activated, generated reports, briefings, alerts, attachments, or test messages could be delivered to that account.

This issue does not independently bypass authorization or acquire additional system privileges. Exploitation depends on a user or agent copying the example and subsequently approving or enabling outbound delivery. Nevertheless, the concrete identifier creates a credible unsafe-default condition in a reusable configuration template.

Attack Path

  1. An operator or agent follows the documente ...[truncated 1231 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the concrete Discord identifier in every reusable example with an explicit placeholder:

    json
    "target": "user:<DISCORD_USER_ID>"
    
  2. Ensure the placeholder is intentionally invalid until deployment-specific configuration supplies a recipient.

  3. Add manifest validation that rejects unresolved placeholders and example recipient values.

  4. Require the delivery target to come from trusted local configuration or explicit user input rather than copied documentation.

  5. Before any live test or production activation, display the resolved channel, account, and recipient and require explicit confirmation.

  6. Add a dry-run mode that records the resolved recipient without transmitting content.

  7. Review existing manifests derived from these examples and replace any retained occurrence of user:270548320366100480 unless the operator independently verifies it as the intended recipient.

  8. Add an automated repository check that prevents concrete external account identifiers from being committed to reusable templates.

Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Self-Modification

High
Category
Rogue Agent
Confidence
70% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · references/migration-checklist.md (reported line 57)May include surrounding context.

md
### 7. Relax harmful verification

Keep checks that validate assembly.
Remove checks that freeze old desired behavior.

### 8. Test one live run for content freshness

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest sets the schedule timezone to "Australia/Brisbane", which imposes a locale-specific behavior. There is no accompanying justification that this template is region-specific, nor any indication that users should choose or opt in to a timezone, so it risks violating locale-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The example manifest specifies "tz": "Australia/Brisbane" as a fixed locale setting. This can be a natural-language policy concern because it imposes a specific regional setting without indicating user opt-in or documenting that the skill is intended only for that locale.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This is a manifest file, so vague-trigger checks apply. The template identifies an "Example scheduled job" with runtime and trigger settings, but provides no specificity about what kinds of jobs should or should not use this manifest, which may encourage overly broad reuse without clear activation boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.