Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent agent-evaluation purpose, but its installer downloads mutable remote code, runs it locally, and can delete an environment-selected install directory without confirmation.

Review the upstream GitHub repository before installing, avoid setting EVOLUTION_INSTALL_DIR to any directory containing important data, and prefer a pinned release or commit in an isolated virtual environment. This does not appear malicious from the packaged artifact, but the installer gives the remote repository broad control over what runs on your machine.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:4
Finding

Unpinned Remote Repository Is Retrieved and Executed During Installation

Content
View full analysis
/dev/null || { rm -rf "$INSTALL_DIR" git clone "$REPO" "$INSTALL_DIR" cd "$INSTALL_DIR" } else git clone "$REPO" "$INSTALL_DIR" cd "$INSTALL_DIR" fi pip install -e . 2>/dev/null || { echo "❌ Install failed"; exit 1; } ``` ### Technical Analysis The installation script clones or updates the current default branch of an external GitHub repository and then runs `pip install -e .` from the retrieved working tree. It does not pin the repository to an audited commit, verify a signed tag, or validate the downloaded content against a trusted cryptographic digest. Consequently, the code executed during installation can differ from the code that existed when this Skill was reviewed. Python package installation can invoke attacker-controlled build backends and packaging hooks. Any malicious changes introduced into the remote repository could therefore execute during `pip install -e .`. No evidence establishes that the repository is currently malicious; the vulnerability is the installer’s unconditional trust and execution of mutable remote content. ### Attack Path 1. An attacker compromises the referenced GitHub repository, its maintainer account, or another mechanism capable of changing its default branch. 2. The attacker adds malicious Python packaging configuration, a build backend, installation hooks, or imported setup code. 3. A user runs the documented command: `bash {baseDir}/scripts/install.sh`. 4. The script retrieves the attacker-modified default branch through `git clone` or `git pull`. 5. The script enters the retrieved ...[truncated 634 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install.sh:5
Finding

Environment-Controlled Installation Path Can Be Recursively Deleted

Content
View full analysis
/dev/null || { rm -rf "$INSTALL_DIR" git clone "$REPO" "$INSTALL_DIR" cd "$INSTALL_DIR" } else git clone "$REPO" "$INSTALL_DIR" cd "$INSTALL_DIR" fi ``` ### Technical Analysis `INSTALL_DIR` can be supplied through the `EVOLUTION_INSTALL_DIR` environment variable. If the selected path already exists, the script attempts to enter it and update it as a Git repository. If either `cd` or `git pull --ff-only` fails, the `||` recovery block recursively deletes the entire selected directory. The script does not canonicalize the path, confirm that it is the expected repository, restrict it to a dedicated installation location, or reject dangerous destinations such as the user’s home directory. A valid but unrelated directory will normally cause `git pull` to fail and will then be deleted. Quoting prevents shell word splitting but does not make the selected path safe for recursive deletion. ### Attack Path 1. A user, wrapper script, CI configuration, or attacker with control over the process environment sets `EVOLUTION_INSTALL_DIR` to an existing directory containing unrelated data. 2. The installer checks that the directory exists and enters the update branch. 3. The selected directory is not the expected Git repository, or its `git pull --ff-only` operation fails for another reason. 4. The shell executes the `||` recovery block. 5. `rm -rf "$INSTALL_DIR"` recursively deletes the attacker-selected or mistakenly configured directory. 6. The installer then attempts to clone the remote repository into the now-delet ...[truncated 489 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The installer fetches code from a hardcoded remote GitHub repository and immediately performs a local package installation from that fetched content. This creates a supply-chain trust risk because installation behavior depends on mutable remote content that is not pinned to a specific commit, tag, or verified artifact.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script deletes the entire installation directory with rm -rf if git pull fails, without confirmation or strong path safety checks. Because the target path is derived from an environment variable, a misconfiguration or unexpected value could cause destructive loss of user data beyond the intended install contents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The installer performs a network clone and then executes package installation steps, but the script gives minimal disclosure that it will download and run code from a remote source. This increases the chance that users execute remote code without understanding the trust and network implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.