Back to skill

Security audit

GPU shader toolkit

Security checks for vulnerabilities and agentic risk

Overview

This shader toolkit is coherent and purpose-aligned, but users should verify or sandbox the unpinned third-party tools it tells them to clone and run.

Install is reasonable for shader-development work. Before following the optional reverse-engineering workflows, treat the referenced GitHub tools as third-party code: pin known commits, review or checksum the source, and run them from a low-privilege sandbox or disposable workspace containing only the shader files you intend to analyze.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:119
Finding

Unpinned Remote Source Retrieval and Native Code Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 119-126
Vulnerability Type: Unpinned remote payload retrieval and execution
Risk Level: Medium

bash
git clone https://github.com/therontarigo/nvcachetools.git
cd nvcachetools

# Build nvcachedec (extracts .toc/.bin to .nvuc files)
gcc -o nvcachedec nvcachedec.c

# Build nvucdump (extracts sections from .nvuc files)
gcc -o nvucdump nvucdump.c

Technical Analysis

The Skill instructs users to clone the mutable default branch of a third-party GitHub repository and compile its source into native executables. No reviewed commit hash, immutable release, checksum, or cryptographic signature is specified.

Consequently, the code executed by a user can differ from the code available when the Skill was audited. Although the repository is relevant to the declared shader-cache analysis functionality and no currently malicious payload was established, the installation procedure creates a remote payload substitution risk. Compiled native code is not constrained to shader-cache processing and can perform any operation permitted to the invoking user.

Attack Path

  1. An attacker compromises the upstream repository, a maintainer account, or its mutable default branch.
  2. The attacker modifies nvcachedec.c, nvucdump.c, or related build inputs to include malicious behavior.
  3. A user follows the Skill instructions and clones the modified repository.
  4. The user compiles the attacker-controlled source with gcc.
  5. When the resulting utility is invoked during shader analysis, malicious native code executes with the user's permissions.

Impact Assessment

Successful exploitation could provide arbitrary code execution under the account running the compiled utilities. Depending on that account's permissions, the payload could read or modify accessible files, inspect shader and game archives, access user-level credentials, or initiate network commun ...[truncated 181 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specific, reviewed commit hash or immutable signed release.
  • Publish the expected SHA-256 digest and require verification before compilation.
  • Prefer a release artifact with a verifiable maintainer signature and reproducible build instructions.
  • Instruct users to inspect the resolved commit and source before compiling it.
  • Perform compilation and execution in a sandbox, container, or disposable virtual machine with no secrets mounted and minimal filesystem access.
  • Run the utilities as an unprivileged user and restrict outbound network access when it is not required.
  • Document the exact reviewed repository version so future upstream changes trigger a new security review.

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:346
Finding

Unpinned Remote Python Tool Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 346-350
Vulnerability Type: Unpinned remote payload retrieval and script execution
Risk Level: Medium

bash
# Get the tool
git clone https://github.com/aizvorski/dx-shader-decompiler.git
cd dx-shader-decompiler

# Decompile DX9 shader binary
python dx-shader-decompiler.py shader.bin

Technical Analysis

The Skill retrieves a Python program from a mutable third-party GitHub branch and directly instructs the user to execute it. The instructions do not pin a reviewed commit or release and do not verify a checksum or signature.

A Python script has the full permissions of the interpreter process and is not restricted to parsing the supplied shader file. An upstream modification could therefore perform arbitrary filesystem, process, credential-access, or network operations when the documented command is run. No evidence shows that the referenced project is currently malicious; the vulnerability is the unsafe, mutable retrieval-and-execution workflow.

Attack Path

  1. An attacker gains control of the upstream repository, maintainer credentials, or default branch.
  2. The attacker inserts malicious Python code into dx-shader-decompiler.py or a locally imported module.
  3. A user follows the Skill and clones the latest repository state.
  4. The user invokes python dx-shader-decompiler.py shader.bin.
  5. Python executes the attacker-controlled code with the user's permissions, potentially before or alongside legitimate shader decompilation.

Impact Assessment

Exploitation could result in arbitrary user-level code execution. The malicious script could access files readable by the user, alter writable project data, inspect local credentials, execute child processes, or transmit information over the network. The documented command does not require administrative privileges, so no privilege escalation or system-wide compromise is directly demons ...[truncated 7 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the mutable clone instruction with a checkout of a specific reviewed commit or immutable signed release.
  • Provide and verify an expected SHA-256 checksum for the reviewed source archive.
  • Review the main script and all local imports because malicious behavior may be placed outside the entry-point file.
  • Execute the decompiler in an isolated environment with an unprivileged account, a read-only input mount, a dedicated output directory, and no unnecessary credentials.
  • Disable outbound network access while running the decompiler unless a documented feature specifically requires it.
  • Avoid executing the repository's installation hooks or dependency files unless those components are separately pinned and reviewed.
  • Record the approved version in the Skill and require renewed review before updating it.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.