Back to skill

Security audit

verbs-to-urma-converter

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent URMA migration guide, but its reference material can steer generated code toward unsafe remote-memory token handling and unauthenticated network exposure.

Review before installing. This skill should only be used by developers who can audit the generated URMA security model. Do not copy its token or client/server examples into production without replacing fixed tokens, adding authenticated encrypted control channels, limiting exported memory and access flags, and binding listeners only to trusted interfaces.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
references/patterns.md:1127
Finding

Predictable Fallback Token and Plaintext Token Transmission

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/pitfalls.md:34
Finding

Mandatory Migration Guidance Presents Fixed and Plaintext Tokens as a Correct Pattern

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/urma_sample.md:215
Finding

Canonical Sample Exposes Broadly Writable URMA Memory to Unauthenticated Network Peers

Content
View full analysis
token.token = 0xACFE; ``` It registers a 1 GB memory region with no token authentication and broad remote privileges: ```c urma_reg_seg_flag_t flag = { .bs.token_policy = URMA_TOKEN_NONE, .bs.cacheable = URMA_NON_CACHEABLE, .bs.access = URMA_ACCESS_READ | URMA_ACCESS_WRITE | URMA_ACCESS_ATOMIC, .bs.token_id_valid = 0, .bs.reserved = 0 }; urma_seg_cfg_t seg_cfg = { .va = (uint64_t)ctx->va, .len = MEM_SIZE, .token_id = NULL, .token_value = ctx->token, .flag = flag, .user_ctx = (uintptr_t)NULL, .iova = 0 }; ``` The metadata exchange uses unencrypted socket I/O: ```c static int sock_sync_data(int sockfd, int size, char *local_data, char *remote_data) { int rc; int read_bytes = 0; int total_read_bytes = 0; rc = write(sockfd, local_data, (size_t)size); if (rc < size) { (void)fprintf(stderr, "Failed writing data during sock_sync_data, errno: %s.\n", strerror(errno)); } else { rc = 0; } while (rc == 0 && total_read_bytes < size) { read_bytes = read(sockfd, remote_data, (size_t)size); if (read_bytes > 0) { total_read_bytes += read_bytes; } else { rc = read_bytes; } } return rc; } ``` The exchanged structure contains endpoint and memory-access metadata: ```c typedef struct seg_jetty_info { /* Common */ urma_eid_t eid; uint32_t uasid; /* segment */ uint64_t seg_va; uint64_t seg_len; uint32_t seg_flag; uint32_t seg_token_id; /* jetty */ urma_jetty_id_t jetty_id; } __attribute__((packed)) seg_jetty_info_t; ``` That structure is sent to connected ...[truncated 4218 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/patterns.md (reported line 922)May include surrounding context.

md
// 9. Delete event channel
if (jfce) urma_delete_jfce(jfce);

// 10. Delete context
urma_delete_context(ctx);

// 11. Free device list

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · references/patterns.md (reported line 939)May include surrounding context.

md
// 9. Delete event channel
if (jfce) urma_delete_jfce(jfce);

// 10. Delete context
urma_delete_context(ctx);

// 11. Free device list

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says to invoke on broad terms like 'rdma', 'ibv_*', or 'urma', which can match general troubleshooting, architecture discussion, or educational questions rather than an actual migration request. Over-broad activation can route users into a high-impact code transformation workflow unnecessarily, increasing the chance of unwanted file generation, incorrect guidance, or unsafe automated edits in contexts where migration was not intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The 'When to Use This Skill' section lists short keyword-based triggers without boundaries, disambiguation rules, or exclusions. In an agentic environment, this makes accidental invocation likely, which is dangerous because the skill performs prescriptive multi-phase migration steps and can steer analysis or code changes even when the user's goal is only discussion, review, or debugging.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document shows transmitting URMA access tokens over sockets with no warning that these tokens may authorize remote memory operations. In this skill context, that omission is more dangerous because readers are likely to copy migration examples directly into production or test harnesses, causing credential exposure, unauthorized segment imports, and possible remote memory read/write abuse if the channel is intercepted or spoofed.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill is scoped as an API migration guide, but it introduces token exchange over raw TCP/socket without authentication, confidentiality, integrity protection, or clear trust-boundary guidance. Because these tokens gate remote memory access/import operations, normalizing ad hoc network exchange in migration docs can lead downstream users to ship insecure credential transport in real deployments.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/pitfalls.md (reported line 1084)May include surrounding context.

.max_sge = 13, .max_rsge = 13, // Wrong! Device max_jfs_rsge = 1

// ❌ Set without checking device capabilities .depth = user_value, // may exceed max_jfs_depth

text

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reference documentation presents the sample as a canonical client/server URMA implementation but does not warn that it performs real network communication and exchanges remote memory addressing metadata such as EID, UASID, segment virtual address, and jetty identifiers. In a migration skill, users may copy or run this example in inappropriate environments, increasing the chance of unintentionally exposing RDMA-accessible memory or testing against reachable hosts without understanding the trust assumptions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.