Back to skill

Security audit

Checking Uptime Status

Security checks for vulnerabilities and agentic risk

Overview

This is a read-only Uptimely status-check skill whose access and behavior match its stated purpose, with minor caution around broad activation phrases.

Install this if you want Codex to read Uptimely project status, incidents, alerts, maintenance windows, and on-call information. Be aware that broad requests like 'is anything down' may cause it to check Uptimely, so ask explicitly or confirm the project when the context is ambiguous.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description contains many broad natural-language trigger phrases such as 'is anything down', 'is my site up', and 'show uptime', which can cause the skill to activate in situations where the user did not clearly intend to invoke this specific integration. Because the skill queries live operational data from an external service, unintended activation can expose monitoring, incident, on-call, or maintenance information more readily than necessary.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The body text says to answer broad status questions like 'is anything wrong, and who is handling it' from live data, which is ambiguous enough to match routine troubleshooting conversations outside the intended scope. In context, this can lead to accidental invocation and unnecessary retrieval of sensitive operational details such as current incidents and on-call personnel.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.