Back to skill

Security audit

Json Tool

Security checks for vulnerabilities and agentic risk

Overview

This is a simple local JSON utility, but users should know some operations overwrite or create files unless an output path is used.

Install only if you are comfortable with a local script reading and writing JSON files you point it at. For important data, pass --output or keep a backup because some operations modify the original file by default.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
scripts/json_tool.py:121
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill documentation advertises running a local Python script that can format, minify, convert, and sort JSON, and the static analyzer detected file-write capability, but the manifest declares no explicit tool scope such as permissions or allowed-tools. That creates an authorization and transparency gap: consumers of the skill cannot tell up front that it may modify or create files, especially during conversions or formatting operations that commonly write output. In this context the capability is plausibly legitimate, but undeclared write access still increases risk if the implementation writes unexpected paths or overwrites user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tool defaults to writing formatted, minified, or sorted JSON back to the original input file when no --output path is supplied. This creates an unsafe destructive side effect: a user or calling agent expecting a read-only transformation can unintentionally overwrite source data, potentially causing data loss or corruption of important configuration files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The conversion paths create .yaml or .csv files on disk, but the skill only states it can 'transform JSON data' and does not disclose that conversion produces new files. This is a file-writing side effect that lacks an upfront user warning in the code's visible descriptions or CLI help.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.