Back to skill

Security audit

Network Tool

Security checks for vulnerabilities and agentic risk

Overview

The skill is documented as a local network information viewer but actually provides broader active network probing and arbitrary HTTP request capabilities.

Install only if you intend to give the agent active network testing authority. Reviewers should require the documentation to match the implemented commands, add explicit consent and target limits for HTTP requests and port scans, and disclose third-party IP/speed-test requests before approval.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/net.py:149
Finding

Undocumented Active Port Scanning of Arbitrary Hosts

Content
View full analysis
List[int]: """Scan a range of ports.""" print(f"Scanning {host} ports {start_port}-{end_port}...") open_ports = [] for port in range(start_port, end_port + 1): sock = socket.socket(socket.AF_INET, socket.SOCK_STREAM) sock.settimeout(timeout) try: result = sock.connect_ex((host, port)) if result == 0: print(f"✓ Port {port} is OPEN") open_ports.append(port) except: pass finally: sock.close() print(f"\nScan complete. Found {len(open_ports)} open ports") return open_ports ``` ```python elif args.command == 'ports': if '-' in args.range: start, end = map(int, args.range.split('-')) scan_ports(args.host, start, end) else: print("Error: Range should be like 80-90") ``` ### Technical Analysis The implementation permits TCP connection attempts against an arbitrary host and caller-selected inclusive port range. It does not restrict targets to localhost or authorized address ranges, limit the number of ports, require confirmation, or enforce an authorization policy. This active probing capability is materially broader than the behavior declared in `SKILL.md`, which describes displaying interfaces, connections, routes, and local network statistics. In an agent context, untrusted instructions could therefore induce active reconnaissance against internal or external systems. The code does use a subprocess argument list safely for its separate ping feature, and no shell-command injection was identified. The risk here is unauthorized network access rather than command injection. ...[truncated 990 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/net.py:32
Finding

Unrestricted HTTP Client Can Reach Internal and Metadata Services

Content
View full analysis
bool: """Make HTTP request (simplified curl).""" print(f"{method} {url}") req = urllib.request.Request(url, method=method) if headers: for key, value in headers.items(): req.add_header(key, value) if data: if isinstance(data, dict): data = urllib.parse.urlencode(data) req.data = data.encode('utf-8') try: if follow_redirects: response = urllib.request.urlopen(req, timeout=30) else: # Don't follow redirects class NoRedirectHandler(urllib.request.HTTPRedirectHandler): def redirect_request(self, req, fp, code, msg, headers, newurl): return None opener = urllib.request.build_opener(NoRedirectHandler) response = opener.open(req, timeout=30) print(f"\nStatus: {response.status} {response.reason}") print(f"Headers: {dict(response.headers)}") content = response.read().decode('utf-8') print(f"\n--- Response ({len(content)} bytes) ---") print(content[:2000]) # Limit output return True except urllib.error.HTTPError as e: print(f"HTTP Error: {e.code} {e.reason}") return False except urllib.error.URLError as e: print(f"URL Error: {e.reason}") return False except Exception as e: print(f"Error: {e}") return False ``` ```python elif args.command == 'curl': headers = {} if args.header: for h in args.header: ...[truncated 2396 chars]
Remediation
View remediation

other

Note
Location
scripts/net.py:171
Finding

Undisclosed External Requests Reveal Runtime Network Information

Content
View full analysis
bool: """Get public IP address.""" print("Getting public IP...") services = [ 'https://api.ipify.org', 'https://ifconfig.me/ip', 'https://icanhazip.com' ] for service in services: try: response = urllib.request.urlopen(service, timeout=10) ip = response.read().decode('utf-8').strip() print(f"Public IP: {ip}") return True except: continue print("Could not determine public IP") return False def speed_test() -> bool: """Simple speed test.""" print("Running speed test...") # Test download speed test_urls = [ ('https://speed.cloudflare.com/__down?bytes=1000000', 'Cloudflare'), ] for url, name in test_urls: print(f"\nTesting {name}...") try: start = time.time() response = urllib.request.urlopen(url, timeout=30) data = response.read() end = time.time() size_mb = len(data) / (1024 * 1024) duration = end - start speed_mbps = (size_mb * 8) / duration print(f"Downloaded: {size_mb:.2f} MB in {duration:.2f}s") print(f"Speed: {speed_mbps:.2f} Mbps") return True except Exception as e: print(f"Error: {e}") return False ``` ### Technical Analysis The `ip` and `speed` commands contact hardcoded third-party services. These communications are not disclosed in `SKILL.md`, which describes local interface, connection, routing, and statistics functionality. Every request necessarily reveals the runtime's source IP address and ordinary connection metadata to the sel ...[truncated 1332 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
scripts/net.py:99
Finding

Unpinned Third-Party Dependency Installation Guidance

Content
View full analysis
Remediation
View remediation

other

Note
Location
SKILL.md:2
Finding

Skill Declaration Does Not Match Implemented Network Capabilities

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is passive local network diagnostics, but the finding indicates materially different behavior including remote port scanning, outbound HTTP requests, public IP lookup, and speed testing. That mismatch is dangerous because it can conceal unexpected external network activity and dual-use reconnaissance functions behind an innocuous description, reducing the chance of detection during review.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises operational capabilities related to networking and appears to require shell/network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This is dangerous because it weakens enforcement of least privilege and can allow broader execution capability than reviewers or runtime policy expect.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/net.py (reported line 22)May include surrounding context.

python
cmd = ['ping', '-c', str(count), '-W', str(timeout), host]
    
    try:
        result = subprocess.run(
            cmd, capture_output=True, text=True, timeout=timeout * count + 5
        )
        print(result.stdout)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The implementation substantially broadens capability beyond the stated purpose by providing generic HTTP requests, DNS enumeration, port checks, port-range scanning, and public IP discovery rather than focusing on interfaces, connections, and routing information. This mismatch is dangerous because users or downstream systems may grant trust based on the benign-looking description while the code supports broader remote probing behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes range-based port scanning, which enables active reconnaissance against arbitrary hosts and moves beyond passive interface or routing diagnostics described in the metadata. In an agent setting, this can be misused to enumerate internal or external services without clear authorization controls or scope restrictions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Port-range scanning is performed immediately on any supplied host and range with no warning, confirmation, or safety messaging about potentially sensitive network probing. In shared, enterprise, or cloud environments, this can lead to unauthorized scanning activity, policy violations, or unintended impact on monitored systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.