Back to skill

Security audit

BugPack Fix Bug

Security checks for vulnerabilities and agentic risk

Overview

This skill gives an agent straightforward instructions to fix a BugPack bug and update its local BugPack status, with no hidden code or persistence.

Install this if you want an agent to actively fix BugPack issues. Before relying on the final status update, review the code diff and make sure tests or manual checks support marking the bug as fixed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill explicitly directs the agent to modify source files and then update an external bug-tracking state by marking the bug as fixed, but it provides no requirement for explicit user confirmation, dry-run behavior, or safeguards before making those changes. This is dangerous because an agent could perform unintended code edits or prematurely change workflow state in BugPack, causing integrity issues in the repository and external system even when the bug context is incomplete, ambiguous, or maliciously crafted.

Static analysis

No suspicious patterns detected.