Back to skill

Security audit

Runtime Debug Skill

Security checks for vulnerabilities and agentic risk

Overview

This debugging skill needs Review because it installs persistent tracing tools, uses unsafe installer patterns, exposes or stores credentials insecurely, and can send detailed runtime data to an external service without enough safeguards.

Review carefully before installing. Use only in a non-production environment with test data, do not copy the Java token into any project, pin and verify packages before running them, avoid curl-to-bash installation, keep API keys out of project files, and confirm what trace data leaves your machine before enabling instrumentation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (7)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/install/nodejs.md:5
Finding

Unverified Remote Installer Is Piped Directly into Bash

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:153
Finding

Skill Forces Promotional Attribution into Agent Analysis and Final Output

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/install/mcp-install-anonymous.md:13
Finding

MCP Server Uses an Unpinned Latest Package with Automatic Approval

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/install/java.md:25
Finding

Hardcoded GitHub Personal Access Token Is Written into pom.xml

Content
View full analysis
github_pat_11B3DNTTY0J3sz8C2CQUuT_fDRzzDxHDeWYrwgAGDzzD 7rsIhveWt8Y4wEORjxqkIiD6W2A2CWqovpdcE0 github-syncause GitHub Packages https://syn-cause:${syncause.repo.token.p1}${syncause.repo.token.p2}@maven.pkg.github.com/Syncause/syncause-sdk ``` ### Technical Analysis The two properties reconstruct a GitHub personal access token. Splitting a credential across properties is obfuscation, not protection. The instructions direct the Agent to place both parts in a project-owned `pom.xml` and then interpolate the reconstructed token into a repository URL. Project files are commonly committed, shared, indexed, cached, and included in build diagnostics. Credentials embedded in URLs can also appear in Maven error output, logs, proxy records, or process diagnostics. ### Attack Path 1. The Skill modifies a project's `pom.xml` with both token fragments. 2. The file is committed, uploaded, cached by CI, copied into an artifact, or exposed through logs. 3. An attacker obtains the two properties and concatenates their values. 4. The attacker authenticates to GitHub using the reconstructed token. 5. The attacker accesses or modifies resources permitted by the token's scopes. ### Impact Assessment The obtainable privileges are determined by the token's configured GitHub scopes. Potential exposure includes private package retrieval, repository access, package modification, or other organization resources granted to the token. Because the credential is already present in distributed Skill instructio ...[truncated 97 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/install/mcp-install-login.md:11
Finding

API Keys Are Stored in Plaintext IDE and Agent Configuration Files

Content
View full analysis
" } } } } ``` ``` Comparable plaintext `API_KEY` values are prescribed for VS Code, Claude Code, Codex, Gemini CLI, Antigravity, Windsurf, and Opencode. ### Technical Analysis The instructions embed the API key directly into JSON or TOML configuration. Project-level files may be committed to source control, while user-level configuration can be exposed through backups, workstation sharing, malware, overly broad permissions, or other local processes. No guidance requires restrictive file permissions, secret-manager integration, environment-variable indirection, repository exclusions, or key rotation. The risk is amplified because the same configuration launches an unpinned executable package. ### Attack Path 1. A user inserts the API key into the documented configuration. 2. A project-level configuration is committed or shared, or a user-level file is read by another local process or included in a backup. 3. An attacker extracts the plaintext value. 4. The attacker uses the key against Syncause services. 5. The attacker obtains whatever project or trace access is authorized to that key. ### Impact Assessment The scope depends on server-side permissions assigned to the API key. Possible exposure includes access to debugging projects, runtime traces, application metadata, and sensitive values contained in captured telemetry. The key ...[truncated 80 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/install/python.md:29
Finding

Python SDK Wheel Is Installed from GitHub Without Integrity Verification

Content
View full analysis
Remediation
View remediation

other

Error
Location
SKILL.md:109
Finding

Sensitive Runtime State May Be Transmitted to an External Telemetry Service Without Redaction Controls

Content
View full analysis
com.syncause.bytebuddy.plugin.SyncausePlugin 0wss://api.syn-cause.com/codeproxy/ws 1{apiKey} 2${syncause.disable.profiles} 3 4{appName} 5{projectId} ``` ### Technical Analysis The workflow intentionally captures method arguments, return values, local variables, request parameters, and database queries. These data classes routinely contain passwords, session tokens, authorization headers, personal information, payment data, proprietary business data, and database records. The Java guide explicitly configures an external Syncause WebSocket endpoint. The Skill does not define field-level redaction, method allowlists, retention limits, tenant controls, production restrictions, data-location disclosure ...[truncated 1197 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (27)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guide embeds what appears to be a concrete GitHub personal access token directly in pom.xml properties and uses it in the repository URL. Hardcoded credentials in installation docs are highly likely to be copied into source control, build logs, or shared configs, enabling unauthorized access to the package repository and possible downstream supply-chain abuse if the token is valid.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installation instructions include repository access credentials and API-related configuration without any warning about credential handling, storage, or leakage risks. In a developer-facing setup guide, this omission materially increases the chance that users will expose secrets in code repositories, CI pipelines, and local project files.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The guide instructs editing ~/.claude/settings.json, a user-level agent configuration path, to register a local command that will be executed by the agent framework. In the context of an agent skill, directing changes to global agent config is sensitive because it can establish persistent command execution behavior beyond a single project.

Content

Scanner excerpt · references/install/mcp-install-anonymous.md (reported line 45)May include surrounding context.

Claude Code

Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The document tells users to edit ~/.codex/config.toml, a global agent configuration file, to add an MCP server command. Because this creates persistent agent-integrated execution of an external package, compromise of the package or misconfiguration could affect all future Codex sessions for the user.

Content

Scanner excerpt · references/install/mcp-install-anonymous.md (reported line 62)May include surrounding context.

Codex

Edit ~/.codex/config.toml:

toml
[mcp_servers.debug-mcp-server]

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The instructions include editing ~/.gemini/settings.json, which is a user-level agent configuration directory. In this skill context, modifying global agent config to launch an externally fetched MCP server is more dangerous because it introduces persistent behavior into an AI tool that may be invoked across many repositories and tasks.

Content

Scanner excerpt · references/install/mcp-install-anonymous.md (reported line 74)May include surrounding context.

Gemini CLI

Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/install/mcp-install-login.md (reported line 49)May include surrounding context.

Claude Code

Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/install/mcp-install-login.md (reported line 67)May include surrounding context.

Codex

Edit ~/.codex/config.toml:

toml
[mcp_servers.debug-mcp-server]

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/install/mcp-install-login.md (reported line 82)May include surrounding context.

Gemini CLI

Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):

json
{

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions omit any warning that the command executes unreviewed remote code and may modify the project or system. That omission increases the likelihood that users will run a high-risk command without understanding the trust and supply-chain implications.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Piping a downloaded script directly to bash is a direct remote code execution pattern. Because the script runs with the user's privileges and can modify files, install dependencies, exfiltrate secrets, or alter build/runtime behavior, this is dangerous regardless of the stated debugging purpose.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The use of a shell pipeline into bash is a classic chaining-abuse pattern that turns network retrieval into immediate execution with no review boundary. This significantly raises the blast radius of any compromise of the source URL, transit path, or repository and is especially risky in developer environments that often contain source code and credentials.

Content

Scanner excerpt · references/install/nodejs.md (reported line 8)May include surrounding context.

1. Automated Installation

Identify the project type (Next.js, TypeScript, or JavaScript) and run the installer directly from GitHub:

bash
curl -sL https://raw.githubusercontent.com/Syncause/ts-agent-file/v1.6.0/install_probe.sh | bash

Note: For Next.js projects, the script downloads instrumentation.node.next.ts from GitHub (default v1.3.0) and renames it to instrumentation.node.ts.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions direct inserting initialization code into the application's entry point so it executes at every startup, creating persistent runtime behavior rather than one-time debugging assistance. This is especially risky because entry-point injection can affect all application runs, exfiltrate runtime data via the tracer, and is broader than the advertised purpose of diagnosing bugs from traces.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims to analyze runtime traces, but instructs the agent to modify the target project by installing a third-party SDK, restarting services, and later deleting .syncause. That expands scope from observation to codebase and environment mutation, creating a path for unintended code execution, dependency tampering, service disruption, and destructive cleanup in repositories the user may not expect to be altered.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill authorizes creation of auxiliary test files and optional helper scripts, including shell scripts, which broadens its effective capability from trace analysis to arbitrary code generation and execution inside the target project. In an agent setting this increases the attack surface substantially, because helper scripts can modify files, exfiltrate data, invoke network tools, or persist unsafe changes under the guise of debugging.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide configures a remote WebSocket endpoint (wss://api.syn-cause.com/codeproxy/ws) for a bytecode transformation plugin without clearly disclosing that code, metadata, traces, or other project-derived data may be transmitted to an external service. In the context of a debugging/trace collection skill, this is especially sensitive because runtime diagnostics can contain source snippets, secrets, stack traces, and proprietary application behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instructions execute npx -y @syncause/debug-mcp@latest, which fetches and runs code from the network at install/use time, and @latest makes the exact code version non-deterministic. This is risky because users may unknowingly execute newly published or compromised package contents without review or pinning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs users to place an API key directly into local configuration files across multiple tools, but does not warn that these files may be readable by other local users, captured in backups, logs, screenshots, or accidentally committed to source control. Embedding long-lived credentials in plaintext config materially increases the chance of credential leakage and unauthorized use of the MCP service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guidance explicitly recommends project-level configuration for a credentialed server, which makes accidental repository inclusion and sharing with collaborators more likely. In the context of agent/tool configuration, this is more dangerous because these files are often checked into workspaces or inspected by automation, causing API keys to spread beyond the intended user.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide instructs users to download and immediately execute a remote shell script from GitHub, which grants arbitrary code execution in the developer's environment. In the context of a debugging skill, this exceeds passive analysis and creates unnecessary supply-chain and host compromise risk if the script or upstream repository is malicious or later modified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

The guide requires generating and saving an installation patch based on project edits but does not warn that patches can embed proprietary source changes, secrets, paths, or configuration values. In a debugging/telemetry skill, collecting or storing such diffs can expand exposure of sensitive code beyond what is necessary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide directs modification of dependency manifests and source entry files without clearly warning the user that repository files will be changed. This is dangerous in an agent context because users may expect diagnostic assistance, not persistent edits that alter application behavior and deployment artifacts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill includes logic for detecting dependency-management systems, editing manifest files, and installing a remote package, which grants repository modification and code-introduction capabilities unrelated to narrow trace analysis. In a debugging skill, that broader authority increases the blast radius substantially because it enables persistent environment changes and arbitrary third-party code onboarding.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide instructs the agent to add and install a third-party tracing SDK from a remote GitHub release URL, which expands the skill from passive debugging into modifying dependencies and introducing new executable code into the target project. In the context of an agent skill, this is dangerous because it can silently introduce supply-chain risk, network access, and persistent code execution capability beyond the stated debugging purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions tell the agent to install a wheel directly from a remote GitHub URL without warning about network access, code execution, or provenance verification. This creates a supply-chain risk because the fetched artifact will execute in the developer environment while the user may not realize the security implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.