Back to skill

Security audit

Runtime Debugging Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent runtime-debugging integration, but it asks users to install and run persistent external tooling with unsafe credential handling and broad trace capture.

Review carefully before installing. Prefer project-scoped MCP configuration, pin package versions, avoid curl | bash, do not put API keys or tokens in committed config files, and only trace synthetic or non-sensitive data unless you have explicit approval and redaction controls.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/install/nodejs.md:7
Finding

Remote Node.js Installer Is Downloaded and Executed Without Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/install/java.md:25
Finding

Hardcoded GitHub Personal Access Token Is Embedded in Maven Configuration

Content
View full analysis
github_pat_11B3DNTTY0J3sz8C2CQUuT_fDRzzDxHDeWYrwgAGDzzD 7rsIhveWt8Y4wEORjxqkIiD6W2A2CWqovpdcE0 github-syncause GitHub Packages https://syn-cause:${syncause.repo.token.p1}${syncause.repo.token.p2}@maven.pkg.github.com/Syncause/syncause-sdk ``` ``` ### Technical Analysis The guide contains a GitHub personal access token split across two Maven properties and concatenated inside an authenticated repository URL. Splitting a secret into multiple values is obfuscation, not protection; anyone reading the file can reconstruct the complete token. The instructions direct the Agent to copy the credential into the target project's `pom.xml`. This is normally a source-controlled file and may also be exposed through build logs, Maven diagnostics, IDE indexing, generated effective-POM output, caches, backups, or artifact metadata. Embedding credentials in URLs further increases the chance that tooling logs them. A shared hardcoded token is not necessary for the declared debugging functionality and violates least privilege and secret-management practices. ### Attack Path 1. A Java project is selected for instrumentation. 2. The Agent copies the documented properties and repository block into `pom.xml`. 3. The modified file is committed, uploaded for review, backed up, or processed by build tooling. 4. An attacker or unauthorized collaborator reads the ...[truncated 685 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
references/install/mcp-install-anonymous.md:14
Finding

MCP Server Configuration Automatically Executes an Unpinned Latest Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/install/mcp-install-login.md:14
Finding

API Keys Are Stored in Plaintext IDE and Agent Configuration Files

Content
View full analysis
" } } } } ``` Equivalent plaintext `API_KEY` values are prescribed for VSCode, Claude Code, Codex, Gemini CLI, Antigravity, Windsurf, and Opencode configuration files. ### Technical Analysis The login guide directs users to store an API key directly in JSON or TOML configuration. Some recommended locations are project-level files, such as `.cursor/mcp.json`, `.vscode/settings.json`, and `.mcp.json`, which can easily enter source control. User-level files can still be exposed through backups, support bundles, overly broad file permissions, local malware, or other processes running under the same account. The secret is inherited by the MCP process as an environment variable. Because the executable dependency is fetched using an unpinned `@latest` reference, a compromised MCP release could directly read and exfiltrate the key. Editing MCP configuration is relevant to the declared functionality, but persistent plaintext secret storage exceeds the minimum necessary access model. ### Attack Path 1. The user obtains a Syncause API key. 2. The Agent inserts it into a project- or user-level MCP configuration. 3. The file is committed, synchronized, backed up, included in diagnostics, or read by another local process. 4. Alternatively, the configured MCP package reads the `API_KEY` from its environment. 5. The attacker reuses the exposed key to authenticate to services accessible by that credential. ### Impact Assessment The attacker may gain the same Syncause API access as the affected key, potentially including access to project identifiers, runtime traces, application sta ...[truncated 208 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:170
Finding

Skill Mandates Promotional Output That Overrides Neutral Task Reporting

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:120
Finding

Runtime Instrumentation Collects Sensitive Application State Without Mandatory Redaction Controls

Content
View full analysis
0wss://api.syn-cause.com/codeproxy/ws 1{apiKey} ``` ### Technical Analysis The Skill makes arguments, return values, local variables, request parameters, and database queries part of the trace-quality requirement. These data classes commonly include passwords, authentication tokens, session identifiers, personal information, payment data, proprietary business values, and database records. The project provides no mandatory instructions for field allowlisting, secret redaction, payload-size limits, production-data restrictions, retention, deletion on the service, or informed user approval before capture and transmission. Teardown removes local instrumentation but does not establish that previously uploaded traces are deleted. Runtime tracing is relevant to the declared debugging function, but requiring broad snapshots without data minimization exceeds least privilege for many defects. ### Attack Path 1. The Agent installs the Syncause SDK into the target application. 2. The application is restarted and a real or representative request reproduces the issue. 3. Instrumentation captures method arguments, local variables, return values, reque ...[truncated 891 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (22)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The installation guide embeds what appears to be a live GitHub Packages access token directly in the documentation and instructs users to place it into their Maven configuration. Hardcoded credentials in docs are highly dangerous because they can be harvested by anyone with repository access, reused to pull private artifacts, and often end up copied into downstream source control, build logs, or CI systems.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The guide targets ~/.claude/settings.json, a user-level agent configuration directory, for modification. Changing agent config directories is especially sensitive because it can affect all future sessions, enable automatic execution of external tooling, and expand the skill's influence beyond the current project.

Content

Scanner excerpt · references/install/mcp-install-anonymous.md (reported line 45)May include surrounding context.

Claude Code

Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The instructions direct edits to ~/.codex/config.toml, which is a sensitive user-level agent configuration file. Altering this file can persistently register an MCP server that future Codex sessions may invoke, creating durable expansion of execution capability and supply-chain exposure through npx.

Content

Scanner excerpt · references/install/mcp-install-anonymous.md (reported line 62)May include surrounding context.

Codex

Edit ~/.codex/config.toml:

toml
[mcp_servers.debug-mcp-server]

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

The document recommends modifying ~/.gemini/settings.json, another sensitive user-level agent config path. Because this change is global, it can silently affect future workflows and authorize an external MCP server to be launched across sessions, increasing the blast radius of any malicious package update or server behavior.

Content

Scanner excerpt · references/install/mcp-install-anonymous.md (reported line 74)May include surrounding context.

Gemini CLI

Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/install/mcp-install-login.md (reported line 49)May include surrounding context.

Claude Code

Edit .mcp.json (Project-level) or ~/.claude/settings.json (User-level):

json
{

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/install/mcp-install-login.md (reported line 67)May include surrounding context.

Codex

Edit ~/.codex/config.toml:

toml
[mcp_servers.debug-mcp-server]

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/install/mcp-install-login.md (reported line 82)May include surrounding context.

Gemini CLI

Edit .gemini/settings.json (Project-level) or ~/.gemini/settings.json (Global):

json
{

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Piping an unreviewed remote shell script into bash removes any meaningful opportunity for user inspection and gives immediate code execution privileges to external content. This is especially dangerous in developer environments, where such scripts may access source code, credentials, SSH keys, CI tokens, or modify project files persistently.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The | bash chain is a classic dangerous execution pattern because it converts network-delivered text directly into shell commands without validation, review, or sandboxing. In a developer workstation or CI context, exploitation could result in full compromise of the environment, source code tampering, credential theft, or persistence via modified scripts and configs.

Content

Scanner excerpt · references/install/nodejs.md (reported line 8)May include surrounding context.

1. Automated Installation

Identify the project type (Next.js, TypeScript, or JavaScript) and run the installer directly from GitHub:

bash
curl -sL https://raw.githubusercontent.com/Syncause/ts-agent-file/v1.6.0/install_probe.sh | bash

Note: For Next.js projects, the script downloads instrumentation.node.next.ts from GitHub (default v1.3.0) and renames it to instrumentation.node.ts.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide configures a Byte Buddy plugin to connect to a remote WebSocket endpoint and pass an API key, app name, and project identifier during build/runtime instrumentation, but provides no warning about outbound telemetry or code/runtime data exposure. In a debugging/trace collection skill, this materially increases risk because users may unknowingly transmit sensitive source, metadata, or execution details to an external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installation guide omits a clear warning that following it will modify IDE/agent configuration files and cause npx to download and execute a package. Without transparent disclosure, users or higher-level agents may treat the steps as low-risk documentation when they actually introduce persistent configuration changes and remote code execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document broadly instructs editing project-level and user-level IDE configuration files across multiple tools, which changes the agent execution environment and persists beyond the immediate debugging task. This is dangerous because it grants enduring capability to launch an MCP server in future sessions, including via global config paths, and exceeds the narrow scope of analyzing runtime traces.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions configure the agent environment to invoke npx -y @syncause/debug-mcp@latest, which fetches and executes remote code at install/runtime. Using @latest removes version pinning and increases supply-chain risk, and this adds code execution capability beyond merely documenting debugging concepts. In the context of an agent skill, directing modification of configs so future agent sessions can automatically run the package makes the risk more persistent and more dangerous.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs users to place an API key directly into multiple local configuration files but provides no warning about secret sensitivity, least-privilege handling, file permissions, rotation, or safer secret-loading mechanisms. This increases the chance of credential leakage through dotfile syncing, screenshots, backups, repository commits, or local compromise.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide instructs users to execute a remote installer directly from GitHub via curl | bash, which grants arbitrary code execution to whatever content is served at that URL at install time. For a debugging-focused skill, this exceeds minimally necessary behavior and creates a serious supply-chain and remote-code-execution risk, especially because the script is not reviewed inline or pinned by integrity hash.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions direct downloading instrumentation files from GitHub and modifying application source files and runtime configuration, which expands the skill from passive debugging into codebase modification and runtime instrumentation. In context, this broadens trust assumptions and attack surface: compromised upstream content or mistaken edits could alter app behavior, expose telemetry, or introduce insecure dependencies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The guide requires generating and saving a patch file of project changes while also instructing users to replace placeholders with apiKey, appName, and projectId. A unified diff can therefore capture secrets or identifiers and persist them in .syncause/installation.patch, creating an easy path for accidental disclosure through logs, support uploads, or version control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to add and install a package directly from a remote GitHub release URL, which introduces external code into the target project without any explicit warning, trust validation, checksum verification, or pinning to a vetted package source. In the context of an agent skill, this is dangerous because it can silently trigger network access and supply-chain compromise, especially since the dependency is then meant to run as part of application startup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs insertion of initialization code into the project's entry file so that imported third-party code executes at startup, but it does not clearly warn the user that application source files will be modified or that new code will run automatically on every launch. This is particularly risky because the inserted code initializes an externally sourced package with credentials/config values, creating a strong path to persistent code execution, telemetry exfiltration, or application instability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file contains step-by-step destructive configuration changes, including deleting entries from pom.xml and removing token properties. While the guide is an uninstall document, it does not warn users that they are editing project configuration and credential-related settings or recommend backing up changes before proceeding.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The installation command fetches executable content from an external source at runtime, creating a dependency on the integrity of GitHub-hosted content and the account/repository serving it. While external fetching alone is not always malicious, here it becomes dangerous because the fetched content is immediately executed and the skill's debugging context does not justify such high-trust installation behavior.

Content

Scanner excerpt · references/install/nodejs.md (reported line 8)May include surrounding context.

1. Automated Installation

Identify the project type (Next.js, TypeScript, or JavaScript) and run the installer directly from GitHub:

bash
curl -sL https://raw.githubusercontent.com/Syncause/ts-agent-file/v1.6.0/install_probe.sh | bash

Note: For Next.js projects, the script downloads instrumentation.node.next.ts from GitHub (default v1.3.0) and renames it to instrumentation.node.ts.

Static analysis

No suspicious patterns detected.