Back to skill

Security audit

Elcano Superpowers

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent development workflow, but it includes deployment-affecting actions like git push and PM2 restarts without a clear final user approval gate.

Review this skill before installing if your repositories or PM2 services are connected to shared, staging, or production systems. It is best used only where the agent is expected to make commits and deployment-style changes, and users should require explicit approval before git push, PM2 restart, or broad git checkout operations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs git push, PM2 restarts, and post-change operational steps without requiring an explicit user confirmation checkpoint immediately before those actions. In an agentic workflow, these are state-changing operations that can affect production code or running services, so baking them into the default flow increases the risk of unintended deployment or service disruption.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

This natural-language instruction narrows activation to requests from specific individuals, which is an organizational usage policy embedded in the skill text. While not a security flaw by itself, it is a policy-style constraint expressed in natural language and not framed as optional or justified context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.