Back to skill

Security audit

Deep Research.Bak

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent deep-research/report skill, but it needs review because it writes persistent local reports/state, can spawn continuation agents, uses optional third-party tools with API keys, and has unsafe citation/HTML handling.

Review before installing. Use it only with research topics and output paths you are comfortable storing locally, approve any file writes or auto-open behavior, avoid untrusted Markdown inputs, and do not configure search provider API keys or install the optional CLI unless you trust and pin those dependencies.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/verify_citations.py:145
Finding

Report-Controlled Server-Side Request Forgery in Citation Verification

Content
View full analysis
Tuple[bool, str]: """ Verify URL is accessible (2025 CiteGuard enhancement). Returns (accessible, status_message) """ if not url: return False, "No URL" try: # HEAD request to check accessibility without downloading req = request.Request(url, method='HEAD') req.add_header('User-Agent', 'Mozilla/5.0 (Research Citation Verifier)') with request.urlopen(req, timeout=10) as response: if response.status == 200: return True, "URL accessible" else: return False, f"HTTP {response.status}" ``` The verification flow passes report-controlled data directly to that function: ```python # STEP 3: Check URL accessibility (if no DOI or DOI failed) if entry['url'] and result['status'] != 'verified': url_ok, url_status = self.verify_url(entry['url']) ``` ### Technical Analysis The verifier treats bibliography URLs as trusted network destinations. It does not: - Resolve and inspect the destination IP address. - Reject loopback, priva ...[truncated 2126 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/md_to_html.py:44
Finding

Stored HTML Injection and Script Execution in Generated Reports

Content
View full analysis
str: """Convert main content sections to HTML""" html = markdown # Remove title and front matter (first ## heading is handled separately) lines = html.split('\n') processed_lines = [] skip_until_first_section = True for line in lines: # Skip everything until we hit "## Executive Summary" or first major section if skip_until_first_section: if line.startswith('## ') and not line.startswith('### '): skip_until_first_section = False processed_lines.append(line) continue processed_lines.append(line) html = '\n'.join(processed_lines) # Convert headers # ## Section Title →

Section Title

html = re.sub( r'^## (.+)$', r'

\1

', html, flags=re.MULTILINE ) # ### Subsection →

Subsection

html = re.sub( r'^### (.+)$', r'

\1

', html, flags=re.MULTILINE ) # #### Subsubsection →

Title

html = re.sub( r'^#### (.+)$', r'

\1

', html, flags=re.MULTILINE ) ``` Bibliography text and URL attributes are also interpolated without HTML escaping: ```python def _convert_bibliography_section(markdown: str) -> str: """Convert bibliography section to ...[truncated 4229 chars]
Remediation
View remediation
` tags, event-handler attributes, malformed tags, quote-breaking URLs, SVG payloads, encoded payloads, and unsafe URI schemes. ]]>

T08 · Insecure Dependencies

Warning
Location
README.md:18
Finding

Unpinned Third-Party Tool Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Rogue AgentSelf-Modification, Session Persistence
Findings (37)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description describes a broad research workflow system with analysis, synthesis, verification, and credibility assessment. The provided code chunk does not perform research at all; it only manages citation metadata and formats bibliographies. Citation tracking is consistent with part of the description, but the primary purpose is materially narrower than claimed. Additionally, the code includes file output functionality (export_to_file) despite no declared permissions, which is an undeclared capability relevant to resource access. Therefore, the description does not accurately represent the actual behavior of this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a substantive research pipeline with analysis, verification, and credibility assessment. The actual code only transforms markdown text into HTML, including special handling for sections and bibliography formatting. While this could be a supporting component within a larger research-reporting system, the supplied chunk itself does not implement the core declared capabilities and instead has a materially different primary purpose: presentation/rendering.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a functioning research engine that performs deep research, source collection, verification, synthesis, and citation-backed reporting. The supplied code mostly defines data structures and phase instructions, then prints those instructions and saves empty/intermediate state to disk. Although the prompts mention tools like WebSearch/WebFetch and structured outputs, the code itself never invokes such tools or implements the claimed research actions. Its real behavior is a workflow shell/orchestrator for a human or external agent ('Claude should execute each phase using the displayed instructions'), plus file persistence. That is a material difference in primary purpose and capability, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a research-generation skill whose primary function is to perform deep research and synthesize findings into a report. The supplied code does not perform research at all: it only validates the formatting and completeness of an existing markdown report. Its checks are structural and heuristic (required sections, citation numbering, bibliography entries, placeholders, truncation phrases, broken local links), not substantive research, source retrieval, citation tracking across external sources, or credibility scoring. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a broad research skill that gathers and synthesizes sources into citation-backed reports. The supplied code chunk is much narrower: it validates citations in an already-written report by extracting bibliography entries, resolving DOIs, checking title/year consistency, probing URLs, and applying heuristics for suspicious patterns. Citation verification is consistent with one small part of the description, but the primary purpose is materially different from the claimed end-to-end research/reporting capability. No undeclared sensitive permissions appear, but the behavior is substantially narrower and different than advertised.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a research pipeline that conducts comprehensive research, synthesizes multiple sources, tracks citations, verifies claims/sources, and produces citation-backed reports. The code shown does none of that primary work. Instead, it is a QA/validation script for checking whether an already-generated HTML report correctly reflects a Markdown report and contains expected formatting/structure. While it does include limited citation/bibliography presence checks, those are formatting validation steps rather than research, source verification, or credibility scoring. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs installation of an external CLI, adding a third-party toolchain and prompting configuration of provider API keys inside the research workflow. This materially expands the trust boundary, can lead to secret handling/exposure risks, and enables outbound data transfer through tools not essential to the declared skill purpose.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/research_engine.py (reported line 440)May include surrounding context.

python
"""
        }

        return instructions.get(phase, "No instructions available for this phase")

    def execute_phase(self, phase: ResearchPhase) -> Dict[str, Any]:
        """Execute a research phase"""

Hidden Instructions

High
Category
Prompt Injection
Confidence
95% confidence
Finding

The template embeds substantial operational instructions inside HTML comments, including tool-use guidance, output sizing rules, and citation-tracking requirements. Hidden instructions are dangerous because they can steer agent behavior in ways not visible to end users or higher-level reviewers, reducing transparency and making risky actions like progressive file writes easier to smuggle into execution flow.

Content

Scanner excerpt · templates/report_template.md (reported line 3)May include surrounding context.

md
# Research Report: [Topic]

<!-- =============================================================================
PROGRESSIVE FILE ASSEMBLY STRATEGY (2025 - Unlimited Length):

This report is generated section-by-section using progressive file assembly.

Hidden Instructions

High
Category
Prompt Injection
Confidence
88% confidence
Finding

These hidden comments contain writing and citation rules rather than overtly harmful commands, but they are still concealed behavioral instructions that influence model output without user visibility. This undermines prompt transparency and creates a channel for future injection of stronger hidden directives in the same pattern.

Content

Scanner excerpt · templates/report_template.md (reported line 55)May include surrounding context.

md
============================================================================= -->

<!-- WRITING STANDARDS (Apply to EACH section): -->
<!-- - PRECISION: Each word deliberately chosen, carries intention -->
<!-- - ECONOMY: No fluff, eliminate fancy grammar, unnecessary adjectives -->
<!-- - CLARITY: Use exact numbers, specific data, precise technical terms -->

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · templates/report_template.md (reported line 407)May include surrounding context.

md
**Word Count:** [Approximate count]
**Research Duration:** [Time taken]
**Generated:** [Date and time]
**Validation Status:** [Passed with X warnings / Passed without warnings]

---

Hidden Instructions

High
Category
Prompt Injection
Confidence
86% confidence
Finding

The end-of-template comments include concealed instructions about required report length and comprehensiveness. While not directly malicious, they continue the pattern of hidden behavioral control, which is risky in an agent skill because it obscures operational constraints and can amplify resource usage or unexpected output volume.

Content

Scanner excerpt · templates/report_template.md (reported line 411)May include surrounding context.

md
---

<!-- END OF TEMPLATE -->
<!-- Remember: Write COMPREHENSIVE, DETAILED reports -->
<!-- Target 2,000-5,000 words minimum, more for deep modes -->
<!-- Include specific data, evidence, and analysis throughout -->

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs loading reference files, writing outputs to a user Documents path, and relies on network-backed research behavior, yet it declares no tool scope or permissions boundary. Missing explicit scope increases the chance that an agent invokes file and network capabilities without user-visible consent or least-privilege constraints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill specifies creating files in a fixed user directory and automatically opening HTML/PDF outputs, but it does not warn users about filesystem modification or application-launch side effects. Automatic writes and launches can surprise users, overwrite data, expose sensitive report contents on-screen, or trigger unsafe handling of generated content without an explicit approval step.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The protocol directs the agent to append to report files, update continuation state, and delete the continuation state file automatically, but does not require explicit user notice or consent for these data-modifying actions. In a recursive continuation workflow, silent writes and cleanup increase the chance of unexpected file modification, overwriting, or loss of forensic/debugging state without the user realizing the agent is mutating local data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The continuation protocol instructs the agent to execute a local command (python scripts/validate_report.py --report [path]) even though the skill’s stated purpose is research synthesis and report generation. Allowing a research skill to run arbitrary local validation scripts expands its privilege boundary, creating risk of unintended code execution, abuse of a compromised script, or execution against attacker-influenced paths.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The methodology explicitly instructs the agent to invoke Bash to run date +%Y-%m-%d, introducing shell execution into a research workflow that does not require arbitrary command execution. Even though the example command is harmless, permitting Bash use broadens the skill's execution surface and can normalize unsafe tool use or become a pivot point if the instruction is later generalized or influenced by untrusted input.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The design intentionally uses progressive writes to enable effectively unlimited report length across multiple tool calls and to survive context compaction. In context, this is functional for large research outputs, but it also creates session-persistent state and artifacts that can accumulate sensitive information and be resumed or reused in ways the user may not expect.

Content

Scanner excerpt · reference/report-assembly.md (reported line 27)May include surrounding context.

md
## Progressive Section Generation

**Core Strategy:** Generate and write each section individually using Write/Edit tools. This allows unlimited report length while keeping each generation manageable.

### Phase 8.1: Setup

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly instructs persistent writes to the user's home directory and creation of a durable sources.json provenance file. While report generation may justify writing the main output, the instructions expand persistence beyond the immediate response and create retained artifacts without any clear consent or minimization controls, which increases privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file operations create directories and append content in the user's home directory, but the instructions shown do not include any user-facing warning or consent checkpoint about these filesystem side effects. Even for a research skill, silent writes can surprise users, overwrite existing work, or persist sensitive material locally without informed approval.

Content

No source excerpt is available for this finding.

Unbounded Output

Medium
Category
Output Handling
Confidence
60% confidence
Finding

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

Content

Scanner excerpt · reference/report-assembly.md (reported line 83)May include surrounding context.

md
7. **Bibliography** (CRITICAL)
   - EVERY citation from citations_used list
   - NO ranges, NO placeholders, NO truncation
   - Tool: Edit(append)

8. **Methodology Appendix**

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to save a second copy under ~/.claude/research_output/ introduces undisclosed duplication into an internal tracking location unrelated to the user's requested deliverable. This creates unnecessary data exposure and retention risk, especially if reports contain sensitive research topics, proprietary material, or user-supplied content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Saving an additional copy to ~/.claude/research_output/ is a hidden side effect because users may believe only the requested report file is being created. Undisclosed duplication is especially risky for confidential or regulated content because it broadens where the data resides and may bypass user expectations for deletion or access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The top-level docstring and CLI description present the file as actively orchestrating comprehensive research across sources with verification and synthesis. In reality, the implementation prints templated instructions and writes state files, explicitly noting that Claude should perform the real work separately, which contradicts the documentation's implication of direct execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persists research state containing the user's query, metadata, and potentially future source/findings content under the home directory without clear user warning or consent. In a research skill, queries may include confidential business topics, internal project names, or sensitive investigative context, so silent local persistence increases privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.