Back to skill

Security audit

Claude Code Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Claude Code control tool, but it grants broad command, file, tool, backend, and MCP subprocess authority with weak guardrails.

Review this carefully before installing. Use only in trusted, isolated project directories; prefer plan/default permission modes; avoid skip-permissions and bypassPermissions; restrict allowed tools to the minimum needed; use only authenticated local or trusted HTTPS backends; do not put real tokens in MCP JSON configs; pin MCP server packages instead of npx -y floating versions; and run third-party MCP servers with a minimal environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/index.ts:9
Finding

Configurable Remote Backend Permits Plaintext Transmission of Sensitive Control Data

Content
View full analysis
{ const url = `${SASHA_DOCTOR_URL}${PREFIX}${endpoint}`; const options: RequestInit = { method, headers: { 'Content-Type': 'application/json' }, }; if (body) { options.body = JSON.stringify(body); } try { const response = await fetch(url, options); return await response.json() as ApiResponse; } catch (error) { return { ok: false, error: (error as Error).message }; } } ``` The streaming endpoint uses the same configurable URL without transport or authentication enforcement: ```typescript const url = `${SASHA_DOCTOR_URL}${PREFIX}/session/send-stream`; try { const response = await fetch(url, { method: 'POST', headers: { 'Content-Type': 'application/json' }, body: JSON.stringify({ name, message, timeout: parseInt(options.timeout) }) }); ``` The documentation explicitly suggests an insecure remote endpoint: ```bash # Default: http://127.0.0.1:18795 export SASHA_DOCTOR_URL="http://your-server:port" # Alias also supported: export CLAUDE_CODE_API_URL="http://your-server:port" ``` ### Technical Analysis The backend URL is entirely controlled through `SASHA_DOCTOR_URL`, and the implementation does not: - Require HTTPS for non-loopback destinations. - Restrict the destination to trusted hosts. - Authenticate requests to the backend. - Warn the user when crossing the local trust boundary. - Validate response bodies against endpoint-specific ...[truncated 2047 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/mcp/client.ts:13
Finding

MCP Subprocesses Inherit the Entire Parent Environment

Content
View full analysis
{ logger.info(`Creating client for ${id}...`); const transport = new StdioClientTransport({ command: config.command, args: config.args, env: { ...Object.fromEntries( Object.entries(process.env) .filter(([_, v]) => v !== undefined) .map(([k, v]) => [k, v as string]), ), ...(config.env || {}), }, }); ``` ### Technical Analysis Every configuration-selected MCP subprocess receives a copy of the complete parent-process environment. This can include credentials unrelated to the selected MCP server, such as: - Cloud provider access keys. - GitHub, Slack, and package-registry tokens. - Database credentials. - CI/CD secrets. - Proxy credentials. - Internal service tokens. This violates least privilege. An MCP server normally needs only a minimal process environment plus a small set of explicitly declared credentials. Because `config.command` and `config.args` determine the executable, any malicious or compromised configured process automatically gains access to every environment variable available to the parent. The explicit `config.env` object does not mitigate the issue because it is merged on top of the already copied global environment. ### Attack Path 1. An attacker causes a malicious executable to be added as an MCP server, compromises an existing MCP package, or publishes a malicious update to an unpinned package. 2. The application initializes or resumes that MCP server. 3. `createClient` launches the executable using `StdioClientTransport`. 4. The implementation copies all values from `process.env` into the child environment. 5. The malicious subprocess reads unrelated creden ...[truncated 780 chars]
Remediation
View remediation
= {}; for (const key of ["PATH", "HOME", "TMPDIR"]) { const value = process.env[key]; if (value !== undefined) env[key] = value; } Object.assign(env, validatedServerEnvironment); ``` 3. Define a per-server allowlist of environment-variable names. 4. Resolve secret references through an operating-system secret store instead of placing values directly in general configuration. 5. Require explicit user approval before granting a newly configured MCP server access to credentials. 6. Run third-party MCP servers in a sandbox or container with restricted filesystem, network, and process permissions. 7. Display the names—not values—of environment variables that will be shared before process launch. 8. Add tests that verify unrelated environment variables are absent from child processes. ]]>

T08 · Insecure Dependencies

Error
Location
mcp_config.example.json:2
Finding

Example Configuration Automatically Downloads and Executes Unpinned MCP Packages

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
mcp_config.example.json:8
Finding

MCP Credentials Are Encouraged and Persisted in Plaintext Configuration

Content
View full analysis
{ try { await fs.mkdir(path.dirname(CONFIG_PATH), { recursive: true }); await fs.writeFile(CONFIG_PATH, JSON.stringify(config, null, 2)); } catch (error) { throw error; } } ``` ### Technical Analysis The example’s `env` fields encourage users to replace placeholders with real tokens. The configuration writer then stores the entire object as human-readable JSON without: - Secret-store integration. - Encryption. - Redaction. - An explicit restrictive file mode. - A check that the destination is outside a repository. - Ownership or permission validation. The resulting permissions depend on the host process’s umask and the state of any pre-existing file. Plaintext tokens can consequently be exposed through local file access, backups, diagnostics, support bundles, or accidental source-control commits. ### Attack Path 1. A user copies `mcp_config.example.json` to the active configuration path. 2. The user replaces placeholder strings with live GitHub or Slack credentials. 3. Configuration management calls `updateMcpConfig`, or the user saves the file directly. 4. The credentials remain in plaintex ...[truncated 802 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (30)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a tool for controlling Claude Code through the MCP protocol with broad automation capabilities. The actual code chunk is instead a local persistent chat-store example: it defines chat/session state, persists it via IndexedDB, supports session/message CRUD operations, and waits for hydration before use. This is a materially different primary purpose. The code does not demonstrate any of the claimed capabilities such as MCP communication, command execution, filesystem access, code search, or programmatic use of Claude Code tools.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad Claude Code control interface over MCP with command execution, file operations, code search, and tool orchestration. The actual code shown does not implement or expose any of those behaviors; it merely re-exports store-related modules for persistence and synchronization. This is a materially different purpose from the declared functionality, so the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a powerful Claude Code control skill with MCP-based tool access, command execution, file operations, and code search. The supplied code does none of that. It only provides a Zustand-compatible storage backend backed by IndexedDB with localStorage fallback, including SSR-safe localStorage handling and persistence methods. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description claims a broad Claude Code control interface over MCP with command execution, file operations, code search, and tool orchestration. The supplied code chunk does none of that. It is a local state-management helper for Zustand persistence, adding hydration tracking and update helpers. While it can accept an abstract storage backend for persisted state, that is an implementation detail of client-side/store persistence, not a Claude Code control mechanism or file/system access feature. Therefore the actual behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a powerful Claude Code control/integration skill with command execution, filesystem access, code search, and tool orchestration. The provided code chunk does none of those things. It is purely an in-memory state synchronization utility module: deep-merging objects, selecting non-function fields, reconciling updated state by timestamps, merging chat sessions/messages, and merging key-value stores. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · examples/basic-mcp.ts (reported line 19)May include surrounding context.

ts
async function main() {
  // Optional: Set a custom config path
  setConfigPath("./mcp_config.json");

  // Initialize the MCP system
  console.log("Initializing MCP system...");

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · src/index.ts (reported line 407)May include surrounding context.

ts
}
  });

// Send message to a persistent session
program
  .command('session-send <name> <message>')
  .description('Send a message to a persistent session')

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · src/mcp/actions.ts (reported line 352)May include surrounding context.

ts
const configStr = await fs.readFile(CONFIG_PATH, "utf-8");
    return JSON.parse(configStr);
  } catch (error) {
    logger.error(`Failed to load MCP config, using default config: ${error}`);
    return DEFAULT_MCP_CONFIG;
  }
}

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

md
# Use GPT-4o via OpenAI-compatible endpoint
claude-code-skill session-start gpt-task -d ~/project \
  --model gpt-4o \
  --base-url https://api.openai.com/v1

# Use any OpenRouter model
claude-code-skill session-start mixtral-task -d ~/project \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README explicitly demonstrates command execution and file-writing primitives without a prominent warning that these actions can modify the local system or project state. In a skill designed for programmatic tool control, users may copy examples directly, so normalizing destructive-capable operations without safety framing increases the risk of accidental misuse or over-trusting agent actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes a bypassPermissions mode that skips all prompts, but labels it only as 'dangerous' without clearly explaining that it enables unattended command execution and file modification. Given this skill's purpose—remote control of code tools and agents—this setting materially raises the chance of destructive or unintended actions if enabled casually.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises powerful capabilities including MCP control, network access, command execution, and file operations, but the frontmatter does not declare any explicit tool scope or permission boundaries. That omission makes it easier for a caller or wrapper to invoke the skill with overly broad authority, reducing transparency and increasing the chance of unsafe execution in an agentic context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation prominently encourages command execution, file writes, session automation, and broad tool orchestration, but it does not lead with a strong safety warning about the consequences of autonomous edits and shell access. In an agent skill, that increases the likelihood of unsafe use because users may copy dangerous examples without understanding the trust boundary or blast radius.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill explicitly supports auto-approving tools, which is a form of autonomous decision-making that can let an agent execute commands or operate on files without human review. In a tool-control skill, that meaningfully raises the chance of unsafe or unintended actions, especially if the whitelist is broad or includes shell commands.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

md
# With permission mode (plan = preview changes before applying)
claude-code-skill session-start review -d ~/project --permission-mode plan

# With tool whitelist (auto-approve these tools)
claude-code-skill session-start safe -d ~/project \
  --allowed-tools "Bash(git:*),Read,Glob,Grep"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation exposes a bypassPermissions mode and labels it only as 'dangerous,' without clearly explaining that it can enable unattended destructive actions such as arbitrary command execution, mass file modification, or exfiltration through enabled tools. In this skill context, which is specifically designed to control tools and files autonomously, documenting a full bypass mode without robust guardrails materially increases risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code creates a persistent chat store using IndexedDB and stores full chat session/message content, which can affect user data privacy by retaining conversations across runs. While the comments describe persistence technically, there is no explicit user-facing warning or disclosure that chat contents will be stored locally and recovered automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The bash command forwards arbitrary user-supplied shell commands to the backend with no validation, no confirmation prompt, and no contextual safety checks. Because this skill's purpose is remote programmatic control of Claude Code tools, this creates a straightforward path to destructive command execution, credential access, or local data exfiltration if the CLI is used by an untrusted workflow or prompt chain.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The generic call <tool> entrypoint allows invocation of any Claude Code tool with attacker-controlled JSON arguments, effectively bypassing the narrower safety affordances of dedicated subcommands. In a skill whose core function is broad MCP tool control, unrestricted tool dispatch greatly expands the attack surface and can enable chaining of sensitive capabilities like file access, command execution, or stateful agent manipulation.

Content

Scanner excerpt · src/index.ts (reported line 128)May include surrounding context.

ts
}
  });

// Call any tool
program
  .command('call <tool>')
  .description('Call any Claude Code tool with JSON args')

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The option to auto-approve allowed tools reduces human oversight over tool usage and supports more autonomous agent execution. While autonomy is a stated feature of the skill, combining auto-approval with tools such as Bash, Read, or Edit can enable unintended or unsafe actions at scale, especially when driven by untrusted prompts or external orchestration.

Content

Scanner excerpt · src/index.ts (reported line 297)May include surrounding context.

ts
.option('-b, --base-url <url>', 'Custom API endpoint (for Gemini/GPT proxy)')
  .option('--permission-mode <mode>', 'Permission mode: acceptEdits, bypassPermissions, default, delegate, dontAsk, plan', 'acceptEdits')
  .option('--fork-session', 'Create a new session ID instead of reusing (use with --resume)')
  .option('--allowed-tools <tools>', 'Comma-separated list of tools to auto-approve (e.g. Bash,Read,Edit)')
  .option('--disallowed-tools <tools>', 'Comma-separated list of tools to deny')
  .option('--tools <tools>', 'Limit available tools (use "" to disable all, "default" for all)')
  .option('--max-turns <n>', 'Maximum agent loop turns')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI exposes multiple permission-bypassing and auto-approval controls, including permissive permission modes and a --skip-permissions flag that maps directly to dangerouslySkipPermissions = true, without any runtime confirmation, warning gate, or environment-based restriction. In a skill specifically designed to control Claude Code, these options materially increase the chance of unsafe file edits, command execution, or other high-risk tool actions being performed silently or with reduced human oversight.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The module allows CONFIG_PATH to be changed dynamically via setConfigPath and later writes arbitrary JSON to that path with fs.writeFile. If an untrusted caller can influence the path, this becomes an arbitrary file write primitive that can overwrite application files, user files, or security-relevant configuration on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code updates and persists MCP server configuration, which changes user/system state, but the relevant functions only log errors and do not provide any visible user disclosure, confirmation, or explanatory comment about the write side effects. The same pattern also applies to pause/remove flows that update the config and delete in-memory client registrations, making these state-changing operations insufficiently disclosed within this code file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The code executes MCP requests against a client, which may transmit user or system data to an external server, but this file provides only internal logging and no user-facing warning or explanatory documentation about that behavior. Because the data flow and external effects are not disclosed here, users may not realize that request contents are being sent to connected MCP servers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The client spawns an MCP server process while forwarding nearly the entire parent process environment, only filtering out undefined values. In this skill's context, the spawned process is controlled by config.command/config.args and the skill is explicitly designed to execute commands and control external tools, so any untrusted or compromised MCP server would automatically receive secrets such as API keys, cloud credentials, tokens, and internal configuration from the host environment.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"author": "enderfga",
  "license": "MIT",
  "dependencies": {
    "commander": "^12.1.0",
    "node-fetch": "^3.3.2"
  },
  "devDependencies": {

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/index.ts:9