Back to skill

Security audit

Web Security Client-Side Scanner 1773654191

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed client-side web security assessment skill with real testing risk, but its behavior is purpose-aligned and includes scope and safety limits.

Install only if you intend to run authorized client-side web security assessments. Before use, clearly state the target origin, whether subdomains are included, whether authenticated testing is allowed, and whether active scanners such as nuclei are approved; otherwise keep it to passive and low-risk browser-facing review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger language is broad enough that ordinary requests like 'test the security of this site' may invoke a penetration-testing workflow without clear confirmation of authorization, scope, or risk. In agent systems, overbroad auto-triggering can cause sensitive security actions to start in contexts where the user only wanted high-level advice or defensive review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill is framed as client-side/front-end only, but the prescribed use of subdomain discovery and broad endpoint enumeration can expand activity beyond a browser-facing assessment into wider infrastructure reconnaissance. In an automated agent context, this scope drift can cause unauthorized or unexpected testing of assets the user did not intend to include.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Although the skill claims to be non-destructive and client-side focused, it instructs active scanning and package auditing tools that may probe targets or analyze dependencies not strictly limited to delivered frontend assets. This creates ambiguity that can lead an agent to perform noisier or broader actions than the user expects, increasing operational and authorization risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Automatically writing a report file to the current working directory without an explicit user-facing notice can create unintended side effects, especially in shared or sensitive environments. While low severity, silent file creation reduces user control and may overwrite expectations about a read-only or analysis-only interaction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.