Back to skill

Security audit

systematic-debugging

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent debugging guide, but it needs review because it can lead an agent to enumerate local keychains/signing identities and log sensitive runtime context without clear gating or redaction.

Review before installing. This skill can be useful for disciplined debugging, but users should require explicit approval before running credential, keychain, signing-identity, or environment-dump diagnostics, and should redact paths, stack traces, and environment values from shared logs or CI output.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill explicitly recommends diagnostic commands that enumerate keychain contents and signing identities during troubleshooting. Even though framed as debugging, this can expose sensitive environment/configuration details and credential metadata in logs or agent output, which may aid credential discovery or lateral movement if logs are accessible.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
env | grep IDENTITY || echo "IDENTITY not in environment"

   # Layer 3: Signing script
   echo "=== Keychain state: ==="
   security list-keychains
   security find-identity -v

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The security find-identity -v example can reveal available signing identities and related metadata, which are sensitive operational details. In an automated agent context, encouraging such enumeration increases the chance that secrets-adjacent information is surfaced into transcripts, CI logs, or other shared artifacts.

Content

Scanner excerpt · SKILL.md (reported line 99)May include surrounding context.

md
# Layer 3: Signing script
   echo "=== Keychain state: ==="
   security list-keychains
   security find-identity -v

   # Layer 4: Actual signing

Context Leakage

High
Category
Data Exfiltration
Confidence
92% confidence
Finding

The example recommends logging sensitive execution context, including the full current working directory and a stack trace, for 'forensics'. In real systems, stack traces and path information can expose internal code structure, usernames, repository locations, secrets embedded in paths, or other sensitive operational details if logs are accessible to attackers or lower-privileged users.

Content

Scanner excerpt · defense-in-depth.md (reported line 73)May include surrounding context.

text

### Layer 4: Debug Instrumentation
**Purpose:** Capture context for forensics

```typescript
async function gitInit(directory: string) {

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill when encountering "any bug, test failure, or unexpected behavior," which covers a very wide range of routine technical work. It does not provide narrower trigger constraints or exclusion conditions, so the activation scope is ambiguous and could cause unintended invocation in many ordinary contexts.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · condition-based-waiting.md (reported line 89)May include surrounding context.

md
**❌ Polling too fast:** `setTimeout(check, 1)` - wastes CPU
**✅ Fix:** Poll every 10ms

**❌ No timeout:** Loop forever if condition never met
**✅ Fix:** Always include timeout with clear error

**❌ Stale data:** Cache state before loop

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly recommends logging process.env.NODE_ENV alongside a captured stack trace and contextual data during debugging, but it does not warn that environment-derived values and stack traces can expose sensitive information in CI logs, shared test output, or developer consoles. In a debugging skill, this guidance is more likely to be copied directly into real code or test helpers, increasing the chance of inadvertent leakage of secrets, internal paths, usernames, repository structure, or other sensitive runtime context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This pressure-test scenario is framed as an imperative decision exercise without clear constraints limiting when or how it should be used, which can push an agent to bypass the referenced systematic debugging process under urgency. The content explicitly pressures immediate action, discourages questions, and rewards shortcut behavior, making it more likely that the surrounding skill is misapplied in production incidents and that safety or verification steps are skipped.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file is not a debugging procedure artifact; it is a behavioral pressure scenario that forces the reader to choose under authority and social pressure. In a skill intended to enforce systematic debugging discipline, that framing can train or normalize bypassing root-cause analysis in favor of deference, which undermines the reliability and safety purpose of the skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The scenario explicitly cites the skill's requirements to read the middleware completely and understand dependencies, then applies social and authority pressure to steer the user toward options that may violate those requirements. That makes the content more dangerous in this skill context, because it directly conditions users to disregard the skill's safeguards when pressured by seniority, time pressure, or group dynamics.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.