Back to skill

Security audit

Original task qualification

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated purpose, with disclosed SameDayDesk network calls and local private attempt files, and I found no active malicious behavior.

Install only if you intend to submit a public original-task request to SameDayDesk and later read the same private attempt. Use separate cache and private directories, keep the private directory protected because it contains the generated registration secret, and do not provide or expose any admin/operator token to this skill.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose presents the skill as a limited qualification/read client, but the detected behaviors include cryptographic token issuance, request canonicalization, secret comparison, and random identifier generation. Those capabilities are consistent with authentication, session handling, or request signing logic that can materially expand trust and security impact beyond the user-facing description, making it harder for reviewers and operators to assess what the skill can actually do.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
directory. A description match does not run the task. The installed command is `scripts/cli.mjs`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
directory. A description match does not run the task. The installed command is `scripts/cli.mjs`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
directory. A description match does not run the task. The installed command is `scripts/cli.mjs`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
directory. A description match does not run the task. The installed command is `scripts/cli.mjs`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
directory. A description match does not run the task. The installed command is `scripts/cli.mjs`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
directory. A description match does not run the task. The installed command is `scripts/cli.mjs`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
directory. A description match does not run the task. The installed command is `scripts/cli.mjs`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
[client/original-task-client.tar.gz](client/original-task-client.tar.gz)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · client/source/server/lib/original-task/action.mjs (reported line 29)May include surrounding context.

js
};
const SPEND_KEYS = new Set(["checkout", "maxSpend", "payment", "reward", "spend", "wallet", "x402"]);
const LABEL_KEYS = new Set(["agent", "authenticated", "declaredSource", "operator", "role", "source"]);
const FORBIDDEN_MEMBER = ["collect.mjs", "operator-http.mjs", "event-guard.mjs", "deps.mjs", "store.mjs", "mount.mjs", ".sql", ".env"];
const DEPENDENCY_IMPORT = new RegExp(String.raw`(?:\bfrom|\brequire\()\s*['"](?:pg|express)['"]`);
const DATABASE_URL = "postgres" + "://";

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Referencing a Bearer CORRESPONDENCE_ADMIN_TOKEN for a client whose stated purpose is limited qualification/read access introduces unjustified privileged access. If an agent, wrapper, or future implementation consumes this descriptor and honors the operator fields, compromise or misuse of that token could allow broad administrative visibility and state changes across correspondence tasks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The contributionProfile function expands the contract from a narrowly scoped original-task qualification/read flow into a reusable contribution/foundry profile with added capabilities such as bounded_foundry_use and voluntary_reusable_contribution. That creates a privilege and purpose mismatch: code in this skill can mint terms for broader reuse than the declared skill metadata, increasing the chance of unauthorized access patterns or capability creep if invoked by surrounding components.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

For a skill described only as qualifying one public original task and reading the corresponding private attempt, generating reusable contribution/foundry terms is not justified by the stated business purpose. The mismatch is dangerous because security review, operator expectations, and policy controls may assume limited read/qualification behavior, while the code quietly enables broader standing-scope contribution semantics.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description says it only qualifies a public task and reads a private attempt, but this code implements a full submit command that transmits task data and local private-state directory contents to a remote correspondence service. That is a material capability expansion beyond the declared purpose, and could cause unintended disclosure or modification of user/workflow state if invoked by an orchestrator or unsuspecting caller.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permission boundaries even though its documented behavior includes network access and environment/runtime-dependent execution via Node.js. Without an allowlist for permitted tools and connectivity, an agent platform may grant broader capabilities than intended, increasing the chance of unintended outbound requests, data exposure, or misuse of ambient environment access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The descriptor includes an operator capability to list task-bearing projects and post dispositions using an administrative bearer token, which exceeds the declared user-facing scope of qualifying one public original task and reading the same private attempt. Even if this JSON file itself does not execute requests, shipping this capability in the skill expands the accessible attack surface and can enable queue enumeration or unauthorized workflow actions if the client or surrounding tooling exposes it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill for qualifying a single public SameDayDesk original task and reading the related private attempt correspondence. This file implements broad local capabilities to create secret files, write arbitrary JSON, replace existing JSON atomically, and manage lock files, which are not obviously required to merely qualify and read correspondence.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest is narrowly scoped to qualifying one public task and reading a private attempt, but this module exposes a reusable API client that can send arbitrary HTTP methods and JSON bodies to any validated HTTPS origin or localhost path. That is a more general network capability than the stated purpose alone justifies, especially in a shared utility module.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill fetches a live discovery descriptor over the network and later uses fetched metadata to drive further client execution, but this file provides no confirmation prompt, user-facing log, or inline warning to disclose that external network communication will occur. For a code file, outbound HTTP requests that may transmit system context such as the requested URL should be disclosed somewhere visible to the user unless clearly surfaced elsewhere.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The submit path accepts a caller-provided --base-url and then sends local task and directory data to that endpoint as long as it matches the hardcoded path and is either the production origin or loopback HTTP. For a skill whose stated role is only qualification/read access, exposing configurable remote submission unnecessarily enlarges the attack surface and enables redirection to a local service for SSRF-style interaction or unintended data exfiltration to an unexpected backend.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The notes state "This file does not call the network," but the same descriptor specifies visitor and operator HTTPS endpoints, HTTP methods, and submit/read commands that drive networked interactions. While the JSON file itself is declarative, the note overstates the absence of network behavior in a way that contradicts the operational meaning of the descriptor.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The submit command writes receipt.json and retrieval.json into the provided directory, but this file-writing behavior is only implicit in the implementation. In this file there is no confirmation prompt, comment, or user-facing notice explaining that running the command will create or overwrite files in the target directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The read command performs a local file write via writePrivate to retrieval.json as part of normal execution, including in the grant_expired branch. This side effect is not disclosed by a prompt, comment, or visible message in this file, so users may not realize that a read operation modifies on-disk state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The minimalEnv function hard-codes LANG to C.UTF-8 for spawned subprocesses, which imposes a specific locale regardless of the user's environment or preferences. This matches the language/locale policy violation category because the file does not offer an opt-in or explain a justified locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The helper removes directories recursively with rmSync(..., { recursive: true, force: true }), which is a destructive filesystem operation. Although it is scoped to owned temporary paths, this code file does not provide any visible warning, confirmation, or explanatory comment to disclose that cleanup deletes filesystem contents.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/cli.mjs:484