Back to skill

Security audit

Received useful work

Security checks for vulnerabilities and agentic risk

Overview

This skill openly runs bounded local integration checks against hash-pinned public packages, and I found no hidden payment, credential use, persistence, or exfiltration behavior.

Install only if you are comfortable with this skill running Node, tar, and npm, fetching from the listed public domains, and executing hash-pinned third-party CLIs inside caller-chosen work directories. Use a disposable work directory, keep credentials out of request files, and review caller-mode requests before running them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (27)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

md
ation as free_sufficient or missing_field_not_paid_demand and sends no payment. scripts/dispatch.mjs qualifies compatibility-query for a tool input compatibilit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
`scripts/task-distribution/distribution.mjs`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
`scripts/task-distribution/source.mjs`

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/pins.json (reported line 62)May include surrounding context.

json
red": true
        },
        {
          "id": "capability-preflight",
          "role": "subject-archive",
          "archive": "/downloads/capability-preflight/capability-preflight.tar.gz",
          "sha256": "477e31cb09818409ff9fe81b9d8401bc227591be100a2aca7edf73ca1a45e551",
          "bytes": 143275,
          "layout": "unextracted",
          "required": true
        }
      ],
      "taskDescription": "Prepare one walletless CRT envelope for crt-100198-capability-preflight-reuse and record a useful-negative evaluation. The envelope is not transmitted and payment stays off.",
      "usages": [
        "run --crt-client CRT --budget fixtures/budget-walletless.json --subject SUBJECT --outcome useful_negative --out OUT"
      ]
    },
    {
      "id": "grantless-retained-read",
      "class": "hosted_library",
      "hostedApi": false,
      "subscription": false,
      "spendingPermission": false,
      "publicationStatus": "hosted_library_received",
      "hostedAcquisitionVeri

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented behavior says examples/admissible.json is not loaded, but runComposition explicitly loads that bundled example and uses it in execution mode. This mismatch is dangerous because operators or upstream tooling may trust the stated requirement that caller-supplied composition is mandatory, while the code silently falls back to fixture-driven behavior that can produce misleading results or bypass expected caller control.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly states it has no allowed-tools field and does not create a sandbox, yet it installs and runs Node-based executables that perform network access, archive extraction, npm dependency installation, and child process execution. That mismatch is dangerous because consumers cannot enforce least-privilege boundaries from the manifest alone, increasing the risk of unexpected environment and network exposure when caller-supplied inputs are processed.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
"skill": "received-useful-work",
  "version": "0.1.1",
  "installedCommand": "scripts/dispatch.mjs",
  "nativeProviderRoute": "/.well-known/skills/received-useful-work/SKILL.md",
  "index": "/.well-known/skills/index.json",
  "paymentAuthority": "none",
  "claimAuthority": "none",

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
"skill": "received-useful-work",
  "version": "0.1.1",
  "installedCommand": "scripts/dispatch.mjs",
  "nativeProviderRoute": "/.well-known/skills/received-useful-work/SKILL.md",
  "index": "/.well-known/skills/index.json",
  "paymentAuthority": "none",
  "claimAuthority": "none",

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/pins.json (reported line 6)May include surrounding context.

json
"skill": "received-useful-work",
  "version": "0.1.1",
  "installedCommand": "scripts/dispatch.mjs",
  "nativeProviderRoute": "/.well-known/skills/received-useful-work/SKILL.md",
  "index": "/.well-known/skills/index.json",
  "paymentAuthority": "none",
  "claimAuthority": "none",

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · scripts/dispatch.mjs (reported line 410)May include surrounding context.

js
"skill": "received-useful-work",
  "version": "0.1.1",
  "installedCommand": "scripts/dispatch.mjs",
  "nativeProviderRoute": "/.well-known/skills/received-useful-work/SKILL.md",
  "index": "/.well-known/skills/index.json",
  "paymentAuthority": "none",
  "claimAuthority": "none",

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes this skill as discovering libraries and making classification/compatibility decisions, with explicit emphasis that a description match does not complete the task and that no payment is sent. The source notice additionally states that the integration 'persists a referral exclusively with file/directory sync' and handles persistent commit failure, which indicates stateful persistence behavior not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comments/next-action text say replay dates are not used and fixture dates are not written in, yet the compatibility runner hard-codes observed, expiry, and current timestamps. Hard-coded temporal inputs can invalidate the trust model around freshness checks, making outputs appear based on caller-provided timing when they are actually driven by embedded fixtures.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file is a code file, so SQP-3 applies to natural-language policy issues expressed in code behavior. The child environment hard-codes LANG and LC_ALL to "C", which forces a specific locale for all spawned commands and does not provide any user opt-in or documented region-specific justification.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The dispatcher does substantially more than passive qualification/classification: it verifies archives, extracts them, installs dependencies with npm, and executes bundled programs and child processes. Because these actions are reachable from request handling, the file acts as a code execution/orchestration surface; if pins, archives, or invoked package contents are compromised, this becomes a pathway to run attacker-controlled code despite the skill description implying a narrower decision role.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The compatibility path runs npm ci and then executes package-provided code to decide compatibility, which is a powerful operation compared with the claimed purpose of making a compatibility decision. Even with --ignore-scripts, installed dependencies and the executed consumer binary still expand the attack surface and can process attacker-supplied inputs, turning a metadata/query operation into code execution.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/dispatch.mjs:215

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/task-distribution/distribution.mjs:72