Back to skill

Security audit

spots

Security checks for vulnerabilities and agentic risk

Overview

The skill’s purpose is coherent, but it asks users to install a mutable external executable and exposes an exact 1Password location for a Google API key.

Review this before installing. Use a pinned and reviewed version of the `spots` binary if possible, restrict the Google API key to the needed APIs and quotas, and do not expose or print the referenced 1Password secret in agent transcripts or scripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:12
Finding

Unpinned Third-Party Executable Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 12
Vulnerability Type: Unpinned and externally maintained executable dependency
Risk Level: Medium

Vulnerable Code:

text
Binary: `~/projects/spots/spots` or `go install github.com/foeken/spots@latest`

Technical Analysis

The Skill directs users to install the latest available revision of an externally maintained Go module. The @latest selector is mutable: the source code and transitive dependency graph retrieved by this command can change after the Skill has been reviewed.

The project contains no local copy of the executable's source code, version lock, expected checksum, signature, or reproducible-build information. Consequently, the effective behavior of the installed program cannot be established from the audited project. This creates a supply-chain trust boundary in which compromise of the upstream repository, a maintainer account, a release process, or a transitive dependency could introduce arbitrary code.

Attack Path

  1. An attacker compromises the upstream repository, maintainer account, release process, or one of its dependencies.
  2. The attacker causes a malicious revision or release to become the version resolved by github.com/foeken/spots@latest.
  3. A user follows the installation instruction in SKILL.md.
  4. Go downloads and compiles the attacker-controlled source and its dependency graph.
  5. The user invokes the resulting spots executable as instructed.
  6. The malicious payload executes with the privileges of the user running the binary and can access resources available to that account.

Impact Assessment

Successful exploitation permits arbitrary code execution under the invoking user's account. The resulting process could read or modify user-accessible files, make network requests, alter project data, and access environment variables available to the process. Because the documented setup requires `GOOGLE_P ...[truncated 334 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace @latest with a specific, reviewed semantic version or immutable commit identifier.
  • Record and verify trusted release checksums or cryptographic signatures before installation.
  • Prefer signed release artifacts from a controlled distribution channel, with documented verification steps.
  • Pin and audit the complete transitive dependency graph using Go module metadata and checksum verification.
  • Document the exact source revision corresponding to the reviewed executable.
  • Where feasible, include reviewable source code or a reproducible-build configuration in the Skill package.
  • Run the executable with least privilege and provide only the required Google API credential.
  • Restrict the Google API key to the required Places and Geocoding APIs, enforce quotas, and apply supported application or network restrictions.
  • Avoid exposing unrelated secrets or sensitive environment variables to the executable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation discloses a concrete 1Password secret path for a Google API key, which reveals where sensitive credentials are stored and encourages direct retrieval of a live secret during skill setup. Even though it is 'just documentation', exposing an internal vault/item/field reference increases the chance of credential misuse, accidental propagation, and unauthorized access attempts in environments where agents or users can resolve 1Password references.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill documentation includes a precise 1Password secret reference without any warning that it points to sensitive credentials. This normalizes hardcoding or casually fetching secrets in operational workflows, making accidental disclosure to logs, transcripts, screenshots, or downstream tools more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.