Back to skill

Security audit

FOSMVVM ServerRequest Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent code-generation helper, but its CRUD server templates can produce read, update, and delete endpoints without explicit authentication or object-level authorization checks.

Review generated server handlers before installing or using this skill in production work. Add authentication, object-level authorization, tenant or ownership scoping, CSRF protection for browser routes, and explicit confirmation or recovery behavior for destructive operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
reference.md:136
Finding

Generated CRUD Controller Omits Authentication and Object-Level Authorization

Content
View full analysis
ResponseBody { let db = request.db // 1. Fetch entity (with relationships if needed) guard let {entity} = try await {Entity}.query(on: db) .filter(\.$id == requestBody.{entity}Id) .with(\.$createdBy) // Add relationships as needed .first() else { throw Abort(.notFound, reason: "{Entity} not found: \(requestBody.{entity}Id)") } // 2. Perform the operation // {entity}.someField = requestBody.newValue // try await {entity}.save(on: db) // 3. Build and return ViewModel let viewModel = {Entity}ViewModel( id: try {entity}.requireID() // ... map fields ) return .init(viewModel: viewModel) } } ``` ### Technical Analysis The template retrieves an entity using an identifier supplied by the client: ```swift .filter(\.$id == requestBody.{entity}Id) ``` It then returns or potentially modifies that entity without requiring an authenticated principal or verifying ownership, tenant membership, role, or an operation-specific authorization policy. Loading the `createdBy` relationship does not itself enforce access control. This is an insecure default for generated read, update, or delete handlers. If an application does not independently enforce authorization through middleware or another mandatory layer, generated endpoints may be vulnerable to insecure direct object reference or broken object-level authorization. The project provides no evidence that authe ...[truncated 2496 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown skill says it is used when 'implementing client-server communication' and that requirements are understood 'from conversation context automatically,' but it does not define clear boundaries for when the skill should or should not activate. Those phrases are broad enough to overlap with many ordinary development discussions, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill provides concrete browser fetch and server-processing flow examples that perform networked request handling but does not warn that these patterns transmit user-supplied data and may trigger real server-side actions. In an agentic coding context, omission of side-effect and trust-boundary guidance can cause generated integrations to forward sensitive data, omit CSRF/authn/authz checks, or normalize unsafe request flows without explicit developer review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown includes a reusable DeleteRequest template for delete operations, but it provides no accompanying warning, confirmation step, or caution about destructive effects. Because this reference is intended to guide implementation of deletion flows, the omission could lead users of the template to build destructive actions without any disclosure to end users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

Earlier sections explicitly state that custom ResponseError types must be nested inside the request class and demonstrate catching errors as MoveIdeaRequest.ResponseError. However, this example catches CreateIdeaError, which contradicts the documented nesting pattern and suggests a top-level error type instead.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The error-localization examples define only en: message catalogs and provide no indication that other locales are supported or that English is merely an example. In a reference file, this can encourage implementations that default to English-only behavior without offering user choice or documenting a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This additional YAML localization example again uses only en: entries and does not state that other languages should be supported or selectable. Repeating the pattern in reference material increases the risk that downstream skills hard-code English as the only language.

Content

No source excerpt is available for this finding.