Back to skill

Security audit

Text Case Tool

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple local text case converter with no network, credential, persistence, or destructive behavior found.

Installing this skill should be low risk. It runs a local Python helper to transform text you provide, so avoid pasting sensitive text unless you are comfortable processing it locally in your agent environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest sets language: en, which indicates a fixed language setting rather than an explicit user-selectable locale. Because the file also contains Chinese documentation later, this suggests the skill can support multiple languages but does not clearly present language choice or opt-in in its policy-facing metadata.

Content

No source excerpt is available for this finding.

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/text_case.py (reported line 96)May include surrounding context.

python
# Find which converter to use
    for name, func in converters.items():
        if getattr(args, name):
            result = func(args.text)
            print(result)
            return

Static analysis

No suspicious patterns detected.