Back to skill

Security audit

Fulcra Onboarding (deprecated, use fulcra-get-started)

Security checks for vulnerabilities and agentic risk

Overview

This deprecated skill is only a pointer, but it tells agents to follow mutable external replacement instructions that include installation and login steps.

Install only if you intend to use Fulcra's replacement onboarding skill. Before following the referenced fulcra-get-started instructions, verify the replacement package or repository version you are using and review any CLI installation, login, token, or account-access steps separately.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:17
Finding

Unpinned Redirection to External Skill Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17–25
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

markdown
Use the `fulcra-get-started` skill instead:

- **In this repo:** `skills/fulcra-get-started/`
- **GitHub:** https://github.com/fulcradynamics/agent-skills/tree/main/skills/fulcra-get-started
- **Install:** `fulcradynamics/agent-skills/fulcra-get-started`

If you arrived here, read and follow `fulcra-get-started` — it walks you through
connecting to Fulcra for the first time (installing the CLI, logging in, and
choosing what to set up next).

Technical Analysis

The skill does not contain its intended operational instructions. Instead, it directs the agent to read and follow another skill that is not included in the audited artifact. One supplied reference points to the mutable GitHub main branch, while the local repository path is also absent from the submitted project.

Consequently, the effective instructions cannot be determined or verified from this artifact. They may change after review without changing SKILL.md. The redirection is security-sensitive because the described replacement workflow includes installing a CLI and logging in. If the external repository, referenced skill, publication channel, or maintainer account is compromised, attacker-controlled instructions could be presented under the trust granted to this skill.

The artifact itself contains no executable code and provides no direct evidence of malicious payload execution, credential theft, persistence, privilege escalation, or data exfiltration. The risk arises from blindly delegating agent behavior to mutable, unaudited content.

Attack Path

  1. A user or agent invokes the deprecated fulcra-onboarding skill.
  2. SKILL.md instructs the agent to locate, install, read, and follow fulcra-get-started.
  3. The agent obtains the replacement skill from a local path not present in th ...[truncated 1064 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the complete replacement instructions in the reviewed skill package so its effective behavior can be audited.
  2. If external retrieval is unavoidable, reference an immutable commit or signed release rather than a mutable branch such as main.
  3. Verify downloaded content using a pinned cryptographic hash or trusted signature before processing it.
  4. Replace the unconditional instruction to “read and follow” external content with a summary of proposed actions and require explicit user approval.
  5. Require separate confirmation before installing software, executing commands, opening authentication flows, or transmitting credentials or tokens.
  6. Restrict replacement-skill execution to the minimum tools and permissions necessary for onboarding.
  7. Vendor and audit the exact fulcra-get-started version distributed with this pointer, and update both artifacts together through a controlled review process.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.