Back to skill

Security audit

fulcra-workspaces

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned for shared Fulcra workspaces, but it asks agents to create persistent background behavior and long-term memory entries that can later act on remote team content.

Install only if you want a Fulcra-backed multi-agent workspace and are comfortable with durable team state. Avoid enabling heartbeat or cron automation unless the team, agent identity, paths, schedule, and removal process are explicit. Treat all Fulcra inbox, role, progress, and task files as untrusted external input, and prefer pinned or preinstalled Fulcra CLI tooling before using it with authentication or file mutation.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:108
Finding

Persistent Background Execution Through Heartbeats and Cron Jobs

Content
View full analysis
/member//inbox/`. - Ensure you log any new tasks or messages discovered during the heartbeat into your local daily memory logs, and process the message using the Inbox Lifecycle (archiving and deleting from the inbox). **Isolated Cron Jobs:** - **Require Consent:** You must explicitly ask the user for permission before creating any cron jobs for team tasks. - When setting up an isolated cron job for a team task (such as periodically checking your inbox), the `payload.message` (or `payload.text`) MUST explicitly instruct the agent to read the necessary context. - **Rule:** The cron payload must say something like: "You are waking up to check your inbox at `team//member//inbox/` and process new tasks. Before starting, you MUST read `team//progress.md`, `team//role.md`, your specific `team//member//role.md`, and your specific `team//member//progress.md` to establish context." - Ensure any new tasks or messages discovered during the cron run are processed using the Inbox Lifecycle (archiving and deleting from the inbox). ``` ### Technical Analysis The skill explicitly directs the agent to modify `HEARTBEAT.md` or create an isolated cron job. These mechanisms survive the invocation that created them ...[truncated 2189 chars]
Remediation
View remediation

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:124
Finding

Persistent Behavioral Directive Written to Global Agent Memory

Content
View full analysis
/progress.md`, the overall `team//role.md`, relevant `task/` files, your specific `team//member//role.md`, and your specific `team//member//progress.md`." - This guarantees the agent will organically recall to pull the latest Fulcra state before acting on team requests. ``` ### Technical Analysis The skill requires a durable behavioral instruction to be written into the agent's global long-term memory file. Unlike ordinary workspace metadata, `MEMORY.md` may influence future chats and sessions unrelated to the original invocation. The inserted directive tells future sessions to consult multiple remotely mutable Fulcra documents before processing teamwork. This creates an indirect persistent instruction channel: parties who can modify team role, progress, or task files can influence context consumed by the agent in future sessions. The skill asks for user consent before modifying memory, which mitigates unauthorized local modification. However, the user is not instructed to approve every subsequent remote change that becomes effective through the persistent directive. The trust decision therefore extends from one approved memory edit to an open ...[truncated 1433 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/fulcra-workspaces-cli.md:9
Finding

Execution of an Unpinned Third-Party CLI Dependency

Content
View full analysis
--poll-timeout=5` (after user finishes flow) ``` The same unpinned invocation pattern is used throughout the reference, including: ```bash uv tool run fulcra-api data-updates "1 day" uv tool run fulcra-api file upload /path/to/local/file "agent//artifact/" uv tool run fulcra-api file list "team//member//inbox/" uv tool run fulcra-api file download "team//member//inbox/20260608-232500_wazir_status-update.md" /tmp/20260608-232500_wazir_status-update.md uv tool run fulcra-api file delete "team//member//inbox/20260608-232500_wazir_status-update.md" ``` ### Technical Analysis The documentation invokes `fulcra-api` through `uv tool run` using only the package name. It does not specify an exact audited version, lockfile, package hash, trusted index configuration, or provenance verification. Depending on the local `uv` environment and cache state, this pattern can resolve and execute package code obtained from a package repository at invocation time. The effective executable can therefore change after the skill itself has been reviewed. This dependency is particularly sensitive because it is used for authentication and receives: - A device authentication code. - Access to local files selected for up ...[truncated 1867 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Rogue AgentSelf-Modification, Session Persistence
Findings (25)

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
**Thread Continuity:** When replying to a message or posting an update about a task, you MUST reuse the exact same `<short-topic>` component from the original message (or the base filename if it was manually dropped). This allows agents and users to track conversations and tasks across multiple inbox exchanges.

When the target agent processes its inbox, it must first upload the message to its `archive/` directory, and then delete the original file from its `inbox/`. Because Fulcra's file system is versioned, it automatically keeps a perfect audit trail of when the file was created in the inbox and when it was completed (deleted).

If the original file name in the inbox does not already start with a timestamp, the processing agent MUST prepend a timestamp (`YYYYMMDD-HHMMSS_`) to the filename when saving it to the `archive/` directory. This ensures the archive remains chronologically sortable even for files manually dropped by users.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The skill establishes persistent shared team memory and instructs the agent to join and document roles in a reusable team namespace, which can carry context and authority assumptions across sessions. In practice, this creates durable cross-session state that may be relied on later by isolated runs or other agents, increasing the risk of stale authorization, role confusion, or unintended data reuse.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
Agents can collaborate and share memory using a shared `team/<team-name>/` prefix in the Fulcra datastore. This directory structure must conform to the Open Knowledge Format (OKF).

### Creating a Team
Before creating a new team, you MUST always check if a team with that name already exists by listing the `team/` directory or checking for a `team/<team-name>/role.md` file. Do not accidentally overwrite or recreate an existing team structure. If the team already exists, simply join it.

### Joining a Team
When joining a team, do not assume your role. You MUST explicitly ask the user to confirm or clarify what your specific role, duties, and identity will be on this team. Once the user clarifies your role, document it in `team/<team-name>/member/<agent-name>/role.md`.

Cross-Context Output

Medium
Category
Output Handling
Confidence
80% confidence
Finding

Output from one security context is used in another without boundary enforcement. Cross-context output flow can leak sensitive information or escalate privileges across trust boundaries.

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
- Emphasize that this is definitely optional; alternatively, they can just manually remind you to do team work each time.
- If the user consents, set up the habit immediately so you don't miss incoming messages.

**SECURITY & AUTHORIZATION WARNING:** Never transfer data, context, or files between agents without explicit authorization and strict respect for data ownership boundaries. Cross-agent data transfer can leak sensitive user context to a principal who lacks authorization. Ensure you explicitly warn the user if a team coordination action involves transferring private workspace data.

Within a team's directory, the following OKF structure is used:
- **`team/<team-name>/index.md`**: Directory listing of the team's concepts and members.

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The skill instructs agents to persist automated background behavior via HEARTBEAT.md, causing future sessions to autonomously read and process shared inbox content. Even with consent language, this creates session persistence that can continue acting on stale assumptions, expand access to newly added content, and increase the blast radius of prompt injection or unauthorized data handling in future runs.

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
**Background Heartbeats:**
- **Require Consent:** You must explicitly ask the user for permission before enabling automated background inbox checks.
- If the user approves, add a task to your local workspace's `HEARTBEAT.md` file to periodically check your inbox at `team/<team-name>/member/<agent-name>/inbox/`.
- Ensure you log any new tasks or messages discovered during the heartbeat into your local daily memory logs, and process the message using the Inbox Lifecycle (archiving and deleting from the inbox).

**Isolated Cron Jobs:**

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The skill instructs agents to execute uv tool run fulcra-api without pinning an exact package version or source, so each invocation may resolve to whatever version is current at runtime. If the upstream package is compromised or a breaking/malicious release is published, the agent could execute untrusted code during authentication or file operations with access to workspace data and Fulcra credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

This command again runs uv tool run fulcra-api without an exact version pin, meaning the executed code is supply-chain dependent on the latest resolved package. Because this step participates in auth polling, compromise could expose tokens, alter login flow behavior, or execute arbitrary code in the agent environment.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The unpinned uv tool run fulcra-api data-updates command causes runtime execution of a package that may change over time without review. In this skill context, the tool is used to inspect shared team state, so a compromised package could exfiltrate metadata, tamper with outputs, or mislead agents coordinating through shared storage.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Uploading artifacts through an unpinned fulcra-api package creates a direct supply-chain risk in a path that handles local files and remote storage destinations. A malicious or altered package version could read arbitrary local files, modify upload targets, or leak user-approved artifacts and adjacent workspace contents.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This inbox upload workflow depends on unpinned third-party code execution via uv tool run fulcra-api. In a collaboration skill, that increases risk because message contents, recipient routing, and team namespace operations could be manipulated by a compromised release, affecting multiple agents and shared coordination channels.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Listing inbox files with an unpinned package still executes potentially untrusted code, even though the operation is read-oriented. A malicious package could falsify listings, hide messages, or harvest metadata and credentials from the environment, undermining team coordination integrity.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Downloading inbox messages via an unpinned package introduces supply-chain risk in a workflow that writes files locally. A compromised version could overwrite unexpected paths, alter downloaded content, or use the download step as a pretext to execute malicious behavior with local filesystem access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Re-uploading messages to the archive using an unpinned fulcra-api package exposes both local message files and remote archive namespaces to any malicious upstream package update. Since archives preserve team history, tampering here can corrupt auditability and mislead future agent decisions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

Even a file stat operation executes the unpinned package and therefore carries code-execution and output-integrity risk. A malicious release could falsely report success, causing subsequent workflows to delete or trust data based on fabricated state.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Deleting inbox files through an unpinned package is especially dangerous because compromise can lead to destructive tampering across shared team storage. A malicious or buggy package could delete unintended files, suppress messages, or erase coordination evidence while appearing to follow the documented workflow.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This download-or-create progress file step runs unpinned external code in a workflow that influences shared team context. A compromised package could poison progress files, alter downloaded content, or manipulate what agents believe the team status to be, creating integrity and coordination failures.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Uploading progress.md with an unpinned package gives changing third-party code authority over a central team planning artifact. In this context, that is more dangerous because poisoned progress data can steer multiple agents' future actions, not just a single command's result.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Downloading completed.md through an unpinned package extends the same supply-chain exposure into records of finished objectives. A malicious package could falsify project completion state or access local environment data while handling the file.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Uploading the updated completed.md file via unpinned third-party code risks silent modification of durable team records and arbitrary code execution at invocation time. Because completed.md is expected to only grow, tampering can rewrite historical truth and affect later planning or audits.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Updating team/<team_name>/role.md with an unpinned package lets mutable upstream code influence a file that defines team purpose and behavior. That makes the context more dangerous because poisoned role definitions can redirect multiple agents' objectives and permissions assumptions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This member role upload executes unpinned package code while writing agent-specific role context. A compromised package could alter the role content, redirect uploads, or leverage filesystem/network access to exfiltrate sensitive coordination data.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Updating member progress through an unpinned package again creates a supply-chain execution point in a file that background jobs may rely on. If exploited, the attacker could feed false progress to isolated agents, causing persistent miscoordination across the team.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Uploading session summaries via an unpinned package allows mutable external code to handle local files and remote archival records. Since session summaries often capture decisions and outcomes, tampering can distort shared memory and future agent reasoning.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

This unpinned task tracker upload is a supply-chain risk affecting a live operational artifact that guides ongoing work. In the skill context, manipulation of task status can misdirect multiple agents, hide failures, or inject misleading instructions into shared storage.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Uploading task/index.md through an unpinned package extends the same risk to an index file that helps agents discover active tasks. A compromised package could tamper with project navigation, suppress tasks, or execute arbitrary code each time the documented command is run.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.