Back to skill

Security audit

Clean Code

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a clean-code guide, but it also tries to impose mandatory cross-agent workflows and run unbundled local validation scripts.

Install only if you are comfortable with a style guide that may pressure agents to run local validation scripts outside the reviewed package. Treat the listed .agent/skills Python commands as untrusted unless you separately verify those scripts and want them run for the current task.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:6
Finding

Mandatory Cross-Agent Workflow and Script-Execution Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 6 and 126-199
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code

yaml
priority: CRITICAL
markdown
## 🔴 Self-Check Before Completing (MANDATORY)

**Before saying "task complete", verify:**

| Check | Question |
|-------|----------|
| ✅ **Goal met?** | Did I do exactly what user asked? |
| ✅ **Files edited?** | Did I modify all necessary files? |
| ✅ **Code works?** | Did I test/verify the change? |
| ✅ **No errors?** | Lint and TypeScript pass? |
| ✅ **Nothing forgotten?** | Any edge cases missed? |

> 🔴 **Rule:** If ANY check fails, fix it before completing.

---

## Verification Scripts (MANDATORY)

> 🔴 **CRITICAL:** Each agent runs ONLY their own skill's scripts after completing work.

### Agent → Script Mapping

| Agent | Script | Command |
|-------|--------|---------|
| **frontend-specialist** | UX Audit | `python .agent/skills/frontend-design/scripts/ux_audit.py .` |
| **frontend-specialist** | A11y Check | `python .agent/skills/frontend-design/scripts/accessibility_checker.py .` |
| **backend-specialist** | API Validator | `python .agent/skills/api-patterns/scripts/api_validator.py .` |
| **mobile-developer** | Mobile Audit | `python .agent/skills/mobile-design/scripts/mobile_audit.py .` |
| **database-architect** | Schema Validate | `python .agent/skills/database-design/scripts/schema_validator.py .` |
| **security-auditor** | Security Scan | `python .agent/skills/vulnerability-scanner/scripts/security_scan.py .` |
| **seo-specialist** | SEO Check | `python .agent/skills/seo-fundamentals/scripts/seo_checker.py .` |
| **seo-specialist** | GEO Check | `python .agent/skills/geo-fundamentals/scripts/geo_checker.py .` |
| **performance-optimizer** | Lighthouse | `python .agent/skills/performance-profiling/scripts/lighthouse_audit.py <url>` |
| **test-engineer** | T
...[truncated 4451 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove priority: CRITICAL and replace mandatory language with clearly advisory guidance scoped to clean-code practices.
  2. Remove all cross-agent role mappings. A clean-code skill should not redefine the operating policies of frontend, backend, security, testing, SEO, mobile, database, or performance agents.
  3. Do not instruct agents to execute scripts that are absent from the reviewed package.
  4. If validation automation is necessary, bundle each script in the package so it can be audited, pin its expected path and integrity, and document its required permissions.
  5. Require explicit user authorization before executing validation commands not already requested by the user.
  6. Resolve and validate script paths against an approved directory. Reject symlinks, path traversal, unexpected file ownership, and writable untrusted locations.
  7. Run approved validators with least privilege in a sandbox that restricts filesystem access, environment variables, subprocess creation, and network connectivity.
  8. Replace the forced READ → SUMMARIZE → ASK process with a non-binding recommendation that defers to the user's request and higher-level agent policy.
  9. Keep completion checks relevant to the actual task and available tooling; do not claim that unrelated lint, type, localization, or role-specific checks are universally mandatory.
  10. Re-audit any future bundled scripts separately for command injection, unsafe dependency loading, secret access, network behavior, and unintended file modification.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
5. **After fixing** → Re-run script to confirm

> 🔴 **VIOLATION:** Running script and ignoring output = FAILED task.
> 🔴 **VIOLATION:** Auto-fixing without asking = Not allowed.
> 🔴 **Rule:** Always READ output → SUMMARIZE → ASK → then fix.

Static analysis

No suspicious patterns detected.