Back to skill

Security audit

Emergency Rescue Kit

Security checks for vulnerabilities and agentic risk

Overview

This is a legitimate emergency-recovery guide, but it includes powerful copy-paste commands that can delete data, kill services, rewrite history, or install recurring jobs without enough safeguards.

Install only if you want a high-impact operator runbook and will review each command before use. Do not paste the destructive or privileged commands blindly; first confirm the target repo, branch, process, Docker resources, filesystem path, crontab contents, and backups. Be especially careful with cron installation, force-pushing rewritten history, Docker volume pruning, git reset --hard, and commands that print or handle secrets.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:717
Finding

Persistent Cron Installation Replaces the User's Existing Crontab

Content
View full analysis
/dev/null | openssl x509 -checkend 604800 -noout || echo "CERT EXPIRES WITHIN 7 DAYS" | mail -s "SSL ALERT" admin@example.com' | crontab - ``` ### Technical Analysis The command installs a weekly cron task that survives the current Skill invocation and subsequent Agent sessions. Persistent monitoring is not required to resolve an expired certificate, so this behavior exceeds the minimum privileges and duration required for the Skill's immediate recovery function. Piping a single entry directly into `crontab -` also replaces the executing user's entire existing crontab rather than safely adding an entry. Existing backup, maintenance, security, or monitoring jobs may consequently be removed. Although the supplied payload only performs a TLS certificate check and sends a fixed warning, the scheduled command creates a persistent execution mechanism. Any unreviewed modification to its hostname, recipient, or command body before installation would subsequently execute on a recurring basis with the user's privileges. ### Attack Path 1. An operator invokes the Skill to address a certificate incident. 2. The operator follows the “PREVENTION” instruction and copies the cron command. 3. `crontab -` replaces the user's current cron configuration with the supplied entry. 4. The command persists after the rescue operation and runs every Monday at 09:00. 5. Existing cron entries are lost, and any modified command body gains recurring execution under the affected account. ### Impact Assessment The scheduled task obtains recurring command execution with all privileges available to the user who installs it. If installed from a privileged account, the scope may include privileged system resources. The immediate documented ...[truncated 171 chars]
Remediation
View remediation
/dev/null printf '%s\n' '0 9 * * 1 ...' ) | crontab - ``` - Check for duplicate entries before appending. - Validate and quote all configurable hostnames and email recipients. - Prefer a dedicated, least-privileged monitoring service or scoped systemd timer with auditable configuration. - Include an explicit removal procedure and verify the resulting configuration with `crontab -l`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:254
Finding

Forced Broad Cleanup Commands Can Cause Irrecoverable Data Loss

Content
View full analysis
/dev/null find . -name ".next" -type d -exec rm -rf {} + 2>/dev/null find . -name "dist" -type d -exec rm -rf {} + 2>/dev/null find /tmp -type f -mtime +7 -delete 2>/dev/null docker system prune -a --volumes -f ``` ### Technical Analysis These commands perform broad deletion with forced or non-interactive options. Their scope is not limited to resources conclusively identified as the source of the disk-space incident: - `docker system prune -a -f` removes all unused images, containers, and networks visible to the Docker daemon. - `docker volume prune -f` and `docker system prune -a --volumes -f` can remove volumes containing non-reproducible application data. - Recursive `find ... -exec rm -rf` commands delete every matching directory under the current working tree, potentially spanning multiple unrelated projects. - The `/tmp` command deletes every file older than seven days that the executing identity is permitted to remove, including files unrelated to the incident or still required by long-running applications. Suppressing errors with `2>/dev/null` further reduces visibility into partial failures and the actual scope of deletion. Labeling these operations as quick cleanup procedures may encourage execution before affected resources have been inventoried or backed up. ### Attack Path 1. A system experiences disk pressure and an operator consults the emergency procedure. 2. The operator executes a forced cleanup command without first reviewing its candidate resources. 3. The Docker daemon identifies currently unused images, containers, networks, or volumes across unrelated applications. 4. Matching resources are d ...[truncated 1051 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:389
Finding

Unvalidated Process Selection Can Terminate Unrelated or Critical Services

Content
View full analysis
# Graceful pkill -9 -f # Force kill $(ps aux --sort=-%mem | awk 'NR==2{print $2}') ``` ### Technical Analysis The commands dynamically select processes and terminate them without first verifying the selected PID, owner, executable, or role: - `lsof -t -i :8080` can return multiple PIDs, causing every matching process to receive the signal. - `pkill -f` matches against complete command lines. A broad or incorrectly escaped pattern can match unrelated services, shell commands, or monitoring processes. - Selecting the second row from memory-sorted `ps` output assumes that the largest memory consumer is safe to terminate. It may instead select a database, build worker, security process, or another user's critical workload. - `SIGKILL` prevents cleanup handlers, transaction completion, buffer flushing, and graceful shutdown. The issue is unsafe target selection rather than credential theft or privilege escalation. Process ownership checks enforced by the operating system still apply, but execution under a privileged account substantially increases the affected scope. ### Attack Path 1. An operator encounters a port conflict, stuck process, or out-of-memory condition. 2. The operator copies one of the dynamic termination commands. 3. The PID substitution or full-command-line pattern resolves to one or more unintended processes. 4. The command sends `SIGTERM` or `SIGKILL` without displaying and confirming the targets. 5. The affected service terminates; with `SIGKILL`, it cannot flush state or perform graceful cleanup. 6. Dependent services fail, active transactions are interrupted, or application data becomes inconsistent. ...[truncated 655 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (92)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

Force-pushed to main (or any shared branch)

Someone ran git push --force and overwrote remote history.

bash
# DIAGNOSE: Check the reflog on any machine that had the old state

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
65% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

Lost commits after rebase or reset --hard

You ran git rebase or git reset --hard and commits disappeared.

bash
# DIAGNOSE: Your commits are NOT gone. Git keeps everything for 30+ days.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

git reset --hard <commit-hash-before-disaster> overwrites the working tree and index and can destroy uncommitted changes if run before preservation. In an emergency recovery guide, presenting it as the primary fix raises the likelihood of accidental local data loss.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
# Look for entries like "rebase (start)" or "reset: moving to"

# FIX: Reset back to the pre-disaster state
git reset --hard <commit-hash-before-disaster>

# FIX (alternative): Cherry-pick specific lost commits
git cherry-pick <lost-commit-hash>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

git reset --hard HEAD~<N> is explicitly destructive and can erase local work if N is miscounted or if the user is on the wrong branch. In a stressful recovery scenario, this kind of parameterized destructive command has a high error rate.

Content

Scanner excerpt · SKILL.md (reported line 95)May include surrounding context.

md
# FIX: Create the feature branch at current position, then reset main
git branch feature-branch          # Create branch pointing at current commit
git reset --hard HEAD~<N>          # Move main back N commits (⚠️ destructive)
git checkout feature-branch        # Switch to the new branch

# FIX (safer alternative using cherry-pick):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

git reset --hard origin/main is a destructive local reset that discards all uncommitted divergence from the remote branch. It is less dangerous than force-pushing but still risky in a general-purpose emergency skill without mandatory prechecks.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
# FIX (safer alternative using cherry-pick):
git checkout -b feature-branch     # Create and switch to new branch
git checkout main
git reset --hard origin/main       # Reset main to remote state
# Your commits are safely on feature-branch

# VERIFY:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

git reset --hard HEAD~1 after a bad merge can discard local modifications in addition to removing the merge commit. Without an upfront warning, users may lose unrelated in-progress work.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
git merge --abort

# FIX (merge was committed but not pushed):
git reset --hard HEAD~1

# FIX (merge was already pushed): Create a revert commit
git revert -m 1 <merge-commit-hash>

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The repository corruption repair flow instructs users to manually delete objects from .git/objects with rm based on parsed fsck output, but does not clearly warn that mistakes can permanently destroy locally unique history. In a damaged-repo scenario, users are especially likely to act quickly and mis-delete objects they cannot recover from remote.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

Manually deleting files under .git/objects based on parsed git fsck output is dangerous because a typo, malformed output interpretation, or partially corrupt repo can lead to permanent loss of unrecoverable objects. In an emergency skill, users may execute the removal hastily, making this more hazardous than in expert-only documentation.

Content

Scanner excerpt · SKILL.md (reported line 151)May include surrounding context.

md
# Remove corrupt objects and fetch them again
git fsck --full 2>&1 | grep "corrupt\|missing" | awk '{print $NF}'
# For each corrupt object:
rm .git/objects/<first-2-chars>/<remaining-hash>
git fetch origin  # Re-download from remote

# VERIFY:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

md
git add <file>

# STEP 3: Add to .gitignore
echo ".env" >> .gitignore
echo "credentials.json" >> .gitignore
git add .gitignore

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
git add <file>

# STEP 3: Add to .gitignore
echo ".env" >> .gitignore
echo "credentials.json" >> .gitignore
git add .gitignore

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

md
# STEP 3: Add to .gitignore
echo ".env" >> .gitignore
echo "credentials.json" >> .gitignore
git add .gitignore

# STEP 4: Remove from git history (⚠️ rewrites history)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The credential-scrubbing workflow instructs git push origin --force --all and --force --tags without prominent warnings about coordination, protected branches, downstream clone breakage, and the possibility of rewriting unrelated history if the cleanup scope is wrong. In a high-pressure leak response, users may execute this broadly and disrupt repository integrity for the whole team.

Content

Scanner excerpt · SKILL.md (reported line 207)May include surrounding context.

md
git gc --prune=now --aggressive

# STEP 5: Force push the cleaned history
git push origin --force --all
git push origin --force --tags

# STEP 6: Notify all collaborators to re-clone

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

Should return nothing

text

### .env file pushed to public repo

```bash
# STEP 1: Revoke ALL credentials in that .env file. All of them. Now.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

Should return nothing

text

### .env file pushed to public repo

```bash
# STEP 1: Revoke ALL credentials in that .env file. All of them. Now.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

Should return nothing

text

### .env file pushed to public repo

```bash
# STEP 1: Revoke ALL credentials in that .env file. All of them. Now.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

Should return nothing

text

### .env file pushed to public repo

```bash
# STEP 1: Revoke ALL credentials in that .env file. All of them. Now.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

Should return nothing

text

### .env file pushed to public repo

```bash
# STEP 1: Revoke ALL credentials in that .env file. All of them. Now.

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The command git show HEAD~1:.env || git log --all -p -- .env | head -50 explicitly displays historical .env contents in order to inspect what was exposed. Although well-intended, it can unnecessarily re-expose secrets on-screen, in terminal scrollback, screen recordings, shared shells, or copied incident notes during a live response.

Content

Scanner excerpt · SKILL.md (reported line 230)May include surrounding context.

md
git commit -m "Remove .env from tracking"

# STEP 3: Remove from history (see credential removal above)
git filter-repo --path .env --invert-paths

# STEP 4: Check what was exposed
# List every variable that was in the .env:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 298)May include surrounding context.

md
# 2. Package manager caches
# npm
npm cache clean --force
rm -rf ~/.npm/_cacache

# pip
pip cache purge

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 298)May include surrounding context.

md
# 2. Package manager caches
# npm
npm cache clean --force
rm -rf ~/.npm/_cacache

# pip
pip cache purge

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 435)May include surrounding context.

md
kill $(ps aux --sort=-%mem | awk 'NR==2{print $2}')

# 2. Drop filesystem caches (safe, no data loss)
sync && echo 3 | sudo tee /proc/sys/vm/drop_caches

# 3. Disable swap thrashing (if swap is full)
sudo swapoff -a && sudo swapon -a

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 837)May include surrounding context.

md
kill $(ps aux --sort=-%mem | awk 'NR==2{print $2}')

# 2. Drop filesystem caches (safe, no data loss)
sync && echo 3 | sudo tee /proc/sys/vm/drop_caches

# 3. Disable swap thrashing (if swap is full)
sudo swapoff -a && sudo swapon -a

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 884)May include surrounding context.

md
kill $(ps aux --sort=-%mem | awk 'NR==2{print $2}')

# 2. Drop filesystem caches (safe, no data loss)
sync && echo 3 | sudo tee /proc/sys/vm/drop_caches

# 3. Disable swap thrashing (if swap is full)
sudo swapoff -a && sudo swapon -a

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 438)May include surrounding context.

md
sync && echo 3 | sudo tee /proc/sys/vm/drop_caches

# 3. Disable swap thrashing (if swap is full)
sudo swapoff -a && sudo swapon -a

# PREVENT: Set memory limits
# Docker:

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 708)May include surrounding context.

md
sync && echo 3 | sudo tee /proc/sys/vm/drop_caches

# 3. Disable swap thrashing (if swap is full)
sudo swapoff -a && sudo swapon -a

# PREVENT: Set memory limits
# Docker:

Static analysis

No suspicious patterns detected.