Back to skill

Security audit

Clean JSON Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This is a local JSON toolkit with disclosed file-reading and file-writing behavior, but users should be careful with sensitive files and untrusted patch or schema inputs.

Install only if you want a local JSON file toolkit. Avoid running inspection on secrets unless sample values are acceptable in terminal or logs, use --dry-run or backups before patching important files, and do not validate untrusted schemas with complex regex patterns.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/patch.py:217
Finding

Failed JSON Patch Move Operation Can Delete Source Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/validate.py:120
Finding

Schema-Controlled Regular Expressions Permit Denial of Service

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a substantive local JSON/JSONL processing toolkit implemented in Python. The supplied code chunk instead is only a Bash dependency-check script that verifies python3 exists and prints its version. This is materially different from the declared primary purpose and does not implement the advertised capabilities. While dependency checks can be supporting code, this chunk alone does not match the claimed functionality, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description focuses on JSON/JSONL inspection, querying, flatten/unflatten operations, and schema validation. The supplied code instead implements a standalone JSON merge tool whose primary purpose is combining multiple input files into one output file using configurable merge strategies. None of the declared core capabilities (path-tree inspection, jq-style query language, flatten/unflatten, schema validation) appear in this code chunk. While both concern local JSON processing and use no remote calls, the actual behavior is materially different and introduces undeclared file-merging and output-writing capabilities. Therefore this code chunk does not accurately match the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code is a dedicated JSON Patch CLI (patch.py) whose documented and implemented purpose is to apply patch operations to a JSON document. Its core capabilities are parsing JSON Pointer paths and executing add/remove/replace/move/copy/test operations, then emitting patched JSON to disk or stdout. That is materially different from the declared description, which emphasizes inspection of nested structures, jq-style querying, flatten/unflatten conversion, and schema validation. While both concern local JSON manipulation and remain pure standard-library/local-only, the primary purpose and feature set in this code chunk do not match the declared toolkit functionality.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tool prints sampled values from the input JSON/JSONL directly to stdout, which can expose secrets or personal data present in the file to terminals, shell history capture, CI logs, or other logging pipelines. In this skill’s context, the purpose is local data inspection, so showing content is expected, but the lack of any warning, masking, or opt-in control still creates a real data-leak risk when users inspect sensitive files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.