Back to skill

Security audit

QuickStatic Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward API guide for publishing and managing public static sites, with its network publishing and delete capabilities disclosed.

Before installing, understand that uploaded zip contents will be sent to an external service and made publicly reachable. Keep each site_key private because it can update or delete that site, and only run the delete call when you intentionally want the public site removed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

The skill exposes a destructive DELETE operation keyed only by a user-supplied site_key, with no visible authentication, ownership verification, or safety guardrails in the documented interface. In the context of an anonymous publishing service, this creates a realistic risk that an agent could be induced to delete a site if an attacker supplies or guesses a valid key, making destructive tool abuse more dangerous.

Content

Scanner excerpt · skills.md (reported line 26)May include surrounding context.

md
- `GET /v1/sites/{site_key}`

### 3) Delete site
- `DELETE /v1/sites/{site_key}`

## site_key Rules
- Regex: `[A-Za-z0-9_-]{22}`

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents a destructive operation, DELETE /v1/sites/{site_key}, but provides no user-facing warning about its impact. Under the markdown criteria for missing warnings, destructive or system-affecting behavior should be explicitly disclosed so users understand the consequence before invoking it.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.