Back to skill

Security audit

Add Task

Security checks for vulnerabilities and agentic risk

Overview

This skill has a narrow task-file purpose, but it writes persistent workflow files with inconsistent placement rules and unsafe handling of user-supplied content.

Review this skill before installing. It appears intended for local SDD task tracking, not theft or destruction, but users should fix the draft/todo path inconsistency, include or remove the folder-creation script, and ensure stored prompts, titles, and dependencies are safely serialized and treated as untrusted input by later workflow stages.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:102
Finding

Persistent Prompt Injection Through Verbatim User Input

Content
View full analysis
..md`: ```markdown --- title: depends_on: --- ## Initial User Prompt {EXACT user input as provided} ## Description ``` ### Technical Analysis The skill explicitly requires the agent to copy untrusted user input verbatim into a persistent Markdown task file. It does not require escaping Markdown control syntax, neutralizing code fences, validating embedded instructions, or otherwise distinguishing the copied text from trusted workflow instructions. These task files are intended to be consumed during later workflow stages. An attacker can therefore include headings, front matter delimiters, code-fence terminators, or agent-directed instructions in the original request. Once persisted, that content may be interpreted by a downstream agent as authoritative task guidance rather than inert user-supplied data. This is best classified as agent memory poisoning because attacker-controlled instructions are written into workflow state that survives the current invocation and may influence future agent processing. ### Attack Path 1. An attacker submits a task request containing Markdown structure and malicious agent instructions. 2. The skill follows the requirement to preserve the input exactly. 3. The malicious text is written into a persistent file under the `.specs/tasks/` workflow hierarchy. 4. A later business-analysis, planning, or implementation stage reads the generated task file. 5. The downstream agent fails to distinguish the injected text from trusted task instructions. 6. The attacker influences later workflow actions beyond the intended task description. ### Impact Assessment Successful exploitation could manipulate down ...[truncated 504 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:104
Finding

YAML Front-Matter Injection Through Unescaped Task Metadata

Content
View full analysis
depends_on: --- ``` ### Technical Analysis The template places generated titles and user-provided dependency values directly into YAML front matter without requiring quoting, schema validation, filename validation, or safe serialization. A dependency value containing line breaks, colons, YAML collection syntax, anchors, tags, comments, or the `---` document delimiter could change the structure of the generated document. Similar risks apply to a generated title if it retains YAML-significant characters derived from the user request. This enables structural injection into metadata that downstream workflow components may consider trusted. The vulnerability arises from constructing YAML through textual interpolation rather than through a serializer operating on validated values. ### Attack Path 1. An attacker supplies a dependency argument containing YAML syntax or a front-matter terminator. 2. The skill interprets it as a dependency value and inserts it directly after `depends_on:`. 3. The injected newline or delimiter creates additional metadata fields, changes the dependency data type, or terminates the front matter. 4. A downstream YAML parser or agent loads the forged structure. 5. The downstream workflow acts on attacker-defined metadata or processes attacker content in a more trusted document context. ### Impact Assessment Exploitation could corrupt dependency resolution, forge task metadata, alter downstream workflow interpretation, or cause denial of service through malformed YAML. If later workflow stages recognize security-sensitive metadata fields, an attacker may also influence their behavior. No evidence shows that the current project defines privileged YAML fields or ...[truncated 152 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to run a shell script and create directories/files on disk, but does not warn the user that invoking the skill will modify the filesystem. In agent environments, silent writes and shell execution increase the risk of unintended repository changes, especially when user input is preserved into created files and the script path comes from an environment variable.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives conflicting instructions about where the task file should be created: most of the document says .specs/tasks/draft/, but the file creation step says to write into .specs/tasks/todo/. In an automated agent workflow, this inconsistency can cause files to be placed in the wrong lifecycle state, bypass review gates, or trigger downstream automation prematurely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.