Back to skill

Security audit

skill-prescan

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed remote LLM-based pre-scan tool for SKILL.md files, with no evidence of hidden persistence, destructive behavior, or privilege escalation.

Install only if you are comfortable sending the target SKILL.md, and a manifest of nearby file names and sizes, to the configured LLM provider. Do not scan secrets or proprietary material unless that provider is approved for it; use the confirmation prompt carefully and reserve --yes for controlled CI use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description says the scan is performed 'locally,' but the document itself states that the full SKILL.md is sent to a remote third-party LLM endpoint. That mismatch can mislead users into disclosing proprietary or sensitive content under the false impression that analysis stays on-device, and the claimed equivalence to the real scanner may also overstate security coverage.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
This tool reads the target `SKILL.md` and **sends its full contents to the

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
This tool reads the target `SKILL.md` and **sends its full contents to the

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill declares no explicit tool scope or permissions even though its documented behavior requires reading local files, accessing environment variables for API keys, and making outbound network requests. This is risky because users and automated reviewers cannot quickly verify the intended execution boundary, increasing the chance of unintended data exposure or over-broad execution in agent environments.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/scan.py (reported line 454)May include surrounding context.

python
if not args.yes:
        if not sys.stdin.isatty():
            print(
                "\nError: refusing to transmit without confirmation in a "
                "non-interactive session. Re-run with --yes to proceed.",
                file=sys.stderr,
            )

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
- **instruction_scope** — Are the instructions bounded and user-controlled?
- **install_mechanism** — Is the install path transparent and verifiable?
- **environment_proportionality** — Are credentials/environment requirements proportionate?
- **persistence_privilege** — Does the skill persist or escalate privileges?

### Key Rule from ClawHub's Scanner

Static analysis

No suspicious patterns detected.