Back to skill

Security audit

Audit Log Hook

Security checks for vulnerabilities and agentic risk

Overview

This audit-logging skill has a legitimate purpose, but its examples can record sensitive tool inputs, outputs, user IDs, and session IDs without effective redaction.

Use only after changing the examples to log minimal metadata by default, applying tested recursive redaction before any log output, and setting strict log access, retention, and deletion rules. Avoid enabling it in environments with secrets, regulated data, or private file contents unless those controls are in place.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Unredacted Tool Parameters and Results Exposed in Audit Logs

Content
View full analysis
{ const entry = { ts: new Date().toISOString(), event: "before_tool_call", tool: event.tool.name, params: JSON.stringify(event.tool.params).slice(0, 500), session: ctx.sessionKey, user: ctx.session?.senderId || 'unknown' }; console.log("[AUDIT]", JSON.stringify(entry)); return {}; }); api.registerHook("after_tool_call", async ({ event, ctx }) => { const entry = { ts: new Date().toISOString(), event: "after_tool_call", tool: event.tool.name, result: String(event.result).slice(0, 200), error: event.error?.message || null, duration: event.durationMs, session: ctx.sessionKey }; console.log("[AUDIT]", JSON.stringify(entry)); return {}; }); ``` The separately documented redaction function is: ```javascript function redactSensitive(obj) { const sensitive = ['apiKey', 'token', 'password', 'secret']; for (const key of Object.keys(obj)) { if (sensitive.some(s => key.toLowerCase().includes(s))) { obj[key] = '[REDACTED]'; } } return obj; } ``` ### Technical Analysis The hooks serialize tool parameters and results directly into console logs. Tool calls can contain API credentials, authorization headers, passwords, private file content, personal information, command arguments, or other sensitive values. The documented `redactSensitive` function is not invoked by either hook. Consequently, the statement that sensitive fields are automatically redacted does not match the demonstrated implementation. Even if the function were invoked, it would provide incomplete protection because: - It examines only top-level object keys. - It does not recursively process nested objects or arrays. - It relies ...[truncated 2112 chars]
Remediation
View remediation
{ console.log("[AUDIT]", JSON.stringify({ ts: new Date().toISOString(), event: "before_tool_call", tool: event.tool.name })); return {}; }); api.registerHook("after_tool_call", async ({ event }) => { console.log("[AUDIT]", JSON.stringify({ ts: new Date().toISOString(), event: "after_tool_call", tool: event.tool.name, success: !event.error, duration: event.durationMs })); return {}; }); ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill claims sensitive fields are auto-redacted, but the actual hook examples log raw tool parameters and raw results directly via JSON.stringify(event.tool.params) and String(event.result) without invoking the redaction helper. In an audit-hook context this is especially dangerous because tool calls often carry credentials, prompts, tokens, personal identifiers, command output, or file contents, so the logs can become a secondary sensitive-data store.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The purpose section promotes recording all tool calls for auditing and debugging but does not clearly warn users that parameters, results, session identifiers, and user IDs may be captured. This omission undermines informed use and can lead operators to deploy broad logging without understanding the privacy and secret-exposure consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The sensitive-data section suggests redaction exists, but it is incomplete and not presented as a clear warning, while the surrounding examples still log raw params and results before any redaction is applied. That mismatch creates a false sense of safety and increases the likelihood of accidental secret and PII disclosure during routine tool use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.