Back to skill

Security audit

Skill Safety Auditor

Security checks for vulnerabilities and agentic risk

Overview

This local security-audit skill mostly does what it says, but it should be reviewed because its quick scan can print suspected secrets and it writes audit history locally.

Use this only on skill directories you intend to audit, and avoid running quick-scan.sh in shared terminals or CI logs when the target may contain real secrets. Review or patch the scanner to redact secret values and escape JSON safely before relying on its reports for release decisions. Periodically clear or protect the local audit data directory if report history or file paths are sensitive.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/quick-scan.sh:36
Finding

Detected secrets are disclosed through console and CI output

Content
View full analysis
/dev/null | head -5 || true) if [[ -n "$SECRETS" ]]; then echo "⚠️ Potential secrets found:" echo "$SECRETS" else ``` ### Technical Analysis The quick scanner stores complete source lines matched by the secret-detection expression in `SECRETS` and then prints those lines without redacting the detected value. A matching line can contain an entire password, API key, or authentication token. Although the scanner needs to identify the location of suspected credentials, disclosing the complete matching line is unnecessary. When the script runs in a terminal, build pipeline, release workflow, or hosted CI service, its standard output may be retained in logs and made available to a broader group than the original source file. The scanner's own pattern definitions can also produce false positives when it scans itself, as demonstrated by the bundled historical audit report. That accuracy issue does not eliminate the disclosure risk when an actual secret is present. ### Attack Path 1. A target skill contains a plaintext credential matching one of the scanner's regular expressions. 2. A developer or automated pipeline invokes `scripts/quick-scan.sh` against that skill. 3. `grep` captures the complete credential-bearing source line. 4. `echo "$SECRETS"` writes the complete line, including the credential, to standard output. 5. Terminal recording, CI log retention, or centralized log collection preserves that output. 6. A user with access to those logs obtains and reuses the exposed credential. ### Impact Assessment This issue does not direct ...[truncated 453 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/audit-skill.sh:98
Finding

Unescaped target-controlled values can corrupt or inject audit report JSON

Content
View full analysis
"$REPORT_FILE" << EOF { "audit_id": "$AUDIT_ID", "skill": "$SKILL_NAME", "timestamp": "$TIMESTAMP", "summary": { "critical": $CRITICAL, "high": $HIGH, "medium": $MEDIUM, "low": $LOW, "info": $INFO }, "findings": [$JSON_FINDINGS], "passed": $PASSED, "recommendations": [ "Review all findings above medium severity", "Fix critical and high severity issues before release", "Consider addressing medium severity issues" ] } EOF ``` ### Technical Analysis The report is assembled through shell string interpolation rather than a JSON serializer. Values such as `$file` and `$SKILL_NAME` can originate from target-controlled directory or file names. These values are inserted between JSON quotation marks without escaping quotation marks, backslashes, newlines, or other JSON control characters. A target containing a crafted file name can therefore cause a finding to carry attacker-controlled JSON syntax into the generated report. Depending on the crafted name, the report may become syntactically invalid, acquire misleading fields, contain duplicate keys, or have an attacker-influenced structure. The issue is especially relevant because audit reports are security records that may be parsed by release gates or other automation. The vulnerability is limited to report integrity; the reviewed code does not ...[truncated 1640 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is described primarily as performing security audits, but it also exposes report-listing behavior (list-audits.sh) that enumerates stored audit artifacts instead of auditing a supplied target. This mismatch can mislead operators about what data the skill accesses and may enable unintended disclosure of prior audit history or metadata when the skill is invoked under the assumption it only analyzes a provided skill.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
./scripts/audit-skill.sh /path/to/skill --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
./scripts/audit-skill.sh /path/to/skill --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
./scripts/audit-skill.sh /path/to/skill --verbose

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 226)May include surrounding context.

md
./scripts/audit-skill.sh /path/to/skill --verbose

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 174)May include surrounding context.

md
- API keys and tokens
- Database passwords
- Private keys
- Access credentials
- Environment variable patterns

### Code Safety

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises and demonstrates shell-script execution (./scripts/...) but does not declare any explicit tool scope such as permissions or allowed-tools. This creates a governance gap where callers and reviewers cannot clearly see that shell access is required, increasing the chance of unintended or over-broad execution in environments that rely on metadata for enforcement.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 185)May include surrounding context.

md
- Dynamic code execution

### File Permissions
- World-writable files
- Executable permissions on data files
- Sensitive file accessibility

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit-skill.sh (reported line 190)May include surrounding context.

sh
- Dynamic code execution

### File Permissions
- World-writable files
- Executable permissions on data files
- Sensitive file accessibility

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/audit-skill.sh (reported line 187)May include surrounding context.

sh
if [[ "$SCAN_TYPES" == "all" ]] || [[ "$SCAN_TYPES" == *"permissions"* ]]; then
    [[ "$VERBOSE" == true ]] && echo "Checking file permissions..."
    
    # Check for world-writable files
    while IFS= read -r file; do
        if [[ -n "$file" ]]; then
            add_finding "medium" "permissions" "$file" 0 "World-writable file detected" "Remove world-write permission: chmod o-w $file"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This script writes a generated report via shell redirection and may also copy it to a user-specified output path, but those file-modifying actions are performed without confirmation prompts or preceding comments/docstrings warning that files will be created or overwritten. Although a final status message is printed after the write, there is no advance disclosure near the operation itself, which can surprise users when an existing output path is replaced.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger guidance includes broad phrases like 'audit' or 'security check,' which can cause the skill to activate in contexts where the user did not intend this specific skill. Unintended activation is lower severity than code execution flaws, but it can still lead to unnecessary shell/script execution or unexpected access to local files and reports.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/audit-skill.sh:169

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/quick-scan.sh:46