Back to skill

Security audit

Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed server-administration guide for Homebutler, with sensitive capabilities called out and mostly scoped to user-directed actions.

Install this only if you want an agent to help administer the configured servers. Review the Homebutler config, tokens, and SSH access first, and require explicit approval for broad scans, write actions, service changes, restores, purges, and Proxmox power operations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: homebutler
description: Tells an agent what changed on a server since it last looked - plus status, Docker, backups, Proxmox. 44 MCP tools, each classed read, write or destructive.
metadata:
  {
    "openclaw": {

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
79% confidence
Finding

The skill explicitly authorizes autonomous execution of read-class tools without operator confirmation. Although framed as safe because reads do not modify systems, these tools can disclose sensitive operational data such as hostnames, internal addresses, open ports, processes, logs, and inventory details. In an agent setting, this creates a real risk of unauthorized reconnaissance and data exposure if the agent over-collects or shares results inappropriately.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
### What the classes mean for you

- **read** — changes nothing on the machine, so running one needs no
  confirmation. What comes back is another matter: hostnames, internal
  addresses, what is listening, what is running, log contents. So read the
  machine the operator is asking about rather than every machine in the config;

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 158)May include surrounding context.

comes from the archive rather than from you — which is why the CLI refuses a bind mount unless you name the path with --allow-bind. There is a backup_restore tool, and over MCP it never restores bind mounts, for the same reason: an agent has no way to name a host path it is allowed to write to, so the archive's bind mounts are refused and reported in the result.

bash

Static analysis

No suspicious patterns detected.