Back to skill

Security audit

context-engineering

Security checks for vulnerabilities and agentic risk

Overview

This skill provides context-management guidance and local audit utilities; its file reading and report-writing behavior is purpose-aligned and disclosed enough to treat as benign with caution.

Install only if you want an agent to help organize and audit local context. Before running the scripts or adopting the template, choose session directories deliberately, avoid including secrets or private logs unless necessary, review where audit reports and resume briefs will be written, and tighten the template rules for sensitive projects.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (12)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Persistent Context Injection

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill injects content designed to persist in agent memory or context across interactions. Persistent injection can alter agent behavior long after the initial interaction.

Content

Scanner excerpt · SKILL.md (reported line 315)May include surrounding context.

md
For long-running tasks, keep the most important constraints in a
durable location or use the runtime's supported mechanism for
persistent instructions.

Do not repeatedly duplicate the entire instruction set.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/progressive-disclosure-patterns.md (reported line 354)May include surrounding context.

md
Tool outputs are the single largest source of context bloat in most
sessions. A single `read_file` on a large source file can consume 30%
of the context window. Twelve log files can fill the window entirely.

The rule: **any tool output larger than 2,000 tokens must be
summarized before it enters context.**

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · references/token-budget-framework.md (reported line 1253)May include surrounding context.

26. Anti-Patterns

Anti-pattern 1 — Fill the context window

text
"If the model supports 1M tokens, use 1M tokens."

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest describes a skill for diagnosing and improving context usage in AI agent sessions, which implies analysis of session artifacts. This implementation also creates a persistent audit directory under ~/.context-engineering/audits and saves JSON reports there by default, which is additional file-writing behavior not indicated by the description.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The on_demand load rule relies on broad topic-keyword matching and task dependency, which is underspecified and can cause overloading of irrelevant reference material or loading sensitive/internal files too eagerly. In a context-management skill, that ambiguity directly undermines the stated goal of minimizing context and can be exploited by crafted prompts that mention many keywords to force unnecessary context inclusion.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · templates/context-profile.yaml (reported line 88)May include surrounding context.

yaml
# Rules express precedence and policy. They resolve conflicts between
# tiers and prevent common architectural mistakes.
#
# Write rules as imperative sentences. Each rule should be testable —
# a reviewer should be able to say "yes, this session followed that
# rule" or "no, it did not."

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The rule to load a skill only if its description matches the active task is too vague to enforce safely, because 'matches' is undefined and can be stretched by adversarial or merely noisy task descriptions. In an agent environment, ambiguous skill-selection criteria can trigger unnecessary or inappropriate skill loading, expanding the instruction surface and increasing the chance of prompt-conflict or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Mandating that the final action of every session is to write context/resume-brief.md introduces automatic persistence of session-derived content without any disclosure, consent, or data-minimization guardrails. This can capture sensitive prompts, user data, secrets, or proprietary material and store them beyond the active session, creating privacy and retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The emergency compression action instructs the agent to cache all tool outputs to disk, but provides no warning about persistence, sensitivity classification, access control, or redaction. Tool outputs commonly contain credentials, internal code, logs, or personal data, so unconditional disk caching can materially increase exposure and retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code creates an output directory and writes an audit JSON report containing derived information from session artifacts, which may include sensitive conversation or system-context metadata. While the CLI has an --output-dir option, there is no explicit warning in code comments, prompts, or user-facing output before the write occurs to make persistence of potentially sensitive audit results clear.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The manifest frames the skill as diagnosing and improving context usage in agent sessions. The compare mode depends on enumerating previously saved reports from a persistent local store and introduces longitudinal report-management behavior that is not obviously required by that purpose as stated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.