Back to skill

Security audit

hodman

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Hodman CLI operating guide with explicit approval and credential-handling safeguards for sensitive project operations.

Install this only if you intend to let an agent operate your Hodman projects through the Hodman CLI. Review commands before approving writes, publishing, shell execution, mutable SQL, connector grants, or any credential reveal, and keep real tokens in the protected UI or a trusted human terminal rather than chat.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
- `hodman messengers status` discovers the selected project's supported channels and current connection health without exposing credentials.
- `hodman messengers mattermost setup|status` returns Mattermost prerequisites, state and the protected Project Settings deep link. Ask the user to enter the server URL and bot token in that UI; never ask them to paste the token into chat or print it in CLI output.
- `hodman messengers slack setup|status` returns Slack Socket Mode prerequisites, state and the protected Project Settings deep link. Both Slack tokens remain UI-only and write-only.
- `hodman messengers teams setup|status` returns Microsoft Teams prerequisites, state and the protected Project Settings deep link. Entra tenant ID, Microsoft App ID, client secret and access tokens remain UI-only/write-only and must never be accepted or printed by these commands.
- `hodman messengers telegram ...` manages the selected project's platform Telegram channel. Use it when the user wants to talk to the Hodman project agent in Telegram, approve an observed chat, or send a bounded notification to an already approved chat.
- `hodman connectors ...` manages tenant-level App Connections and their source-project grants. These grants allow one project's project CLI to be called by another project; they do not connect Telegram or broaden Inbox access.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: hodman
description: "Use Hodman to turn useful personal AI work into controlled, auditable company projects: create or select applications and agents, delegate work, publish them, and operate them through the user-authorized CLI."
---

# Hodman

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to use Hodman whenever the user asks to work with a project hosted on Hodman is high-level and does not define clearer boundaries or exclusion cases. Because it lacks specific trigger phrases or negative examples, it may cause unintended invocation for a wide range of ordinary project-work requests.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE (reported line 12)May include surrounding context.

text
permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,
INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A
PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT
HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION
OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE

Static analysis

No suspicious patterns detected.