Back to skill

Security audit

Log Anomaly Detector

Security checks for vulnerabilities and agentic risk

Overview

This is a small log-analysis skill with no evidence of hidden access or persistence, but its sample implementation has reliability gaps users should not treat as a full security monitor.

Installing this skill should not expose your system by itself, but treat it as a simple helper rather than a dependable security control. Review or fix the timestamp function and missing warning/performance/security checks before relying on its output for alerting or incident response.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
skill.yaml:15
Finding

Stateful Global Regular Expression Causes Error-Detection Bypass

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skill.yaml:29
Finding

Undefined Timestamp Function Causes Log-Analysis Denial of Service

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skill.yaml:12
Finding

Declared Security Indicators Are Never Evaluated

Content
View full analysis
10) { results.recommendations.push('Excessive errors detected; configure an alert'); } return results; } ``` ### Technical Analysis Although the implementation declares warning, performance, and security expressions, only `patterns.error` is evaluated. The `warnings` and `anomalies` arrays are never populated, and the `sensitivity` parameter does not influence behavior. Consequently, log entries containing only `unauthorized`, `forbidden`, or `injection` are not identified as security events. Likewise, `WARN`, `slow`, `timeout`, and `latency` indicators are ignored despite the documented detection capabilities. This creates a fail-open security-monitoring condition: callers may rely on threat detection that the implementation does not perform. ### Attack Path 1. A user deploys or invokes the skill believing its declared security-threat detection is active. 2. An attacker performs activity that produces entries such as `unauthorized`, `forbidden`, or `injection`, without also producing `ERROR`, `FATAL`, or `Exception`. 3. The analyzer tests only the error expression. 4. The security-related entries do not populate `errors`, `warnings`, or `anomalies`. 5. No security recommendation or alert is returned, allowing the act ...[truncated 459 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill description is written as a Chinese-only instruction set, which can impose a specific language/locale on users without any stated opt-in or alternative. The policy explicitly calls out language or locale constraints as findings when the skill does not offer user choice or justify the restriction.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger patterns are broad and include generic phrases like '分析日志', '日志异常', 'log analysis', and 'error detection', which can match ordinary user requests rather than a narrowly scoped invocation. This creates an over-broad activation surface where the skill may intercept unrelated conversations about logs, causing unintended behavior, context leakage, or misuse of the skill in situations the user did not explicitly intend.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The file presents user-facing trigger and description text in both Chinese and English, but the implementation description and recommendation text are effectively Chinese-oriented and do not indicate any user language preference or opt-in. This can create a locale-policy issue if the skill defaults responses or interaction style to a specific language without documenting that choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.