Back to skill

Security audit

Network Device Monitor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real local network scanner, but its ARP mode can scan beyond the requested subnet and its scan target handling is under-scoped for agent use.

Review this before installing if you use agents on shared, corporate, or sensitive networks. Only run it on networks you are authorized to scan, avoid ARP mode unless you understand that it scans the local network segment, and prefer a validated narrow subnet and non-root nmap mode. Be aware it stores discovered device identifiers locally in a state file.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/scan-network.py:17
Finding

ARP Mode Ignores the Authorized Subnet and Scans All Local Networks

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scan-network.py:35
Finding

Unvalidated Subnet Input Permits Nmap Option Injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The documented behavior claims compatibility with router web UIs, but the visible usage relies on direct subnet scanning via external tools and user-supplied CIDR ranges. This mismatch can mislead users and reviewers about the actual security boundary, causing broader active network probing than expected and potentially increasing operational or policy risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill advertises and instructs use of shell execution and state-file writes, but it does not declare any explicit tool scope or permissions boundaries. In an agent ecosystem, this weakens reviewability and can allow a seemingly simple monitoring skill to run network scans and write persistent files without clear user or platform constraints.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

The skill explicitly instructs running the scanner with sudo for ARP mode, which raises the execution context of the entire Python script and any subprocesses it launches. If the script, its arguments, or dependencies are flawed, this can turn a routine network-monitoring task into privileged code execution or unintended system modification.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
## Notes

- ARP scan requires root: `sudo python3 scan-network.py --arp`
- nmap scan works without root but is slower
- Works on Linux and macOS
- No external API dependencies

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The implementation performs active host discovery across user-specified networks, which is broader and more invasive than the skill description implying passive interaction with a router web UI. In an agent-skill context, this mismatch matters because a caller may invoke what appears to be a benign monitoring skill but actually trigger direct reconnaissance of arbitrary subnets.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The ARP scan path ignores the provided subnet and always scans the local network via --localnet, causing behavior that differs from the user’s explicit target selection. This can lead to unintended probing of the current network segment, which is a security and privacy concern because the tool may touch systems the user did not intend to scan.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan-network.py (reported line 20)May include surrounding context.

python
def arp_scan(subnet):
    """Fast ARP-based scan (requires root)."""
    try:
        result = subprocess.run(["arp-scan", "--localnet"], capture_output=True, text=True, timeout=30)
        devices = []
        for line in result.stdout.splitlines():
            match = re.match(r'(\d+\.\d+\.\d+\.\d+)\s+([0-9a-f:]{17})\s+(.*)', line, re.IGNORECASE)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan-network.py (reported line 39)May include surrounding context.

python
def nmap_scan(subnet):
    """Nmap-based scan (no root required)."""
    try:
        result = subprocess.run(
            ["nmap", "-sn", "-oG", "-", subnet],
            capture_output=True, text=True, timeout=120
        )

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script actively probes the network immediately after argument parsing, but it provides no explicit warning, consent gate, or authorization check before sending scan traffic. In a reusable agent skill, this increases the chance of surprise reconnaissance on a local environment, which may violate policy, trigger alerts, or expose the user to operational risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.