Back to skill

Security audit

Peeps: Your people, remembered.

Security checks for vulnerabilities and agentic risk

Overview

This contact-memory skill is purpose-related but needs Review because it stores sensitive relationship data in plaintext, mandates external lookups, silently mutates action history, and uses unverified mutable update/install paths.

Install only if you are comfortable keeping sensitive contact and relationship notes as local plaintext files. Avoid storing secrets or highly sensitive third-party details, keep the directory out of shared repos and sync folders, require confirmation before web searches or image downloads, and do not use the mutable GitHub-main update path or unpinned npx install without reviewing and pinning the exact version.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T08 · Insecure Dependencies

Error
Location
README.md:42
Finding

Unpinned Third-Party Package Execution During Installation

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:35
Finding

Mutable Remote Skill Payload Retrieved Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:3
Finding

Sensitive Personal and Contact Data Stored in Plaintext Markdown

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:54
Finding

Automatic Disclosure of Person Names and Context to External Search Providers

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:32
Finding

Silent Destructive Cleanup Triggered by Reading the Actions File

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill presents itself as a local contacts tool, but repeatedly requires outbound web searches and remote fetches during normal operation. This expands the trust boundary, can disclose user queries about real people to third parties, and creates a mismatch between user expectations and actual network behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs silent cleanup and deletion of user data, including automatic removal and status changes, without notice or confirmation. Silent mutation of personal records can destroy context, reduce auditability, and cause loss of information the user expected to retain.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs storing highly sensitive personal details—such as debts, conflicts, health issues, family information, and topics to avoid—in plain markdown for later use. Centralizing intimate third-party data in human-readable local files increases exposure risk if the workspace is accessed, synced, indexed, or surfaced by other tools.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The recurring 'Peeps: check' behavior directs the agent to proactively inspect random personal files and surface details in DM or other channels. In a dataset that explicitly includes private notes, family details, health issues, and sensitive topics, proactive resurfacing materially increases the chance of privacy leakage and context-inappropriate disclosure.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The skill explicitly instructs updating itself by fetching a remote SKILL.md and replacing the local file, which is direct self-modification. Self-modifying behavior is dangerous because it bypasses stable review boundaries and allows remote content to redefine future instructions and capabilities.

Content

Scanner excerpt · SKILL.md (reported line 187)May include surrounding context.

Updating

To update this skill to the latest version, fetch the new SKILL.md from GitHub and replace this file:

text
https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This skill handles highly sensitive personal contact and relationship data, but the introductory description does not clearly foreground the privacy implications and local plaintext storage risks. Users may store sensitive notes, affiliations, and interpersonal context without realizing those files may be readable by other local processes, backups, sync tools, or shared accounts.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 37)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

bash
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 38)May include surrounding context.

bash
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 190)May include surrounding context.

bash
mkdir -p ~/.claude/skills/peeps
curl -o ~/.claude/skills/peeps/SKILL.md https://raw.githubusercontent.com/haah-ing/peeps-skill/main/SKILL.md

Other agents

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Mandating web searches for people before asking follow-up questions sends personal names and context to external services without a clear privacy warning or consent step. Because this skill handles relationship data, even a simple lookup may reveal sensitive associations or intentions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to fetch headshots and store them locally introduces collection of third-party personal data that is not necessary for basic contact remembrance or introductions. It increases privacy risk, copyright/licensing risk, and may normalize saving biometric-adjacent imagery without clear consent or need.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Fetching external images into local assets without a strong consent and provenance flow can import unnecessary personal data and untrusted content. The lack of a clear warning is especially problematic in a skill centered on private contacts and personal relationship notes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Suggesting cron-based periodic execution gives the skill a standing background presence unrelated to a simple on-demand contacts utility. This increases the chance of repeated unsolicited access to personal files and proactive disclosure of sensitive relationship data.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The self-update instruction pulls remote content from GitHub and replaces the skill file, introducing an administrative network capability outside the skill's stated purpose. This creates a supply-chain and integrity risk because future behavior can change via remote content without review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The self-update flow instructs replacing the skill from a remote URL without a safety review or verification step. This can silently alter future behavior and permissions, making the skill vulnerable to supply-chain compromise or unsafe upstream changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.