Back to skill

Security audit

Ariadne Thread

Security checks for vulnerabilities and agentic risk

Overview

This skill is a documentation and codebase-indexing guide with broad but disclosed local file changes and no evidence of hidden execution or data exfiltration.

Install this if you want an agent to add and maintain local project navigation files. Expect it to read repository structure and modify AGENTS.md, INDEX.md, llms.txt, docs, and file headers; avoid using it for small projects or casual code searches where that extra persistent documentation is not desired.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

markdown
## Architectural Constraints

<!-- Typical Web app layers; adapt to project: app/, packages/, layers/, etc. -->
- Dependency direction: presentation → domain → infrastructure (never reverse)
  Example: ui/ → core/ → infra/ — or app/features/, packages/core/, etc.
- All external calls (HTTP, DB, cache) go through infrastructure layer — e.g. `src/infra/` or `[project-path]/infra/`

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/index-templates.md (reported line 20)May include surrounding context.

md
## Directory Map

<!-- Typical Web app layout; adapt to project: app/, packages/, layers/, monorepo sub-packages, etc. -->

\```
src/              # (or include/ + src/ for C/C++; or app/, packages/, etc.)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/index-templates.md (reported line 188)May include surrounding context.

md
## Dependents (Fan-in: [N])

<!-- Prefer structural navigation via this list over semantic search. Use repo-root-relative paths. -->
<!-- Optional edge type: [imports] | [inherits] | [instantiates] per line -->
<!-- Discovery: grep -rn "from [this_module]" . or grep -rn "import [this_module]" . -->
<!-- If Fan-in > 10, group by parent module instead of listing individual files -->

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/naming-api-conventions.md (reported line 161)May include surrounding context.

POST /api/v1/users # Create GET /api/v1/users/:id # Read PATCH /api/v1/users/:id # Update DELETE /api/v1/users/:id # Delete GET /api/v1/users/:id/orders # Sub-resource

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation criteria in the front matter are unusually expansive, including broad requests like project structuring, codebase navigation, and any mention of 'ariadne'. In an agentic system, this can cause the skill to activate outside its intended niche, steering workflows or documentation changes in contexts where a lighter or different skill would be more appropriate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/index-maintenance.md (reported line 9)May include surrounding context.

md
| Trigger | Required Action |
|---------|----------------|
| File added | Add entry to parent `INDEX.md` Files table |
| File renamed/moved | Update parent `INDEX.md`; update `AGENTS.md` if in navigation table |
| File deleted | Remove from parent `INDEX.md`; update `AGENTS.md` if in navigation table |
| Module added | Create `INDEX.md` with all sections; update `AGENTS.md` directory map + navigation |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill defines broad natural-language triggers such as "documentation sync", "update docs", and "iteration end" that can cause the agent to enter a multi-step workflow without strong scoping or confirmation. In an agent setting, ambiguous trigger phrases increase the chance of unintended execution, especially when a user mentions those phrases incidentally rather than as an explicit command.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The 'When to Use' section still relies on ambiguous terms such as 'ariadne' and 'codebase navigation' without enough disambiguation. This increases the chance of accidental invocation, but the effect is primarily workflow misrouting rather than direct code execution or data compromise.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.