Back to skill

Security audit

deploy-packager

Security checks for vulnerabilities and agentic risk

Overview

This skill presents itself as an automated deployment packager, but its script can read arbitrary plan-supplied local paths and falsely reports live uploads without creating or uploading packages.

Do not use this in an unattended CI/CD deployment path unless it is fixed. It should validate package paths against a project-local allowlist, reject traversal and absolute paths, create and verify real archives, and only report upload success after a real copy/upload completes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
script/package.py:24
Finding

Arbitrary Local File Read Through Unvalidated Package Paths

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill text claims a narrowly scoped packaging/upload role, but the behavior implied by the findings includes extra file enumeration and manifest/checksum generation while not clearly implementing the stated archive/upload actions. This mismatch is risky because reviewers and operators may approve or invoke the skill under false assumptions, allowing broader file inspection or unexpected data handling in a deployment pipeline.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script claims to create deployment bundles and upload them to shared storage, but in live mode it only constructs a target path, prints a success message, and writes a manifest. This is a security-relevant integrity issue because operators or downstream automation may trust the manifest and logs as evidence that deployable artifacts exist, enabling silent deployment failure, release confusion, or abuse of the false audit trail.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill describes file read/write style behavior but does not declare any explicit tool scope or permission boundaries. In an automated packaging/deployment context, missing scope constraints increases the chance that the agent can read unintended files or write artifacts outside the intended deployment area, especially when it is instructed to trust upstream input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly directs unattended upload to a shared storage location accessible by all team members and CI/CD servers, while also stating that it trusts upstream packaging plans and skips re-audit or confirmation. In this context, a malicious or mistaken packaging plan could cause sensitive files, secrets, or non-deployment artifacts to be automatically published to a broadly accessible location, making exposure and downstream compromise more likely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

In live mode, the code logs '[LIVE] Uploaded' for a bundle path even though no tarball is created and no upload occurs. This misleading success signal can cause users or CI/CD systems to proceed under false assumptions, weakening operational trust and masking failed or missing release artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The file's user-facing description and operational instructions are entirely in Chinese, which can constitute a language/locale policy issue when no user opt-in or alternative is offered. There is no indication that the skill is region-specific or intentionally constrained to Chinese-speaking users.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.