Back to skill

Security audit

Agent Caps

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible offline manifest-validation tool, but its install instructions fetch and then run mutable remote Python code without verification.

Review before installing. Prefer using the packaged agent_caps.py rather than the documented curl command, or require a pinned release plus checksum verification. Do not rely on this validator alone as a security gate until schema enforcement is complete.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:32
Finding

Unpinned Remote Payload Retrieval Followed by Execution

Content
View full analysis
Remediation
View remediation
/agent_caps.py echo ' agent_caps.py' | sha256sum --check - python agent_caps.py self-test ``` 4. Prefer signed release artifacts and document signature verification. 5. Avoid automatically overwriting an existing local script. 6. Ensure CI workflows use repository-checked code or immutable, verified artifacts rather than mutable remote source files. 7. Apply the same correction to both `SKILL.md` and `README.md`. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
agent_caps.py:57
Finding

Manifest Validator Does Not Enforce Its Declared Schema

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file presents an example manifest for an unrelated skill ('OpenClaw') inside a package intended for defining and auditing safe capability manifests. Embedding a manifest with broad operational capabilities and external dependencies in this context is dangerous because it can normalize or facilitate installation of a mismatched, over-privileged skill under the guise of a safety-focused package.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The declared capabilities include browser automation, GUI/desktop control, messaging, and Telegram integration, which are unrelated to a manifest-auditing skill and materially increase attack surface. In this skill context, such capabilities are especially dangerous because users may trust the package as a safety tool while it requests powerful execution and communication channels that could enable data exfiltration, remote control, or covert operator interaction.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises file read/write-related capabilities but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity: a host may install or trust the skill without a clear least-privilege boundary, increasing the chance of unintended filesystem access when the skill is used or interpreted by an agent framework.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Line L064 states that check-deps 'cross-verifies claims against reality before the agent goes live,' which implies broader real-world verification than manifest-based dependency resolution. Elsewhere in the same README, L077-L078 describe check-deps more narrowly as resolving declared dependencies against known agents/manifests, so the claim at L064 overstates and contradicts the documented functionality.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
test_agent_caps.py:14