Back to skill

Security audit

Ansible

Security checks for vulnerabilities and agentic risk

Overview

This is a short Ansible reference skill with no executable payload and no hidden behavior.

Installers should understand that this skill may remind an agent about Ansible privilege-escalation options, so review any playbook changes involving become or sudo before running them. The skill itself is Markdown-only and does not execute those actions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Content
- `--force-handlers` to run even on failure — or `meta: flush_handlers`

## Become (Privilege Escalation)
- `become: yes` to run as root — `become_user:` for specific user
- `become_method: sudo` is default — use `su` or `doas` if needed
- Password needed for sudo — `--ask-become-pass` or in ansible.cfg
- Some modules need become at task level — even if playbook has `become: yes`
Confidence
80% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Content
## Become (Privilege Escalation)
- `become: yes` to run as root — `become_user:` for specific user
- `become_method: sudo` is default — use `su` or `doas` if needed
- Password needed for sudo — `--ask-become-pass` or in ansible.cfg
- Some modules need become at task level — even if playbook has `become: yes`

## Conditionals
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Static analysis

No suspicious patterns detected.