Back to skill

Security audit

Monitor

Security checks for vulnerabilities and agentic risk

Overview

This monitoring skill is mostly coherent, but it asks agents to run recurring user-defined commands and uses unsafe command templates without enough guardrails.

Review this skill before installing. It is not clearly malicious, but only use it where monitor definitions are trusted, avoid or tightly approve custom command checks, validate URLs and webhook destinations, and assume alert payloads may expose service names, outages, timestamps, and failure details to configured third-party services.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
templates.md:17
Finding

Shell Command Injection Through an Unquoted HTTP Monitor Target

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
alerts.md:71
Finding

Curl Option Injection Through a User-Provided Webhook URL

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The template explicitly supports a custom check where the user supplies an arbitrary command and the agent runs it. That expands the skill from monitoring into general command execution, creating a high-risk path for destructive local actions, privilege misuse, or lateral movement if the agent has host or SSH access.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

The referenced Pushover API endpoint confirms that this skill relies on an external network destination for alert delivery. In context, this is less indicative of malicious behavior than hidden exfiltration, but it still creates a data exposure surface because internal incident information leaves the local environment.

Content

Scanner excerpt · alerts.md (reported line 65)May include surrounding context.

Pushover

bash
curl -s -X POST https://api.pushover.net/1/messages.json \
  -d "token=$PUSHOVER_TOKEN" \
  -d "user=$PUSHOVER_USER" \
  -d "message=$MESSAGE"

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

The referenced Pushover API endpoint confirms that this skill relies on an external network destination for alert delivery. In context, this is less indicative of malicious behavior than hidden exfiltration, but it still creates a data exposure surface because internal incident information leaves the local environment.

Content

Scanner excerpt · alerts.md (reported line 65)May include surrounding context.

Pushover

bash
curl -s -X POST https://api.pushover.net/1/messages.json \
  -d "token=$PUSHOVER_TOKEN" \
  -d "user=$PUSHOVER_USER" \
  -d "message=$MESSAGE"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The webhook channel sends alert contents to a user-supplied external URL, but the skill text does not warn users that monitor names, status history, timestamps, outage details, and possibly error messages will be disclosed to a third party. In a monitoring skill, this is a real privacy and data-governance issue because users may configure alerts for internal services and unintentionally exfiltrate operational metadata outside their environment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

md
"name": "api-health",
  "description": "Check API returns 200",
  "checks": [
    {"type": "http", "target": "https://api.example.com/health", "expect": 200}
  ],
  "interval": "5m",
  "requires": []

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · templates.md (reported line 12)May include surrounding context.

md
"name": "api-health",
  "description": "Check API returns 200",
  "checks": [
    {"type": "http", "target": "https://api.example.com/health", "expect": 200}
  ],
  "interval": "5m",
  "requires": []

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation normalizes running user-provided commands without any visible warning about code execution risk, shell injection, data destruction, or privilege boundaries. In a skill whose purpose is monitoring, presenting arbitrary command execution as a routine template makes unsafe use more likely and reduces informed consent for users and operators.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.