Back to skill

Security audit

Reverse Engineering

Security checks for vulnerabilities and agentic risk

Overview

This skill is a structured reverse-engineering workflow with disclosed local note storage and explicit safety boundaries.

Before installing, be aware that this skill may create local reverse-engineering notes under ~/reverse-engineering/ and may help analyze sensitive binaries, APIs, protocols, or traces. Use it only for targets you are authorized to inspect, keep production or third-party systems out of scope unless explicitly approved, and avoid storing credentials or sensitive payloads in the durable memory folder.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
## Requirements

- Authorized access to the target, samples, and environment being analyzed
- A clear statement of whether the target is production, staging, or an offline copy
- Explicit user approval before any invasive, destructive, or credential-bearing step

## Core Rules

Static analysis

No suspicious patterns detected.