Back to skill

Security audit

apporbit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a read-only AppOrbit data lookup helper that fetches public ranking and metadata from disclosed sources without hidden persistence or destructive behavior.

Install only if you are comfortable with a Node.js helper making read-only network requests to GitHub and the AppOrbit website. Avoid setting APPORBIT_SOURCE or APPORBIT_SITE_DIR to untrusted data, because those inputs control what dataset the helper reads and analyzes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
Use the read-only helper in this skill's `scripts/query.mjs` for deterministic selection and calculations. Run the examples below from this skill's directory, o

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
Use the read-only helper in this skill's `scripts/query.mjs` for deterministic selection and calculations. Run the examples below from this skill's directory, o

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
Use the read-only helper in this skill's `scripts/query.mjs` for deterministic selection and calculations. Run the examples below from this skill's directory, o

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
Use the read-only helper in this skill's `scripts/query.mjs` for deterministic selection and calculations. Run the examples below from this skill's directory, o

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
Use the read-only helper in this skill's `scripts/query.mjs` for deterministic selection and calculations. Run the examples below from this skill's directory, o

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
Use the read-only helper in this skill's `scripts/query.mjs` for deterministic selection and calculations. Run the examples below from this skill's directory, o

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
Use the read-only helper in this skill's `scripts/query.mjs` for deterministic selection and calculations. Run the examples below from this skill's directory, o

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill explicitly instructs use of Node, shell commands, environment-controlled behavior, and remote network access, but it does not declare any tool restrictions or permission scope. That leaves the runtime with implicit broad capabilities, increasing the chance of unintended shell execution, unreviewed outbound requests, or abuse via attacker-controlled inputs such as APPORBIT_SOURCE or proxy-related fallback behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
The default ranking source is `https://raw.githubusercontent.com/ivershuo/apporbit/data/v1/`. Set `APPORBIT_SOURCE` or pass `--source` to use a fork's raw `data/v1/` URL or an absolute path to a local `v1` data directory. Under the bundled v1 contract, the source contains `views/agent-index-v1.json`, generated automatically by the collection workflow. If it is absent, follow the format-recovery steps below before concluding that the next collection must build it. The helper can still return ranks and movement when website metadata is temporarily unavailable; names then appear as `null` with a `metadataWarning`.

Before interpreting or analyzing records, read this skill's bundled [data format v1](references/data-format.md) in full. It defines the paths, record fields, index, quality statuses, and time rules needed to interpret the data correctly, and links to the published schemas for exact field types. Resolve field meanings from that reference yourself; give the user the analysis and relevant source links, without asking them to read the format document.

### Recover from a stale or incorrect bundled format

Static analysis

No suspicious patterns detected.