Back to skill

Security audit

Set up Open Agent Search

Security checks for vulnerabilities and agentic risk

Overview

This setup skill is coherent and purpose-aligned, but users should be aware it installs search tooling and modifies local agent configuration.

Install only if you want this project or agent connected to Open Agent Search. Review the MCP config changes before applying them, prefer project scope, avoid optional HTTP hosting unless you need it, and consider pinning or separately verifying the `skills` installer package before running the `npx --yes skills add` command.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Rp1

Medium
Category
MCP Rug Pull
Confidence
65% confidence
Finding

uvx/uv tool run commands without ==version create a rug-pull risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The skill instructs use of npx --yes skills without pinning a specific package version or verifying integrity. Because npx resolves and executes code from the package registry at runtime, a compromised latest release, typo-squatted dependency, or unexpected upstream change could cause arbitrary code execution on the user's machine during setup.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest suggests activation via the general instruction "Use $open-agent-search-setup to connect Open Agent Search in this project," but does not define when this skill should or should not be invoked. It provides no negative examples or scope constraints, which can lead to unintended activation whenever a user mentions connecting search tools in a project.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.