Back to skill

Security audit

Phantom Limb

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent static-analysis guide, but it may cause an agent to read secret-bearing environment and deployment files without clear redaction or user approval.

Use this skill only on repositories where you are comfortable letting the agent inspect configuration files. Before running it, prefer sanitized .env examples or key-only extracts, and avoid exposing real tokens, passwords, CI secrets, production connection strings, or deployment secret manifests in the agent context.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:62
Finding

Sensitive Configuration Values May Be Exposed During Environment Cross-Referencing

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 62
Vulnerability Type: Excessive inspection of secret-bearing configuration files
Risk Level: Medium

Complete Code Snippet:

markdown
**Detection method:** Cross-reference every `process.env`, `os.environ`, `ENV[]` read against actual `.env`, `.env.example`, CI/CD configs, and deployment manifests.

Technical Analysis

The Skill directs the agent to inspect actual .env, CI/CD configuration, and deployment manifest files. These resources frequently contain API keys, access tokens, passwords, private endpoints, and other deployment secrets.

Comparing environment-variable references with declared variable names is relevant to the stated dependency-analysis function. However, reading or retaining the corresponding values is not necessary. The instruction does not require key-only parsing, value redaction, explicit authorization, repository-boundary enforcement, or exclusion of secret-bearing CI/CD fields. Consequently, secret values could enter the model context, tool logs, conversation history, or generated report.

No executable network request or instruction to transmit collected information externally was identified. References to outbound payloads and APIs describe static-analysis targets, while the Skill explicitly claims “Zero API calls.” The risk is therefore inadvertent local disclosure rather than confirmed exfiltration.

Attack Path

  1. A user invokes the Skill against a repository or workspace.
  2. The agent follows the instruction to cross-reference environment reads against actual .env, CI/CD, or deployment files.
  3. The agent opens a file containing plaintext credentials or tokens.
  4. Complete secret values enter the agent context or tool execution logs even though only variable names are needed.
  5. The values may subsequently be reproduced in diagnostic output, retained in conversation history, or exposed to users who can acc ...[truncated 754 chars]
Remediation
View remediation

Remediation Suggestions

  1. Inspect configuration keys and schemas only; never load secret values when determining whether an environment variable is declared.
  2. Parse .env files using a key-only routine that discards text after the assignment delimiter before it enters model context or logs.
  3. Redact values from CI/CD configurations and deployment manifests, including encoded or templated secret fields.
  4. Exclude credential stores, secret manifests, encrypted-secret outputs, and platform-specific secret contexts by default.
  5. Require explicit user authorization before accessing known secret-bearing files or locations.
  6. Restrict inspection to the user-approved project root and reject path traversal, symlink escapes, and unrelated host configuration.
  7. Add an output policy prohibiting secret values from appearing in reports, diagnostics, prompts, or retained artifacts.
  8. Document that only the existence and names of environment variables are required for this analysis.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The 'Invoke when' section lists broad situations such as onboarding, architecture review, and before deploy, but does not define specific trigger phrases, scope constraints, or non-applicable cases. This makes activation ambiguous and could cause the skill to be invoked in many ordinary engineering contexts beyond the intended use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.