Back to skill

Security audit

AO Job Heartbeat

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed helper for a hosted job-heartbeat service and its sensitive actions are purpose-aligned and user-directed.

Before installing, understand that this skill will use your AO Job Heartbeat API key to manage checks on the hosted service. Keep the API key and generated ping URLs private, and only approve deletion or test-fail actions when you intend to change or trigger alerts for a check.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 250)May include surrounding context.

md
helper; no setting or flag changes it. System proxy settings are ignored
  and redirects are refused.
- **Routes used:** `GET /v1/account`, `GET /v1/checks`, `GET /v1/checks/{id}`,
  `POST /v1/checks`, `DELETE /v1/checks/{id}`, `GET /v1/checks/{id}/events`,
  `GET /ping/{id}`, `POST /ping/{id}/fail`.
- **Data sent:** the API key in the `Authorization` header (account and
  check routes only); the check id in the URL; for `create`, only `name`,

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/jobhb.py (reported line 556)May include surrounding context.

python
' or d.get("ok")is not True or d.get("dropped")is not False)')

# macOS cron (cron-52) reads a crontab command into a 1000-byte buffer and keeps
# at most 999 bytes, dropping the rest without warning (VERIFIED 2026-10-04:
# the 0x3e8 size in /usr/sbin/cron on this Mac). It counts bytes, not
# characters: a non-ASCII character takes 2 to 4 bytes in UTF-8. Other crons
# may allow more.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill explicitly describes capabilities to read an environment variable, invoke a Python helper, and make outbound network requests, but it does not declare a corresponding tool scope such as permissions or allowed-tools. This creates a policy/visibility gap: a reviewer or runtime may not have an explicit machine-readable restriction set, increasing the chance of overbroad execution or accidental misuse of shell/network capabilities.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/jobhb.py (reported line 19)May include surrounding context.

python
account                         plan, email_verified, checks in use / allowed
  list                            the account's checks
  get ID                          one check
  create --name N --period P [--grace G]
                                  one new check; refused if the plan is full
                                  or a check with that name already exists
  delete ID --confirm             cancel a check (only after the human said yes)

Static analysis

No suspicious patterns detected.