Back to skill

Security audit

EvoClone

Security checks for vulnerabilities and agentic risk

Overview

This skill is disclosed as an agent-cloning and evolution tool, but it grants destructive rollback and persistent memory-mutation powers without enough safeguards.

Install only in a dedicated, backed-up agent-evolution workspace. Do not use it in important repositories unless rollback, survival mode, seed export, and shared knowledge indexing are gated by explicit approval, previewed diffs, secret review, and recoverable backups.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T02 · Agent Memory Poisoning

Error
Location
SURVIVAL.md:20
Finding

Persistent Agent Memory Mutation and Tool Lockout

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:39
Finding

Destructive Repository Rollback Without Adequate Data-Loss Safeguards

Content
View full analysis
". 2. **Backup**: `git branch backup/cycle__` 3. **Reset**: `git reset --hard ` 4. **Clean**: Remove untracked files if necessary. ``` ### Technical Analysis The rollback procedure invokes `git reset --hard`, which discards tracked working-tree and index changes. The subsequent instruction to remove untracked files can also delete data that Git does not preserve. Creating a backup branch only retains committed objects reachable from the selected revision. It does not preserve uncommitted tracked changes, staged changes that have not been committed, or untracked files. The procedure also lacks validation that the selected commit belongs to the intended repository or corresponds unambiguously to the requested cycle. No clean-tree check, complete backup, dry-run diff, protected-branch policy, or separate confirmation for deletion is required. As a result, a mistaken, ambiguous, or manipulated cycle lookup can cause irreversible workspace loss. ### Attack Path 1. A user requests rollback to a cycle identifier. 2. The skill searches Git history for a matching cycle entry. 3. An incorrect, ambiguous, or manipulated match supplies an unintended commit hash. 4. A backup branch is created, but uncommitted and untracked files are not captured. 5. `git reset --hard` discards tracked local modifications and staged changes. 6. The cleanup step removes untracked files. 7. Data absent from committed Git history cannot be recovered from the backup branch. ### Impact Assessment The opera ...[truncated 480 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
compressor.js:4
Finding

Unrestricted Cross-Package Access to Shared Agent Knowledge

Content
View full analysis
f.endsWith('.md')); files.forEach(file => { const content = fs.readFileSync(path.join(KNOWLEDGE_DIR, file), 'utf8'); // Extract @TAG patterns const regex = /@([A-Z0-9_-]+)(?:\s*[:(]|\s+)(.+)/g; let match; while ((match = regex.exec(content)) !== null) { const key = match[1]; const val = match[2].trim().substring(0, 100); // Limit length tags[key] = val; } }); // Inject File Map tags['_FILES'] = files.reduce((acc, f) => { acc[f.replace('.md', '').toUpperCase()] = f; return acc; }, {}); fs.writeFileSync(OUTPUT_FILE, JSON.stringify(tags, null, 0)); ``` ### Technical Analysis The script resolves a directory two levels above the package and reads every file ending in `.md` from that shared knowledge location. It does not restrict processing to an explicit file allowlist or verify that each directory entry resolves to an authorized regular file. The script aggregates matching knowledge content and source filenames into `TAGS.min.json`, then overwrites that shared file directly. There are no canonical-path containment checks, symlink checks, output ownership checks, backup controls, or atomic-write protections. Although the reviewed code does not transmit the resulting data over a network, it unnecessarily broadens the skill's read and write scope beyond its own package. If the output is consumed or distributed by another component, extracted sens ...[truncated 1210 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The documented use of git reset --hard <hash> is a destructive repository operation that can be abused or mistakenly triggered to wipe local changes and force a repository state change. In the context of an agent skill that advertises autonomous rollback and restart behavior, this is more dangerous because users may treat it as a routine feature and overlook the severity of the operation.

Content

Scanner excerpt · README.md (reported line 52)May include surrounding context.

md
- **Effect**: 
  1.  Checks `memory/EVOLUTION_INDEX.md` for Cycle 50's Commit Hash.
  2.  Creates backup branch `backup/abandoned-future-...`.
  3.  Executes `git reset --hard <hash>`.
  4.  Agent restarts with Cycle 50's brain.

## 📦 Installation

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The rollback section describes destructive repository operations that can discard local work, logs, and untracked files, but it does not prominently warn about irreversible data loss or require confirmation. In an agent skill, this is especially dangerous because an autonomous or semi-autonomous agent may interpret rollback as routine recovery and execute it without the user's informed consent.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

git reset --hard <commit_hash> is a destructive command that forcibly rewrites the working tree and index, potentially erasing uncommitted changes. In this skill's context, the command is presented as part of a normal 'Time Travel' workflow, making it more dangerous because an agent could execute it as a standard remediation step without validating repository state, user intent, or recovery options.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
**Steps**:
1.  **Find Commit**: grep git log for "Cycle #<ID>".
2.  **Backup**: `git branch backup/cycle_<current>_<timestamp>`
3.  **Reset**: `git reset --hard <commit_hash>`
4.  **Clean**: Remove untracked files if necessary.

## 6. EvoSeed Extraction (Soul Kernel)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README promotes exporting an agent's memory, history, taste, and knowledge into evo-seed.zip without warning that these artifacts may contain secrets, personal data, proprietary context, or sensitive internal state. Users may unintentionally package and transfer confidential material because the feature is framed as a convenience rather than a sensitive export operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs a rollback flow that performs git reset --hard <hash>, which can irreversibly discard uncommitted local changes. Although a backup branch is mentioned, the documentation does not clearly warn users about data loss, scope of reset, or required safeguards before executing the command.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger examples are generic enough that an agent could invoke this skill in situations far beyond the author's likely intent, including sensitive repositories or high-risk maintenance tasks. Because the skill includes spawning workers, rollback behavior, and packaging internal state, broad activation increases the chance that dangerous actions are taken without explicit, contextual user approval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly directs stopping a process, mutating knowledge files, restoring snapshots with a recursive copy, and blocking other tools, but provides no safety interlocks, confirmation prompts, scope restrictions, or warning about data loss and service interruption. In an agent skill context, these are operationally dangerous because they normalize destructive state changes that could overwrite workspace contents, corrupt agent behavior, or disrupt other tasks if triggered accidentally or by a malicious actor.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The document presents core headings and feature labels bilingually, which effectively imposes a mixed-language presentation without stating whether users can choose their preferred language. Under the policy, language or locale constraints should be optional or clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The package description is written entirely in Chinese and presents the skill identity and behavior in a single language, with no indication of language choice or opt-in. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The natural-language directive mandates 'Output ONLY strict JSON' and 'No conversational fluff,' which constrains communication format regardless of user preference. Under the policy criteria, forced language or locale behavior without opt-in can qualify as a natural-language policy issue when it removes user choice.

Content

No source excerpt is available for this finding.