Back to skill

Security audit

consensus-persona-generator

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently generates local consensus persona artifacts and does not show hidden network access, credential use, privilege escalation, or destructive behavior.

Install only if you are comfortable with it writing consensus state artifacts under the configured state path. Set CONSENSUS_STATE_FILE or CONSENSUS_STATE_ROOT to a dedicated non-sensitive directory, and consider pinning/upgrading dependencies before production use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
92% confidence
Finding

The lockfile includes fast-uri 3.1.0, which has multiple advisories involving URI parsing inconsistencies such as host confusion and malformed authority handling that can enable SSRF or security-filter bypasses. In this skill context, the risk is moderated because the vulnerable package is transitive through ajv and a lockfile entry does not by itself show attacker-controlled URL validation, but consensus-related tooling may process untrusted structured input, making parser confusion more meaningful than in a purely local-only utility.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.3 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
84% confidence
Finding

The lockfile pins esbuild 0.27.3, which is reported vulnerable to arbitrary file read when using esbuild's development server on Windows. This is a real supply-chain risk, but the impact here is limited because a package-lock entry alone does not prove the skill runs esbuild's dev server, and esbuild appears to be present as a build/runtime tooling dependency via tsx rather than as exposed application functionality.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"demo": "node --import tsx run.js --input ./examples/persona-input.json"
  },
  "dependencies": {
    "consensus-guard-core": "^1.1.15",
    "tsx": "^4.20.3"
  },
  "license": "MIT",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
},
  "dependencies": {
    "consensus-guard-core": "^1.1.15",
    "tsx": "^4.20.3"
  },
  "license": "MIT",
  "engines": {

Static analysis

No suspicious patterns detected.