Back to skill

Security audit

consensus-support-reply-guard

Security checks for vulnerabilities and agentic risk

Overview

This is a local support-reply safety guard with disclosed audit-file writes; the risky SSN example is a test case, but its dependency hygiene should be reviewed before production use.

This skill appears appropriate for reviewing support drafts and recording decisions locally. Before installing it in a production support workflow, review and pin its npm dependencies, update the scanner-flagged transitive packages, and make sure the configured consensus state path is acceptable for storing support draft text and audit records.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The draft reply explicitly asks the customer to share an SSN and pairs that request with a misleading assurance of 'legal certainty,' directly conflicting with the declared no-sensitive-data and no-legal-claims constraints. In a support automation context, this could cause improper collection of highly sensitive personal data, create compliance and privacy exposure, and generate unauthorized legal representations to customers.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: fast-uri==3.1.0 — 7 advisory(ies): CVE-2026-13676 (fast-uri vulnerable to host confusion via failed IDN canonicalization); CVE-2026-18446 (fast-uri vulnerable to host confusion via backslash authority introducer); CVE-2026-75975 (fast-uri vulnerable to server-side request forgery via malformed IPv6 normalizat) +4 more

High
Category
Supply Chain
Confidence
95% confidence
Finding

The lockfile includes fast-uri 3.1.0 through ajv, and the cited advisories indicate host parsing/canonicalization flaws that can enable SSRF or host-confusion bypasses when attacker-controlled URLs are validated or normalized with this library. Given this skill's purpose is risk-aware governance around customer-facing automation, any URL-validation ambiguity in upstream components could weaken trust boundaries if untrusted inputs are processed and security decisions rely on URI parsing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: esbuild==0.27.3 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency uses a caret range (^1.1.15), which permits automatic installation of newer compatible versions. This creates supply-chain risk because a compromised or defective upstream release could be pulled into builds without explicit review, which is relevant for a security-sensitive support-governance skill.

Content

Scanner excerpt · package.json (reported line 10)May include surrounding context.

json
"demo": "node --import tsx run.js --input ./examples/input.json"
  },
  "dependencies": {
    "consensus-guard-core": "^1.1.15",
    "tsx": "^4.20.3"
  },
  "license": "MIT",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The tsx package is also specified with a caret range (^4.20.3), allowing newer versions to be resolved implicitly. Even though it appears primarily used for test/demo execution, unpinned tooling can still introduce supply-chain exposure or unexpected behavior in development and CI environments.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
},
  "dependencies": {
    "consensus-guard-core": "^1.1.15",
    "tsx": "^4.20.3"
  },
  "license": "MIT",
  "engines": {

Static analysis

No suspicious patterns detected.