Back to skill

Security audit

Proof of Work

Security checks for vulnerabilities and agentic risk

Overview

The skill has a plausible verification purpose, but its documentation and scripts include unsafe installation guidance and under-scoped optional monitoring and AI checks.

Review carefully before installing. Prefer the local install command from SKILL.md after inspecting the scripts, do not use the README curl-to-bash installer, do not schedule watch directly in cron, and avoid --ai-check on sensitive files unless you are comfortable sending file excerpts to the configured Ollama environment. Do not rely on this as a strict completion gate until the placeholder and AI verdict handling bugs are fixed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
README.md:29
Finding

Unverified Remote Installer Is Piped Directly into Bash

Content
View full analysis
Remediation
View remediation
install.sh" | sha256sum --check - less install.sh bash install.sh ``` 6. Avoid placeholder installation domains in production documentation. 7. Document that the installer should not be run as root unless elevated privileges are explicitly required and justified. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
proof-of-work.sh:621
Finding

Cron Instructions Repeatedly Launch a Nonterminating Watch Process

Content
View full analysis
/dev/null 2>&1; then log "[$(date '+%Y-%m-%d %H:%M:%S')] $(basename "$file"): PASS" else log "[$(date '+%Y-%m-%d %H:%M:%S')] $(basename "$file"): FAIL" fi done < <(find "$path" -type f -newer "$POW_DIR/.watch_marker" -print0 2>/dev/null) done touch "$POW_DIR/.watch_marker" sleep 60 done } ``` The installer recommends scheduling that nonterminating command every hour: ```bash echo "3. Set up cron monitoring (optional):" echo " ${BLUE}crontab -e${NC}" echo " Add: ${BLUE}0 * * * * $POW_DIR/proof-of-work.sh watch${NC}" ``` The README similarly recommends repeated launches: ```bash 0 * * * * ~/.proof-of-work/proof-of-work.sh watch >> ~/.proof-of-work/cron.log 2>&1 ``` ```bash */30 * * * * ~/.proof-of-work/proof-of-work.sh watch >> ~/.proof-of-work/cron.log 2>&1 ``` ```bash */15 * * * * ~/.proof-of-work/proof-of-work.sh watch | gr ...[truncated 1969 chars]
Remediation
View remediation
> ~/.proof-of-work/cron.log 2>&1 ``` 3. If continuous monitoring is required, provide a properly managed user service rather than repeatedly invoking an infinite loop. 4. Enforce single-instance execution with a portable lock or `flock` where available. 5. Add signal handlers so the watcher exits cleanly on `SIGTERM` and `SIGINT`. 6. Document installation, status checking, log rotation, and complete removal of any service or scheduled task. 7. Add automated tests confirming that repeated scheduler invocations cannot create overlapping watcher processes. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
proof-of-work.sh:231
Finding

Detected Placeholder Content Does Not Fail Verification

Content
View full analysis
/dev/null; then warning "File contains placeholder text: $pattern" found_any=1 fi done if [ "$found_any" -eq 0 ]; then success "No placeholder text found" return 0 fi return 0 } ``` The caller also does not propagate a placeholder failure: ```bash local patterns patterns=$(get_config_array "$CONFIG_FILE" "placeholder_patterns") if [ -n "$patterns" ]; then check_placeholder_patterns "$file_path" $patterns fi ``` ### Technical Analysis The function sets `found_any=1` when configured placeholder text such as `TODO`, `TBD`, `PLACEHOLDER`, or `FIXME` is detected. However, both execution paths end with exit status `0`. The main check command only changes its final status when its `failed` variable becomes nonzero. Because the placeholder function always succeeds and its result is not connected to `failed`, placeholder content cannot cause the overall verification to fail. This contradicts the README's claim that placeholder or incomplete text is filtered and that a file containing `TODO` receives `Status: FAIL`. It undermines the script's central role as a completion gate. ### Attack Path 1. An agent or user creates an incomplete output containing a configured placeholder marker. 2. The verif ...[truncated 806 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
proof-of-work.sh:346
Finding

AI Verdict Parser Treats INCOMPLETE as COMPLETE

Content
View full analysis
/dev/null | tr '[:upper:]' '[:lower:]') case "$response" in *complete*) success "AI quality check: Content appears complete and substantive" return 0 ;; *partial*) warning "AI quality check: Content appears partially complete" return 0 ;; *incomplete*) fail "AI quality check: Content appears incomplete or placeholder" return 1 ;; *) verbose "AI quality check inconclusive" return 0 ;; esac ``` ### Technical Analysis Shell `case` patterns are evaluated from top to bottom. The first pattern, `*complete*`, matches any response containing the substring `complete`. The word `incomplete` contains that substring, so a response of `INCOMPLETE`, after conversion to lowercase, matches the success branch. As a result, the later `*incomplete*` branch is unreachable for a normal `INCOMPLETE` response. Inconclusive or malformed responses also return success, making the optional quality gate fail open. The prompt includes content read from the file being assessed. That content can influence the local language model's response, so an untrusted deliverable may deliberately induce an `INCOMPLETE` verdict while still being accepted due to the parser flaw. ### Attack Path 1. AI checking is enabled and a local Ollama instance is available. 2. An agent submits incomplete or adversarial content. 3. Ollama returns `INC ...[truncated 704 chars]
Remediation
View remediation
/dev/null | tr '[:lower:]' '[:upper:]' | tr -d '\r' | xargs ) case "$response" in INCOMPLETE) fail "AI quality check: Content appears incomplete or placeholder" return 1 ;; PARTIAL) warning "AI quality check: Content appears partially complete" return 1 ;; COMPLETE) success "AI quality check: Content appears complete and substantive" return 0 ;; *) fail "AI quality check returned an invalid verdict" return 1 ;; esac ``` 2. Fail closed when the model response is missing, malformed, or inconclusive if the AI check is configured as a mandatory gate. 3. Propagate the AI function's nonzero status into `failed` in `cmd_check`. 4. Use a structured response format where possible and validate it before making a pass/fail decision. 5. Add tests for `COMPLETE`, `PARTIAL`, `INCOMPLETE`, empty output, multiline output, and adversarial responses containing multiple verdict words. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (9)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The installation instruction pipes a downloaded script directly into bash, which executes unreviewed remote content immediately. If the hosting endpoint, network path, or referenced script is compromised, users can be tricked into running arbitrary code on their systems with the privileges of the invoking user.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

Installation

bash
curl -L https://example.com/proof-of-work/install.sh | bash

Or manual install:

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The use of a shell pipeline into bash removes the opportunity for users or automated controls to inspect the fetched content before execution and is a classic command-chaining anti-pattern. In this context, the README is an installation guide, so readers are likely to copy-paste it verbatim, increasing the chance of arbitrary code execution if the upstream content is altered.

Content

Scanner excerpt · README.md (reported line 32)May include surrounding context.

Installation

bash
curl -L https://example.com/proof-of-work/install.sh | bash

Or manual install:

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · install.sh (reported line 103)May include surrounding context.

sh
echo ""
echo "2. Try the first check:"
if command -v proof-of-work &> /dev/null; then
    echo "   ${BLUE}proof-of-work init${NC}"
    echo "   ${BLUE}proof-of-work check ~/some-file.md${NC}"
else
    echo "   ${BLUE}$POW_DIR/proof-of-work.sh init${NC}"
    echo "   ${BLUE}$POW_DIR/proof-of-work.sh check ~/some-file.md${NC}"
fi
echo ""
echo "3. Set up cron monitoring (optional):"
echo "   ${BLUE}crontab -e${NC}"
echo "   Add: ${BLUE}0 * * * * $POW_DIR/proof-of-work.sh watch${NC}"
echo ""
echo "4. Read the documentation:"
echo "   ${BLUE}$SCRIPT_DIR/README.md${NC}"
echo ""

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README advertises AI-powered checks via Ollama/Heartbeat Kit but does not clearly disclose that file contents may be transmitted to another local or remote inference service for analysis. In a tool designed to inspect agent outputs, those files may contain sensitive data, so missing disclosure and consent language creates a real privacy and data-handling risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · install.sh (reported line 103)May include surrounding context.

sh
fi
echo ""
echo "3. Set up cron monitoring (optional):"
echo "   ${BLUE}crontab -e${NC}"
echo "   Add: ${BLUE}0 * * * * $POW_DIR/proof-of-work.sh watch${NC}"
echo ""
echo "4. Read the documentation:"

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · proof-of-work.sh (reported line 713)May include surrounding context.

sh
fi
echo ""
echo "3. Set up cron monitoring (optional):"
echo "   ${BLUE}crontab -e${NC}"
echo "   Add: ${BLUE}0 * * * * $POW_DIR/proof-of-work.sh watch${NC}"
echo ""
echo "4. Read the documentation:"

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The availability check is written as if [ ! check_ollama_available ]; then, which tests a non-empty string instead of invoking the function. In bash, that condition does not correctly gate the AI path, so the script can proceed to send file content to ollama run even when Ollama is unavailable, undermining the documented 'skip if unavailable' behavior and causing unintended execution/data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The AI quality check reads up to 2000 bytes from the target file and pipes that content into ollama run llama2 without an explicit warning or confirmation at the moment of transmission. In an agent skill context, checked files may contain secrets, internal documents, or user data, so this creates a real confidentiality risk even if Ollama is local, especially because model backends, logging, or future configuration may expose content unexpectedly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · proof-of-work.sh (reported line 664)May include surrounding context.

sh
log "=== Initializing Proof of Work ==="
    log ""

    # Create directories
    mkdir -p "$POW_DIR"
    mkdir -p "$POW_DIR/reports"
    success "Created directory: $POW_DIR"

Static analysis

No suspicious patterns detected.