Back to skill

Security audit

SkillCompass — Skill Evolution Engine

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated purpose, but it needs review because some security-scan paths can run mutable third-party code and some command templates can execute crafted local paths unsafely.

Install only if you are comfortable with persistent hooks, local skill usage tracking, local snapshots, and optional agent status-line configuration. Avoid using the external security-tool path until the scanner version is pinned and explicitly confirmed, and do not evaluate skills from paths containing quotes or other crafted characters until the node -e templates are fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
shared/tool-instructions.md:23
Finding

Automatic Execution of an Unpinned Remote Security Scanner

Content
View full analysis
Remediation
View remediation
scan --skill ``` Use the exact syntax supported by the selected package ecosystem. 2. Where supported, verify the downloaded artifact using a cryptographic hash, lockfile, signed provenance, or trusted publisher signature. 3. Require explicit user confirmation before the first network retrieval or execution: - Display the package name, exact version, registry, and data supplied to it. - Explain that the command may access the network and execute third-party code. - Allow the user to continue with built-in local checks only. 4. Prefer a previously installed and explicitly trusted executable instead of resolving a package dynamically during an audit. 5. Run third-party scanners with reduced privileges: - Restrict filesystem access to the selected Skill. - Pass only required environment variables. - Apply network restrictions where practical. - Avoid forwarding the Agent's complete environment. 6. Update `SECURITY.md` and the declared trust model to disclose optional network calls and third-party execution accurately. 7. Record the exact scanner version in evaluation output so results are reproducible and auditable. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
commands/eval-skill.md:45
Finding

Code Injection Through Unescaped Skill Paths in node -e Commands

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (112)

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SECURITY.md (reported line 3)May include surrounding context.

md
# Security & Trust Model

SkillCompass is a **local skill evaluation tool**. Like antivirus software that must read files to scan them, SkillCompass must read, analyze, and in explicit opt-in flows sometimes modify skill files to evaluate and improve their quality. The behaviors described below are intentional product features with built-in safeguards.

## Reporting a Vulnerability

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the skill can inspect git remotes, perform fetch/pull, and update local repositories, that materially expands capability into network access and code modification beyond a simple evaluator. Such behavior is dangerous because it can change installed code and contact external systems, and the manifest does not clearly surface those powers.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger text includes very broad user-intent phrases like setup, inbox, suggestions, and improvement, which overlap common conversation. Overly generic activation can cause the skill to run unexpectedly, exposing local scanning, persistence, or config-touching behaviors in contexts where the user did not ask for them.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Several aliases are extremely generic, especially setup and inbox, making accidental invocation likely. Because this skill can auto-scan skills, write local state, and potentially modify user configuration, accidental activation raises the risk of unintended side effects.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
95% confidence
Finding

Accessing ~/.claude/settings.json reaches into a sensitive agent configuration directory outside the skill's own sidecar area. Even read access is sensitive because it reveals user configuration, and subsequent logic may steer the user toward modifying the file.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

Step 3: StatusLine Configuration

Check if ~/.claude/settings.json already has a statusLine configured.

If NO existing statusLine:

text

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

Writing to ~/.claude/settings.json changes global agent behavior and persists across sessions, which is a high-sensitivity action. Misconfiguration could break the agent UX, install unwanted status-line behavior, or create a foothold for broader prompt/control influence.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

[极简模式 — 仅 🧭 提示 / 完整 HUD — 含模型、上下文等信息]

text

- **极简模式**: Write statusLine config to `~/.claude/settings.json` pointing to `scripts/hud-extra.js`
- **完整 HUD**: Check for claude-hud, configure `--extra-cmd`, or fall back to 极简
- **跳过**: Do nothing

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · commands/eval-audit.md (reported line 21)May include surrounding context.

md
### Step 1: Discover Skills

Use the **Glob** tool to find all `**/SKILL.md` files recursively under the specified directory. Also check `~/.claude/skills/` if scanning project-level.

Exclude: `test-fixtures/`, `node_modules/`, `archive/`, `.git/`, `.skill-compass/`.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
92% confidence
Finding

The command embeds or requests direct Node.js execution to write audit logs, which introduces unnecessary code-execution capability into a markdown-defined skill workflow. If variables such as skillName, currentVersion, or targetVersion are not strictly controlled, this pattern can enable unsafe execution paths or filesystem effects beyond the intended rollback operation.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
98% confidence
Finding

The skill explicitly targets ~/.claude/settings.json in the user's agent config directory. Access to agent configuration is sensitive because modifications can persistently alter agent behavior, command execution, or displayed status across future sessions.

Content

Scanner excerpt · commands/setup.md (reported line 223)May include surrounding context.

md
**StatusLine integration (first run only):**

After smart guidance, check if `~/.claude/settings.json` already has a `statusLine` configured.

If NO existing statusLine:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
99% confidence
Finding

The instruction to use Bash to write ~/.claude/settings.json creates a direct persistent modification path into the agent's config. Because this is a privileged location affecting future agent behavior, any mistake or abuse here has outsized integrity impact compared with ordinary local output files.

Content

Scanner excerpt · commands/setup.md (reported line 247)May include surrounding context.

[极简模式 / 完整 HUD / 跳过]

text

- **极简模式**: Use the **Bash** tool to write to `~/.claude/settings.json`, adding the `statusLine` field:
  ```json
  {
    "statusLine": {

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.potential_exfiltration

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
lib/update-checker.js:67

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
lib/update-checker.js:164

File read combined with network send (possible exfiltration).

Warn
Code
suspicious.potential_exfiltration
Location
lib/update-checker.js:202