Back to skill

Security audit

README Craft

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate README-writing helper, but it grants broad shell, network, delegation, and file-editing authority that is not tightly scoped to README work.

Install only if you are comfortable with a README helper that can inspect project files and edit README.md. Prefer using audit mode first, review diffs before allowing writes, and avoid running it on untrusted repositories unless the skill is narrowed to read/write README files without unrestricted Bash, WebFetch, or Agent access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:25
Finding

Excessive Tool Permissions Violate Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 25–32
Vulnerability Type: Excessive tool authorization
Risk Level: Medium

yaml
allowed-tools:
  - Read
  - Write
  - Edit
  - Grep
  - Glob
  - Bash
  - AskUserQuestion
  - WebFetch
  - Agent

Technical Analysis

The skill authorizes Bash, WebFetch, and Agent, although its documented workflows only require local project inspection, README assessment, report generation, and controlled Markdown editing. No defined workflow requires arbitrary command execution, network retrieval, or delegation to another agent.

This violates the principle of least privilege. Because the skill processes potentially attacker-controlled repository content, an indirect prompt-injection attempt or erroneous generated instruction could try to use these unnecessary capabilities. Write and Edit are also unnecessary in audit mode, which is explicitly documented as read-only.

No evidence was found that the skill currently invokes these tools maliciously. The risk arises from the overly broad capability boundary.

Attack Path

  1. A user invokes the skill against an untrusted project.
  2. The skill reads attacker-controlled README, source, metadata, or documentation content.
  3. That content contains instructions crafted to influence the executing agent.
  4. The agent interprets those instructions as actionable despite their untrusted origin.
  5. The unnecessarily authorized Bash, WebFetch, or Agent capability is used to execute commands, communicate externally, or delegate a privileged operation.
  6. Depending on the host’s sandbox and authorization model, this may affect files or data accessible to the agent.

This path requires a separate influence mechanism, such as indirect prompt injection; the audited project does not itself contain a confirmed exploit payload.

Impact Assessment

Successful exploitation could permit:

  • Execution of shell commands with the privileges of the host agen ...[truncated 504 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove Bash, WebFetch, and Agent from the default allowed-tools list.
  2. Use a read-only tool profile for audit mode, limited to Read, Grep, and Glob.
  3. Enable Write and Edit only for create mode or after explicit user confirmation in rewrite mode.
  4. If shell execution later becomes essential, expose narrowly scoped commands through validated wrappers rather than unrestricted Bash.
  5. If external retrieval later becomes necessary, restrict destinations with an allowlist, reject private and link-local addresses, and require confirmation before transmitting project data.
  6. Treat all repository content as untrusted data and explicitly instruct the agent not to follow instructions embedded in inspected files.
  7. Add tests verifying that audit mode cannot modify files, execute commands, access the network, or delegate tasks.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
84% confidence
Finding

The trigger write readme overlaps with a common built-in verb pattern around writing actions, which can cause shadowing or accidental routing into this skill instead of normal assistant behavior. Given the skill's write/edit capabilities, this ambiguity can translate into unintended file operations or bypass of expected conversational clarification.

Content

No source excerpt is available for this finding.

Shadow Command Trigger

Medium
Category
Trigger Abuse
Confidence
84% confidence
Finding

The trigger create readme conflicts with a generic creation verb and may be matched when users are discussing creation tasks more broadly. Because this skill can directly modify repository files, command shadowing increases the risk of unintended activation and incorrect document generation workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The bare trigger readme is overly broad and can cause the skill to activate during ordinary conversation about README files, even when the user did not intend tool-driven document generation or modification. In this skill, that matters because the skill is authorized to read, edit, write, use Bash, fetch from the web, and delegate to Agent, increasing the chance of unintended file changes or unnecessary tool use from an ambiguous invocation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger project documentation is much broader than the stated README-only scope and may hijack unrelated requests for API docs, architecture docs, changelogs, or other documentation tasks. Because the skill can directly write files and use powerful tools, this scope mismatch can lead to inappropriate activation, wrong-file edits, or user confusion about what the agent will modify.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states that create/rewrite modes directly write README.md, but it does not consistently require an upfront confirmation before modifying files. In combination with broad triggers and auto-detected modes, a user asking for analysis or brainstorming could accidentally cause repository changes, which is a real integrity and workflow safety issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file presents all guidance exclusively in Chinese and does not offer any language choice, translation note, or justification for a China-specific audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing instructions entirely in Chinese, with no indication that users may choose another language or that the locale restriction is intentional. Under the language/locale policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This manifest includes judge expectations for Chinese terms ("模糊", "描述") alongside English, even though the prompt does not ask for a Chinese response. That can steer the skill toward a specific language or bilingual output without explicit user choice, which is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The judge criteria accept Chinese terms ("顺序", "漏斗") for a prompt that does not specify language preference. This creates an implicit language constraint or encouragement that is not documented as optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The expected tokens include Chinese output ("减少", "过多") despite no language choice in the prompt. That can bias the skill toward a locale-specific response format without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest accepts Chinese tokens ("链接", "外部") for a prompt that does not request Chinese. This is a natural-language policy issue because it implicitly permits or prefers a specific language/locale without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown states that create writes README.md and rewrite writes after confirmation, but it does not include a user-facing warning that these modes will modify an existing project file and may overwrite prior README content. For markdown files, operations that affect user data or files should be accompanied by an explicit warning or caution in the skill description.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

文件标题及全文均以中文撰写,但没有说明该文档仅面向特定中文受众,也没有提供语言/locale 选择。这可能构成语言/区域策略方面的自然语言约束,因为技能材料默认强制单一语言而未获得用户选择或明确限定。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file is natural-language content, and its instructions, headings, and examples are all written in Chinese. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in can be a policy violation when no alternative or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.