Back to skill

Security audit

Autoresearch.Bak

Security checks for vulnerabilities and agentic risk

Overview

This skill is clearly for autonomous experiments, but it can run indefinitely and repeatedly use destructive Git resets, so it needs careful review before installation.

Install only if you are comfortable with an agent editing code, running configured shell commands, creating commits, and continuing until stopped. Use it in a disposable branch or worktree with a clean working tree, set explicit experiment limits, and avoid letting it run where unrelated uncommitted work could be lost.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:218
Finding

Unbounded Autonomous Execution Overrides User Oversight

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:153
Finding

Destructive Git Rollback Can Erase Unrelated Uncommitted Work

Content
View full analysis
(: vs best )" ELIF crashed or timed out: → CRASH: git reset --hard HEAD~1 → Log: "CRASH: (error: )" ``` ### Technical Analysis `git reset --hard HEAD~1` moves the branch to the previous commit and forcibly resets tracked files in both the index and working tree. It is not limited to the configured experiment target files. The setup procedure does not require checking that the repository is clean before starting. It also does not require preserving pre-existing changes in a separate worktree, patch, branch, or user-approved stash. As a result, unrelated tracked changes that remain uncommitted when rollback occurs can be irreversibly discarded. The problem is amplified because failed or non-improving experiments automatically trigger the command. A normal benchmark failure can therefore activate a destructive repository-wide operation without an additional confirmation step. ### Attack Path 1. The user invokes the Skill in a repository containing unrelated, uncommitted tracked changes. 2. The agent modifies the declared target files and commits the experiment. 3. Other tracked changes remain present in the working tree or are created while the experiment runs. 4. The benchmark crashes, times out, or returns a non-improving metric. 5. The Skill executes `git reset --hard HEAD~1`. 6. Git resets tracked files across the worktree, ...[truncated 720 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Using git reset --hard HEAD~1 is a dangerous tool invocation because it forcefully rewinds history and overwrites the working tree. In this skill's context, an autonomous agent may execute it repeatedly inside an indefinite experiment loop, amplifying the chance of irreversible loss of unrelated edits, branch corruption, or rollback beyond intended scope if repository state assumptions are wrong.

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

If the run crashed or timed out:

- Read the error from run.log

- Record as crash in results.tsv

- Revert: git reset --hard HEAD~1

- Diagnose and try a different approach

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The decision logic automates git reset --hard HEAD~1 whenever a metric is equal or worse, making a destructive operation part of the normal control flow rather than an exceptional recovery step. Because the loop is designed to continue indefinitely and the skill can modify multiple target files, a mistaken metric extraction, wrong baseline, or dirty worktree can repeatedly destroy valid user changes.

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
→ Log: "KEEP: <description> (<metric>: <old> → <new>)"

ELIF metric equal or worse:
    → DISCARD: git reset --hard HEAD~1
    → Log: "DISCARD: <description> (<metric>: <value> vs best <best>)"

ELIF crashed or timed out:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Automating git reset --hard HEAD~1 on crashes/timeouts is dangerous because failure conditions are often noisy and can be triggered by unrelated environment problems. In this context, the agent may misattribute a crash, execute the hard reset anyway, and erase useful debugging changes or unrelated local work while continuing the loop, compounding operational damage.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

→ Log: "DISCARD: (: vs best )"

ELIF crashed or timed out: → CRASH: git reset --hard HEAD~1 → Log: "CRASH: (error: )"

text

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase list includes the very broad term "optimize," which can cause this skill to activate for many unrelated requests. Because the skill is authorized to write files, execute shell commands, spawn sessions, and mutate git state, accidental invocation can lead to unintended autonomous code changes and command execution in contexts where the user did not clearly consent to that level of action.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill begins autonomous experimentation with powerful tools but does not prominently warn that it will execute shell commands, modify source files, create branches, and run repeated experiments. That omission increases the chance that users or orchestrators invoke it without understanding the operational and safety consequences, which is especially risky given the indefinite loop and code-modifying behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The workflow instructs the agent to use git reset --hard HEAD~1 to discard experiments, but the skill does not prominently warn that this is destructive and irreversibly discards uncommitted working-tree changes. In a real repository, accidental or mis-scoped execution could wipe unrelated user work, not just the experimental change, causing significant data loss.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.