Back to skill

Security audit

harness-generate-iOS

Security checks for vulnerabilities and agentic risk

Overview

This iOS harness generator is mostly coherent, but it requires persistent agent-memory changes that can affect future sessions without clear opt-in.

Install only if you are comfortable with a skill that scans the whole iOS project and writes documentation/rule files. Before use, remove or disable the post-generation memory-writing section unless you explicitly want it, and review all generated or merged files before keeping the changes.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Error
Location
SKILL.md:245
Finding

Persistent Agent Memory Poisoning Through Mandatory Harness Maintenance Rules

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 245–270
Vulnerability Type: T02: Agent Memory Poisoning
Risk Level: High

Complete Vulnerable Code Snippet:

markdown
## Post-Generation: Write Memory

After all files are generated, write or update a single memory entry to guide Claude's daily behavior when maintaining the harness. This memory teaches Claude how to **use** the harness structure, which CLAUDE.md itself cannot express.

**Memory file**: `feedback_harness_maintenance.md`

```markdown
---
name: Harness maintenance rules
description: How to maintain the harness structure when adding rules, modules, or fixing bugs — keep CLAUDE.md as an index, put details in docs/
type: feedback
---

新增规则/规范时,按 CLAUDE.md 任务路由找对应 docs/ 文件写入,不要直接改 CLAUDE.md。
新增模块时补 README 速查卡,有硬约束时补 .claude/rules/。

**Why:** CLAUDE.md 是索引入口,具体内容分散在 docs/、README、rules 中。直接往 CLAUDE.md 塞内容会破坏分层。

**How to apply:**
1. 用户让记录规则 → 查任务路由确定归属文件
2. 新建模块 → 补 README(20-40 行)+ 按需补 rule(< 15 行)
3. 改完代码 → 执行 Verification Loop

If a memory with similar content already exists (e.g. feedback_docs_harness.md), update it in-place rather than creating a duplicate. Update MEMORY.md index accordingly.

text

### Technical Analysis

The Skill mandates writing its own behavioral instructions into persistent agent memory and registering them in `MEMORY.md`. This is distinct from creating project-local harness documentation: it alters long-term agent state so that Skill-controlled instructions can influence later sessions after the original invocation has ended.

The instruction also permits updating an existing, similarly named memory in place. That behavior can overwrite or blend trusted prior guidance with Skill-supplied rules, weakening provenance, reviewability, and rollback. Persistent memory modification is not required to generate the requested iOS harness and exceeds the necessary scope of the Skill.

### Attack Path
...[truncated 1256 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the mandatory post-generation memory-writing section from SKILL.md.
  2. Keep harness-maintenance guidance in project-local, reviewable files such as CLAUDE.md, docs/, or a dedicated maintenance guide.
  3. Do not create, modify, or index persistent agent memories automatically.
  4. If persistent memory is genuinely desired, present the proposed content to the user and require explicit, informed approval before writing it.
  5. Never update an existing memory merely because its content appears similar. Require an exact target, show a diff, preserve provenance, and provide a rollback mechanism.
  6. Restrict the Skill's write scope to the selected project directory and validate every destination before modification.
  7. Add a final audit step that confirms no files outside the project-local harness were created or changed.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (14)

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
### Phase 2: Generate docs/

Generate each file per [templates.md](references/templates.md) templates. Prepend `<!-- AUTO-GENERATED, review and edit -->` to every file.

| File | Data source | Scan method |
|------|-------------|-------------|

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

| .claude/rules/xxx.md | created | 12 |

text

Prompt the user to review all files marked `<!-- AUTO-GENERATED -->`.

---

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The embedded memory content hard-codes Chinese-language behavioral instructions into persistent memory without user opt-in or locale justification. Because it is durable and prescriptive, it can alter future agent behavior in ways the user may not understand, review, or even notice, especially across unrelated tasks.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates.md (reported line 61)May include surrounding context.

Build & Compile

命令行编译(无需签名):

text
xcodebuild -workspace "{workspace}" -scheme "{scheme}" -configuration Debug -destination 'generic/platform=iOS' build 2>&1 | tail -5
```​

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates.md (reported line 63)May include surrounding context.

Build & Compile

命令行编译(无需签名):

text
xcodebuild -workspace "{workspace}" -scheme "{scheme}" -configuration Debug -destination 'generic/platform=iOS' build 2>&1 | tail -5
```​

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates.md (reported line 88)May include surrounding context.

Build & Compile

命令行编译(无需签名):

text
xcodebuild -workspace "{workspace}" -scheme "{scheme}" -configuration Debug -destination 'generic/platform=iOS' build 2>&1 | tail -5
```​

Hidden Instructions

High
Category
Prompt Injection
Confidence
60% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates.md (reported line 92)May include surrounding context.

Build & Compile

命令行编译(无需签名):

text
xcodebuild -workspace "{workspace}" -scheme "{scheme}" -configuration Debug -destination 'generic/platform=iOS' build 2>&1 | tail -5
```​

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates.md (reported line 81)May include surrounding context.

docs/ARCHITECTURE.md

markdown
<!-- AUTO-GENERATED, review and edit -->
# Architecture

## 分层结构

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/templates.md (reported line 81)May include surrounding context.

docs/ARCHITECTURE.md

markdown
<!-- AUTO-GENERATED, review and edit -->
# Architecture

## 分层结构

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Broad triggers like 'generate harness' and 'init harness' are generic enough to match ordinary user requests unintentionally. This can cause the skill to activate in the wrong context and begin scanning or modifying a repository without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill performs extensive file creation and updates, including merging with existing content, but only tells the user to review outputs after modifications are already made. That weakens informed consent and increases the risk of unwanted changes to important project documentation or rules.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s stated purpose is generating project harness files, but it also instructs the agent to create or update persistent memory outside that scope. This expands the skill’s authority beyond local scaffolding into durable behavioral modification, which can silently influence future agent actions across tasks.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Persistent memory manipulation is not necessary to generate CLAUDE.md, docs, READMEs, or rule files, so granting it here violates least privilege. An unnecessary durable side effect increases the chance of unwanted policy drift, prompt poisoning persistence, or cross-project contamination.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The title "输出文件模板" indicates the template is authored as a Chinese output format, and the document consistently prescribes Chinese section names and checklist text throughout the file. Because this markdown template does not offer an opt-in language choice or explain a region-specific requirement, it violates the policy against forcing a specific language without user choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.