Back to skill

Security audit

Skill Creator

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate skill-building assistant, but it has broad authority around creating, editing, testing, and packaging skills that deserves user review before installation.

Install only if you are comfortable with a skill that can guide an agent to create and edit skills, run local helper scripts, spawn evaluation agents, and package distributable .skill files. Before sharing any generated package, inspect the archive contents, keep secrets and private data out of skill folders, avoid symlinks inside skill directories, and make sure any local review server is stopped after use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init_skill.py:181
Finding

Unvalidated Skill Name Allows Output-Directory Escape

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/package_skill.py:72
Finding

Symbolic-Link Dereference Can Include External Files in Skill Archives

Content
View full analysis
/path/to/sensitive/local/file ``` 3. A user or automated process runs `package_skill.py` on the crafted skill. 4. `rglob()` discovers the symbolic link, and `is_file()` accepts it because its target is a regular file. 5. `zipf.write()` dereferences the link and embeds the external file's contents in the `.skill` archive. 6. The archive is presented ...[truncated 811 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill includes packaging and archive-generation behavior that is not clearly reflected in the high-level description. Hidden or under-disclosed file/archive creation capabilities can surprise users, increase the chance of unsafe execution, and make reviewers underestimate the skill's ability to generate distributable artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes packaging and archive-generation behavior that is not clearly reflected in the high-level description. Hidden or under-disclosed file/archive creation capabilities can surprise users, increase the chance of unsafe execution, and make reviewers underestimate the skill's ability to generate distributable artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill includes packaging and archive-generation behavior that is not clearly reflected in the high-level description. Hidden or under-disclosed file/archive creation capabilities can surprise users, increase the chance of unsafe execution, and make reviewers underestimate the skill's ability to generate distributable artifacts.

Content

No source excerpt is available for this finding.

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly tells the author to make generated skill descriptions 'pushy' and to trigger even when the user does not explicitly ask for that skill. This promotes overbroad auto-invocation, which can cause unrelated or more powerful skills to activate inappropriately, expanding access to tools, files, or workflows beyond user intent.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · scripts/init_skill.py (reported line 266)May include surrounding context.

python
# Print next steps
    print(f"\n✅ Skill '{skill_name}' initialized successfully at {skill_dir}")
    print("\nNext steps:")
    print("1. Edit SKILL.md to complete the TODO items and update the description")
    print("2. Customize or delete the example files in scripts/, references/, and assets/")
    print("3. Run the validator when ready to check the skill structure")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to read and write files, invoke shell commands, launch scripts, and optionally use network-adjacent tooling, but it declares no explicit tool scope or allowed-tools constraints. That creates an over-privileged skill surface where downstream agents may execute powerful operations without a clear least-privilege boundary or user-visible restriction.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

Using nohup to launch the review server creates a background process that persists beyond the immediate interaction and may continue serving local content or consuming resources after the task ends. Persistent processes reduce auditability and can expose review artifacts or stale services if not reliably cleaned up.

Content

Scanner excerpt · SKILL.md (reported line 239)May include surrounding context.

  1. Launch the viewer with both qualitative outputs and quantitative data:
    bash
    nohup python <skill-creator-path>/eval-viewer/generate_review.py \
      <workspace>/iteration-N \
      --skill-name "my-skill" \
      --benchmark <workspace>/iteration-N/benchmark.json \
    

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The packager recursively includes every file under the skill directory, which can unintentionally bundle secrets, local test data, editor metadata, private notes, or other non-distribution artifacts into the resulting .skill archive. Because this tool is specifically for creating distributable packages, overbroad inclusion creates a realistic information disclosure risk if skill folders contain sensitive files that were never meant to be shipped.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.