Back to skill

Security audit

debug-mode

Security checks for vulnerabilities and agentic risk

Overview

This skill gives an agent a structured debugging workflow with temporary probes and cleanup, and its higher-risk actions are disclosed and tied to debugging.

Install this if you want evidence-first debugging assistance. Before using Autopilot, make sure the project commands and tests are safe for the current environment, and review any temporary probe logs for sensitive data before sharing them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly directs the agent to add runtime probes and write their output to a repository-local log file. Even though it later says not to put secrets in probe output, debug instrumentation commonly captures request data, environment-derived values, stack traces, or user content, so this creates a realistic risk of sensitive data exposure and unintended workspace modification.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
82% confidence
Finding

The Autopilot section authorizes the agent to independently run commands, tests, inspect logs, and treat passing machine checks as sufficient completion for machine-only bugs. That increases autonomy in a way that can trigger unintended side effects, especially in projects where tests or debug commands mutate state, contact external services, or operate on production-like resources.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
If the user picks `Autopilot`, verify machine-checkable behavior yourself: commands, tests, APIs, logs, CLI/TUI output, and generated files.
Check output assertions, not only exit codes.
Do not ask the user to run a command you can run.
For a machine-only bug, do not add a verification checkpoint. Passing machine checks complete the run.

Ask the user again only for visual, click, touch, or aesthetic judgment.

Static analysis

No suspicious patterns detected.