Back to skill

Security audit

shodan-skill

Security checks for vulnerabilities and agentic risk

Overview

This Shodan skill is disclosed and purpose-aligned, but it can spend credits or change/delete Shodan account resources immediately after a broadly matched request.

Review this before installing if your Shodan key has paid credits, scan privileges, Enterprise access, or organization-admin rights. Prefer strict safety mode or dry-run for scans, alerts, notifiers, dataset downloads, and organization changes, and use a least-privileged Shodan key where possible.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger description is broad enough to activate on generic research, exposure, monitoring, or account-workflow requests, increasing the chance the skill is invoked when the user did not clearly intend a Shodan-backed action. In this skill, that risk is amplified because the instructions explicitly permit immediate execution of scans, monitoring, and other impactful operations without a second confirmation.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly authorizes credit-consuming, state-changing, destructive, scanning, monitoring, download, streaming, and Enterprise operations to execute immediately on an explicit request, without a user-facing warning about cost, side effects, or scope. This is dangerous because a loosely matched invocation or ambiguous request could trigger external scanning, persistent monitoring, quota consumption, or bulk data access with real operational and financial consequences.

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest explicitly exposes numerous POST, PUT, and DELETE operations that create scans, alerts, notifiers, and organization membership changes, yet the file defines no activation constraints, allowlists, confirmation gates, or scope restrictions for those mutating actions. In this skill’s context, the metadata also says to treat a user’s explicit request as authorization without a second confirmation, which makes accidental or socially engineered execution of destructive or credit-consuming Shodan actions materially more likely.

Static analysis

No suspicious patterns detected.