T01 · Skill Instruction Hijacking
- Location
scanner.py:468- Finding
Unescaped Attacker-Controlled Data in Agent-Facing Markdown Report
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent local security-scanner skill, but its Markdown reports can be influenced by scanned files and its results may overstate scan completeness.
Install only if you treat this as a heuristic helper, not a definitive security gate. Run it only on directories you intentionally choose, and treat the Markdown report as untrusted evidence because scanned filenames or code strings may affect how the report appears.
scanner.py:468Unescaped Attacker-Controlled Data in Agent-Facing Markdown Report
scanner.py:181Dangerous and Network Calls Can Bypass Detection Through Import Aliases
scanner.py:355Unparseable Python Files Are Silently Reported as Clean
Referenced artifact was not completely inspected
n_skill` tool accepts a `path` argument pointing to a skill directory. It runs `scanner.py` against all `.py` files in that directory tree and returns a Markdow
The skill exposes capabilities that can read files, access the network, and invoke a shell via python3 {{SKILL_DIR}}/scanner.py "{{path}}", but the manifest does not declare any scope restrictions such as permissions or allowed-tools. This weakens least-privilege controls and makes the skill harder to sandbox or review safely, especially because the provided path is user-controlled and the scanner is described as recursively analyzing directories.
Detected: suspicious.dynamic_code_execution