Back to skill

Security audit

agent-skills-setup

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed offline migration tool for AI-agent settings, with sensitive local file access that fits its purpose and one optional signing-key hardening issue.

Install only if you want an offline tool that can read and migrate AI-agent skills, rules, and MCP settings. Review generated plans before using --yes, prefer plan-only/dry-run first, and avoid using bundle-keygen on shared systems until its private-key creation is hardened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/context-migrator.py:1045
Finding

Private Signing Key Created Before Secure Permissions Are Enforced

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (120)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a broad context migration and backup system across multiple AI coding tools, with safety and validation features. The supplied code chunk, however, is only a module docstring describing a lightweight detection probe framework that checks local product/profile installation state. Detection may be a supporting component of a migration tool, but in isolation this chunk does not implement or demonstrate the declared primary capabilities. Therefore the description materially overstates what this code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description promises a context migration and management capability across AI coding agents, including sophisticated operations like backup/restore, secret redaction, preview, verification, and rollback. In contrast, this code chunk is a detector module whose purpose is to identify whether certain products/profiles are installed or configured on the local machine. It inspects local binaries, files, directories, home/workspace paths, and macOS app bundles, and may invoke local commands like version checks and mdfind. While such detection could be a supporting component of a migration tool, this chunk by itself does not implement the declared core functionality and instead exposes an undeclared capability: environment/product detection. Therefore the supplied code does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a high-level migration and backup tool for AI-coding-agent context across products. The supplied code does not perform any migration, backup, restore, comparison, movement of context, secret handling, or rollback. Instead, it is a narrow internal utility for resolving registry selector aliases and default profiles. This is a materially different primary purpose, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

There is a clear description-behavior mismatch based on the provided code chunk. The declaration describes a broad tool for migrating and managing AI-agent context across multiple products, with redaction and rollback features. The actual code shown does not implement those workflows; it only exposes a CLI entry point for a secret scanner. While secret scanning could support redaction in a larger system, this chunk's observable behavior is materially narrower and different from the declared primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad context portability tool for multiple AI agent environments, including migration, backup, restore, comparison, redaction, verification, and rollback. The supplied code does none of that. Instead, it inspects files in a single directory tree for likely hardcoded secrets, private keys, connection-string credentials, and symlinks that are absolute or escape the root. While secret redaction/safety is mentioned in the description, this code only detects and rejects potential secrets; it does not migrate or manage context artifacts. Therefore the actual behavior is materially narrower and different in primary purpose from the declared description.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.json (reported line 3)May include surrounding context.

json
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.json (reported line 6)May include surrounding context.

json
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.tsv (reported line 10)May include surrounding context.

text
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.tsv (reported line 13)May include surrounding context.

text
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ides/antigravity.md (reported line 7)May include surrounding context.

md
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ides/antigravity.md (reported line 10)May include surrounding context.

md
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ides/antigravity.md (reported line 24)May include surrounding context.

md
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/ide-paths.tsv (reported line 23)May include surrounding context.

text
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/ide-paths.tsv (reported line 26)May include surrounding context.

text
{
  "antigravity": {
    "global_skills": "~/.gemini/config/skills",
    "project_skills": ".agents/skills",
    "rules": ".agents/rules",
    "mcp": "~/.gemini/config/mcp_config.json",

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.json (reported line 17)May include surrounding context.

json
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |

<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.tsv (reported line 33)May include surrounding context.

text
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |

<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ides/claude.md (reported line 13)May include surrounding context.

md
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |

<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/ide-paths.tsv (reported line 57)May include surrounding context.

text
| MCP | `~/.claude.json` |
| Project MCP | `.mcp.json` |
| Project config | `.claude/settings.json` |
| Config | `~/.claude/settings.json` |

<!-- END GENERATED: ide-paths.json summary -->
- Settings include project `.claude/settings.json` and local `.claude/settings.local.json`; local scopes are manual.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.json (reported line 32)May include surrounding context.

json
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.json (reported line 35)May include surrounding context.

json
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.tsv (reported line 50)May include surrounding context.

text
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ide-paths.tsv (reported line 53)May include surrounding context.

text
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ides/codex.md (reported line 10)May include surrounding context.

md
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/ides/codex.md (reported line 13)May include surrounding context.

md
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/registry-v2.json (reported line 847)May include surrounding context.

json
| Global skills | `~/.agents/skills` |
| Project skills | `.agents/skills` |
| Rules | `AGENTS.md` |
| MCP | `~/.codex/config.toml` |
| Project MCP | `.codex/config.toml` |
| Project config | `.codex/config.toml` |
| Config | `~/.codex/config.toml` |

Static analysis

No suspicious patterns detected.