Back to skill

Security audit

Skill Vet

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to help vet other skills, but its own scanner can give misleading safe results in documented workflows.

Review this carefully before relying on it as an installation gate. It does not show malicious behavior, but its scanning results can be incomplete or attached to the wrong path, and its success status can mean warnings were found. Use only with manual review of the exact target path and do not treat exit code 0 as proof a skill is safe.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
vetting.cjs:142
Finding

Documented subcommands are incorrectly interpreted as scan targets

Content
View full analysis
!a.startsWith('-')) || '.'; // Resolve relative path if (!path.isAbsolute(targetPath)) { targetPath = path.resolve(process.cwd(), targetPath); } ``` The documented interface is: ```bash skill-vet scan /path/to/skill skill-vet scan /path/to/skill --verbose skill-vet check /path/to/skill ``` ### Technical Analysis The parser selects the first argument that does not begin with a hyphen and treats it as the target path. Under the documented interface, that argument is the `scan` or `check` subcommand rather than `/path/to/skill`. Consequently: - `skill-vet scan /path/to/skill` resolves `scan` relative to the current directory. - `skill-vet check /path/to/skill` resolves `check` relative to the current directory. - The intended target path is ignored. - If no corresponding local path exists, the program terminates with a path-not-found error. - If a local file or directory named `scan` or `check` exists, the scanner analyzes that object instead of the requested Skill. Because this tool is intended to act as a security gate before installation or execution, scanning the wrong target undermines the validity of its result. ### Attack Path 1. An attacker distributes a malicious Skill and instructs the user to vet it using the documented command: `skill-vet scan /path/to/malicious-skill`. 2. The command is run from a directory containing a benign file or directory named `scan`. 3. The argument parser selects `scan` as the target and ignores `/path/to/malicious-skill`. 4. The benign local object is scanned. 5. The user may incorrectly associate t ...[truncated 562 chars]
Remediation
View remediation
[--verbose]'); process.exit(2); } const positional = args.slice(1).filter(arg => !arg.startsWith('-')); if (positional.length !== 1) { console.error('Exactly one target path is required.'); process.exit(2); } let targetPath = positional[0]; ``` Additionally: 1. Reject unknown subcommands and unexpected positional arguments. 2. Keep options and positional arguments distinct. 3. Add automated tests for `scan`, `check`, relative paths, absolute paths, missing paths, and extra arguments. 4. Print the canonical target path before scanning and require downstream automation to associate results with that path. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
vetting.cjs:49
Finding

Unsupported and unreadable files are silently counted as scanned

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
vetting.cjs:211
Finding

Medium-risk findings return success and bypass the documented installation gate

Content
View full analysis
0) { console.log(`${colors.yellow}⚠️ Scan complete: Medium risk issues found. Caution advised.${colors.reset}`); process.exit(0); } else { ``` The documented integration treats any successful status as safe: ```bash skill-vet scan ./skills/new-skill && echo "Safe to install" ``` Medium-risk patterns include subprocess use, filesystem writes and deletion, network indicators, delayed execution, and HTTP clients: ```javascript medium: [ { pattern: /fs\.writeFile/g, desc: 'File write operation' }, { pattern: /fs\.unlink/g, desc: 'File deletion' }, { pattern: /fs\.rmdir/g, desc: 'Directory removal' }, { pattern: /https?:\/\//g, desc: 'Network request' }, { pattern: /child_process/g, desc: 'Subprocess spawning' }, { pattern: /setTimeout|setInterval/g, desc: 'Delayed execution' }, { pattern: /fetch\s*\(/g, desc: 'HTTP fetch' }, { pattern: /axios/g, desc: 'HTTP client' }, ], ``` ### Technical Analysis Exit status zero conventionally indicates successful validation. The scanner uses that status even when potentially dangerous operations are detected. This conflicts with the documented shell integration, where the `&&` operator runs the next command whenever the scanner returns zero. As a result, the exact workflow recommended by the project prints “Safe to install” for a Skill containing one or more medium-risk indicators. These indicators cover capabilities relevant to data exfiltration, subprocess execution, destructive filesystem changes, and delayed activity. The weakness is not that every medium finding is necessarily malicious; it is that an unresolved finding is converte ...[truncated 1082 chars]
Remediation
View remediation
0 || (failOn === 'medium' && medium.length > 0)) { process.exit(1); } process.exit(0); ``` Recommended controls: 1. Make pre-installation mode fail on medium or high findings by default. 2. Reserve exit status `0` for scans that satisfy the selected policy. 3. Use a distinct nonzero status for findings and another for operational errors. 4. Require an explicit override, such as `--allow-medium`, when users accept medium findings. 5. Replace the documented “Safe to install” message with policy-aware wording. 6. Provide machine-readable output containing the target path, maximum severity, coverage failures, and policy decision. 7. Add integration tests verifying that medium findings prevent execution of commands chained with `&&` under the default pre-installation policy. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Tp2

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The file presents most instructions and descriptions in Chinese while the main title is in English, but it does not state a supported language policy or offer users a choice of language. This can violate a language/locale policy when users are implicitly forced into one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code hard-codes ANSI color escape sequences for all user-facing output. While not a language issue, it does force a specific output format without checking terminal capabilities or offering an alternative, which can conflict with organizational expectations for adaptable user-facing presentation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
vetting.cjs:69

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
vetting.cjs:14