Back to skill

Security audit

People Strategy

Security checks for vulnerabilities and agentic risk

Overview

This is a local people-relationship database skill whose behavior is disclosed and purpose-aligned, though users should treat its stored and exported contact data as sensitive.

Install only if you are comfortable keeping relationship notes in a local SQLite file. Protect people.db and any exported graph JSON, avoid storing unnecessary sensitive personal details, keep backups before deletions, and be aware that this version may not fully enforce cascade deletion or duplicate-prevention claims.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
database.py:17
Finding

SQLite Foreign-Key Constraints Are Not Enforced

Content
View full analysis
bool: """ Delete a person from the database. Returns: True if the person was deleted, False otherwise """ self.cursor.execute("DELETE FROM people WHERE id = ?", (person_id,)) self.connection.commit() return self.cursor.rowcount > 0 ``` ### Technical Analysis SQLite disables foreign-key enforcement by default for each database connection. Declaring `FOREIGN KEY` constraints in the schema does not activate them. The connection setup never executes: ```sql PRAGMA foreign_keys = ON ``` As a result, the application can insert relationship edges referencing nonexistent people. Additionally, deleting a person does not reliably trigger the declared `ON DELETE CASCADE` actions, leaving orphaned relationship records in the `edges` table. This behavior contradicts the documented guarantees that foreign-key constraints prevent invalid relationships and that deleting a person removes all associated relationships. Parameterized SQL prevents SQL injection here, but it does not compensate for disabled referential-integrity controls. ### Attack Path 1. A caller invokes `add_relationship` with one or both pers ...[truncated 1312 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
database.py:214
Finding

Duplicate Relationship Creation Silently Replaces Existing Records

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

md
See [people_skill.py](people_skill.py) for complete API documentation.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README promotes collecting, storing, and exporting sensitive relationship data about identifiable people, including roles, organizations, personal traits, and notes, but provides no privacy warning, consent guidance, retention expectations, or access-control considerations. In a relationship-management skill, normalizing unrestricted storage/export of personal data increases the risk of privacy harm, unauthorized disclosure, and misuse even if no exploit code is present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly stores personal profiles, relationship metadata, character notes, and exportable graph data, but it does not warn users about the sensitivity of this information or the privacy risks of bulk export. In a people-relationship management context, omission of privacy and handling guidance can lead to unnecessary collection, insecure retention, and accidental disclosure of sensitive personal or organizational data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation presents delete-person and delete-relationship operations as routine commands without any caution about irreversibility, backup, or confirmation. Because the skill also supports cascade deletion, a user or upstream agent could trigger permanent loss of person and relationship data more easily than expected.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 198)May include surrounding context.

text

### Cascade Deletion
Deleting a person automatically removes all associated relationships.

### Duplicate Prevention
The UNIQUE constraint prevents duplicate relationships between the same two people with the same type.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file defines a deletion method that irreversibly removes a person record from the SQLite database, but the implementation provides no confirmation prompt, logging, or user-facing warning about the action. Although the docstring states that the method deletes a person, it does not disclose the safety impact to an end user, and the operation can affect stored relationship data as well.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This method permanently deletes relationship-edge data from the database without any confirmation, print/log disclosure, or explicit warning about the irreversible change. For a skill managing user data, silent destructive operations should be clearly disclosed somewhere visible to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.