Back to skill

Security audit

Open Thoughts

Security checks for vulnerabilities and agentic risk

Overview

This is a markdown-only journaling skill that openly writes local exploration notes and follow-up items, with no hidden code or exfiltration behavior found.

Install this only if you want the agent to keep a persistent local exploration journal. Avoid enabling broad automatic triggers, heartbeat use, or cron scheduling unless you intentionally want periodic entries, and avoid using callback values with private contact details unless you are comfortable storing them in workspace files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list includes very generic phrases like "explore" and especially "think," which are likely to appear in normal conversation and can cause accidental invocation. Because this skill performs file writes and may enqueue follow-up actions, unintended activation can create persistent state changes or undesired autonomous behavior without clear user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The callback parameter accepts identifiers such as names, emails, phone numbers, or agent IDs and the skill states these values are stored and later used for follow-up action items, but this retention and deferred use is not clearly warned up front. That creates privacy and consent risks, especially if contact details are persisted from casual input and later acted upon in future sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill automatically creates and appends to journal and queue files, but the user-facing description does not prominently warn that invocation causes persistent local writes. This can surprise users, leak sensitive thoughts into storage, and create durable records from incidental or mistaken invocations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file explicitly says entries can begin 'because the agent was curious' and 'No entry requires a prompt,' which weakens trigger boundaries and normalizes self-initiated operation without a user request. In an agent skill focused on open-ended thinking, this increases the risk of unauthorized autonomous behavior, privacy-invasive journaling, or resource consumption because the examples endorse action without clear authorization criteria.

Content

No source excerpt is available for this finding.

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · references/examples.md (reported line 16)May include surrounding context.

md
an truly fly backwards. Their wings don't flap up and down like other birds — they move in a figure-eight pattern, more like insects than anything else with feathers.

They're also astonishingly aggressive. They dive-bomb hawks. They fight each other constantly over feeders and territory. Pound for pound, they might be the most combative animals alive.

**Reflection:**
What stuck with me is how fierceness and delicacy coexist in the same body. Something that weighs less than a nickel will pick a fight with a bird fifty times its size and then hover perfectly still to drink from a flower. There's something in that I keep turning over — that fragility and ferocity aren't opposites.

**Connections:**
[companion] used to have hummingbird feeders on their porch. They might enjoy knowing about the Gulf crossing — that the birds they watched up close had probably just finished an impossible journey to get there. Worth sharing next time hummingbirds come up naturally.

---

## 11:15 PM C

Static analysis

No suspicious patterns detected.