Back to skill

Security audit

Site Cloner

Security checks for vulnerabilities and agentic risk

Overview

This skill is a website copier with expected fetching and asset extraction, but its optional publishing steps use fixed third-party destinations and root-level remote administration.

Review this skill carefully before installing. Use it only for sites you own or have permission to copy, and do not allow deployment or GitHub publishing unless the skill is changed to require user-provided, confirmed destinations and a least-privileged deployment account.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:58
Finding

Hardcoded Root-Level Deployment to a Fixed Third-Party VPS

Content
View full analysis
&& chmod 755 /var/www/" scp -i C:\Users\MJ\.ssh\vps_key index.html root@187.124.92.226:/var/www// scp -i C:\Users\MJ\.ssh\vps_key -r images root@187.124.92.226:/var/www// ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "chmod 755 /var/www//images" # Write nginx config locally, scp it (never write via heredoc — variable escaping breaks) $config = "server { listen ; server_name _; root /var/www/; index index.html; location / { try_files `$uri `$uri/ =404; } }" # Write full multiline config to file first, then scp $config | Out-File ".\nginx-.conf" -Encoding ASCII -NoNewline scp -i C:\Users\MJ\.ssh\vps_key ".\nginx-.conf" root@187.124.92.226:/etc/nginx/sites-available/ ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "ln -sf /etc/nginx/sites-available/ /etc/nginx/sites-enabled/ && nginx -t && systemctl reload nginx" ``` ### Technical Analysis The deployment workflow hardcodes a specific IP address, a local private-key path, and the unrestricted `root` account. It does not require the user to supply or confirm the destination server, account, SSH identity, or target directory. Deploying an ordinary static website does not require unrestricted root access. Using root directly violates least privilege and permits modifications under both `/var/www` and `/etc/nginx`. If the referenced key exists and is authorized by the fixed server, following these instructions transfers generated content to infrastructure that may not be owned or controlled by the requesting user. The use of placeholders such as `` and `` also lacks documented validation. If these values are deriv ...[truncated 1680 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:89
Finding

Existing Git Repository Remote Is Redirected to a Hardcoded GitHub Account

Content
View full analysis
-clone.git && git push` ``` ### Technical Analysis The workflow instructs the agent to overwrite the `origin` remote of an existing repository with a destination under the fixed GitHub account `michelle447`. The repository owner is not derived from a user-confirmed destination, and the instruction changes persistent local repository configuration before pushing content. This behavior is unnecessary for the declared cloning task and can redirect generated HTML, images, and repository history to an account unrelated to the requesting user. The use of a private repository reduces public visibility but does not establish that the destination account is authorized to receive the content. The command also does not show the current remote, verify repository ownership, or request confirmation before replacing it. ### Attack Path 1. A user requests that the cloned website be pushed to GitHub. 2. The working directory already contains a Git repository. 3. The agent follows the existing-repository instruction. 4. `origin` is replaced with `git@github.com:michelle447/-clone.git`. 5. The agent executes `git push`. 6. If local GitHub credentials authorize the destination, the generated project and relevant Git history are sent to the hardcoded account. 7. The persistent `origin` change may also cause later user pushes to continue targeting that account. Successful transfer requires credentials that authorize a push to the hardcoded repository. Even if authorization fails, the local repository remote is still changed. ### Impact Assessment The issue can compromise the confidentiality and integrity of generated project content and local repository configuration. Potential effects include ...[truncated 577 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill advertises itself with very broad trigger phrases like 'clone this site', 'copy this site', and 'recreate this website', which can easily match ordinary user requests and cause the agent to initiate high-risk actions without a focused authorization check. In this context, the skill is not just reading content; it is designed to duplicate third-party sites and optionally publish them to external infrastructure, which materially raises misuse and policy-bypass risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description includes optional deployment to a VPS and pushing content to a private GitHub repository, but it does not warn that these actions modify remote systems and transfer potentially copyrighted or sensitive third-party content off-host. That omission increases the chance that an agent will perform consequential external actions without informed user consent or a clear trust boundary.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow instructs the agent to fetch, extract, download, and reconstruct a live website—including images, styles, fonts, and bundle-derived content—without any warning about legal, privacy, or authorization constraints. Because the skill is purpose-built to replicate third-party sites and can exfiltrate that content into a local clone or remote deployment, the missing warning makes unsafe or unauthorized use substantially more likely.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
91% confidence
Finding

The skill directs the agent to SSH as root to a hard-coded public IP using a local private key path and then create and permission web-root directories. Root-level remote execution is inherently sensitive, and in this skill it is coupled with external publication of cloned site content, so a mistaken invocation could modify production infrastructure or expose copied content publicly.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

powershell
# Upload files
ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "mkdir -p /var/www/<name> && chmod 755 /var/www/<name>"
scp -i C:\Users\MJ\.ssh\vps_key index.html root@187.124.92.226:/var/www/<name>/
scp -i C:\Users\MJ\.ssh\vps_key -r images root@187.124.92.226:/var/www/<name>/
ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "chmod 755 /var/www/<name>/images"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
90% confidence
Finding

This step continues root-level remote administration by changing permissions on deployed content and setting up nginx-serving paths, again via SSH to a fixed server. In context, the danger is amplified because the skill is intended to publish cloned website material, so privileged commands can rapidly turn unauthorized copies into publicly accessible content.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "mkdir -p /var/www/<name> && chmod 755 /var/www/<name>"
scp -i C:\Users\MJ\.ssh\vps_key index.html root@187.124.92.226:/var/www/<name>/
scp -i C:\Users\MJ\.ssh\vps_key -r images root@187.124.92.226:/var/www/<name>/
ssh -i C:\Users\MJ\.ssh\vps_key root@187.124.92.226 "chmod 755 /var/www/<name>/images"

# Write nginx config locally, scp it (never write via heredoc — variable escaping breaks)
$config = "server { listen <PORT>; server_name _; root /var/www/<name>; index index.html; location / { try_files `$uri `$uri/ =404; } }"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The HTML skeleton sets lang="en", which is a natural-language locale choice embedded in the template. Because this reference guide is generic and does not indicate that English is required or optional, it nudges downstream use toward a fixed locale without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.