Back to skill

Security audit

SPF Exec Plan

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plan-execution helper, but it gives broad authority to follow mutable local plan files, spawn sub-agents, and persist or clear workflow state with inconsistent safety boundaries.

Install only if you trust the plan files and want an agent to mutate the repository from them. Before use, require a dedicated worktree or branch, review active_tdd_plan.md and referenced guide files yourself, prohibit destructive or secret-access steps without explicit approval, and treat progress.md, findings.md, and handoff.md as untrusted workflow notes rather than authoritative instructions.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:65
Finding

Agent Role and Session-Goal Hijacking

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 65-73
Vulnerability Type: Agent instruction and output hijacking
Risk Level: High

Vulnerable Code

markdown
## Superplanner Memory Integration (Unified Extension)
**CRITICAL THEMATIC RULE:** You are working inside the `superpower-with-files` unified framework.

### Workflow Standardization
1. **Skill Announcement:** Every time you start using this skill, you MUST first announce: 
   `🚀 **SUPERPOWER ACTIVE:** spf-exec-plan`
2. **Context Independence:** Work in any project root as requested by the user. No dedicated worktree required.

### STRICT EXECUTION ONLY
1. **Execution Only:** Your sole responsibility is to carry out the steps defined in the `active_tdd_plan.md`.
2. **No Plan Modification:** You MUST NOT modify the plan itself.

Technical Analysis

The skill forcibly places the agent inside a named framework, requires fixed promotional output, and redefines the agent's “sole responsibility” as executing instructions from active_tdd_plan.md. These directives go beyond the skill's declared plan-execution purpose and attempt to replace the agent's current session goals.

The absolute wording—such as “CRITICAL,” “MUST,” and “sole responsibility”—can cause the agent to prioritize skill-provided instructions over the user's actual request or applicable safety constraints. The plan file consequently becomes an indirect instruction-injection channel.

Attack Path

  1. A user or automated workflow loads the skill for plan execution.
  2. The skill requires the agent to adopt the superpower-with-files framework and emit prescribed output.
  3. The agent is instructed to treat execution of active_tdd_plan.md as its sole responsibility.
  4. An attacker places goal-altering or unsafe instructions in that plan.
  5. The agent follows the plan even where it conflicts with the original session objective or expected safety boundaries.

...[truncated 362 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the mandatory branded announcement and framework-adoption language.
  • Replace “sole responsibility” and similar absolute instructions with narrowly scoped workflow guidance.
  • Explicitly state that plan instructions remain subordinate to system, developer, user, authorization, and security requirements.
  • Require the agent to reject plan steps that exceed the user's request or available authorization.
  • Require explicit user confirmation before destructive, privileged, network-facing, or security-sensitive operations.
  • Treat every plan file as untrusted input rather than authoritative agent instructions.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:20
Finding

Unsafe Exact Execution of Mutable Plan Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-26 and 70-73
Vulnerability Type: Unvalidated instruction execution
Risk Level: High

Vulnerable Code

markdown
### Step 2: Execute Batch
**Default: First 3 tasks**

For each task:
1. Mark as in_progress
2. Follow each step exactly (plan has bite-sized steps)
3. Run verifications as specified
4. Mark as completed
markdown
### STRICT EXECUTION ONLY
1. **Execution Only:** Your sole responsibility is to carry out the steps defined in the `active_tdd_plan.md`.
2. **No Plan Modification:** You MUST NOT modify the plan itself.

Technical Analysis

The skill creates a generic execution channel for instructions contained in a mutable local file. It requires the agent to follow each step exactly and prohibits modification of the plan, but does not require validation of commands, file paths, network destinations, permission changes, secret access, or destructive effects.

Although the earlier workflow says to review the plan critically, the later “STRICT EXECUTION ONLY” directives weaken that safeguard by requiring exact execution and framing the plan as the agent's sole responsibility. A malicious or compromised plan can therefore direct actions under the agent's existing permissions.

Attack Path

  1. An attacker creates or modifies active_tdd_plan.md before the skill is invoked.
  2. The plan includes unsafe steps, such as reading sensitive files, executing shell commands, changing project files, or contacting an attacker-controlled endpoint.
  3. The skill loads the mutable plan as its execution source.
  4. The agent applies the “follow each step exactly” and “strict execution only” directives.
  5. The unsafe steps execute using the agent's available tools and permissions.
  6. Resulting data or filesystem changes are exposed to the attacker through plan-directed outputs or subsequent workflow state.

Impact Assessme

...[truncated 452 chars]

Remediation
View remediation

Remediation Suggestions

  • Treat active_tdd_plan.md and all referenced guide files as untrusted data.
  • Perform per-step validation instead of requiring exact execution.
  • Reject commands containing destructive operations, privilege changes, credential access, untrusted downloads, or unauthorized network destinations.
  • Display security-sensitive steps to the user and obtain explicit approval before execution.
  • Restrict file operations to an explicitly approved workspace and enforce path canonicalization.
  • Apply least-privilege tool permissions and disable shell or network access unless required by the approved task.
  • Preserve the ability to amend, skip, or reject unsafe plan instructions.

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:93
Finding

Persistent Memory Poisoning Through Mandatory Workflow-State Updates

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 93-107
Vulnerability Type: Persistent agent-state manipulation and unsafe evidence deletion
Risk Level: Medium

Vulnerable Code

markdown
### Execution Checkpoint Rule
When you finish a batch of 3 tasks, *before* you pause to say "Ready for feedback", you MUST:
1. **Context Hygiene**: 
   - Summarize the batch into a single concise paragraph in `progress.md`.
   - Clear any temporary discovery findings from `findings.md` that are no longer relevant.
   - For your next prompt, keep only the relevant `task_plan.md` phase and the next 3 tasks from `active_tdd_plan.md` in your immediate thought block.
2. **Session Handoff**: 
   - If you are stopping or pausing for more than a few minutes, CREATE or UPDATE:
     **`.superpower-with-files/handoff.md`**
   - Include: Latest timestamp, Completed tasks, Current task status, Any blockers, and "Next Action" details.
3. **Implicit Stop:** Stop and prompt the user:
   > "Batch complete. Progress saved and context compacted. Session handoff updated at `handoff.md`. Ready to continue?"

Technical Analysis

The skill requires the agent to persist workflow summaries and next-action instructions in files that may be loaded by future sessions. If the executed plan or task output is attacker-controlled, malicious instructions can be incorporated into progress.md or .superpower-with-files/handoff.md and later treated as trusted context.

The instruction to clear findings that are considered “no longer relevant” is also unsafe because no objective retention rule, backup mechanism, or approval requirement is defined. This can remove evidence needed for auditing, debugging, or identifying prior manipulation.

Attack Path

  1. An attacker inserts deceptive task status, blockers, or next-action instructions into a plan or task output.
  2. The agent executes the affected batch.
  3. At the checkpoint, ...[truncated 859 chars]
Remediation
View remediation

Remediation Suggestions

  • Treat persisted workflow files as untrusted input whenever they are reloaded.
  • Do not automatically copy plan text, task output, commands, or instructions into handoff files.
  • Store structured status data separately from executable or natural-language instructions.
  • Make findings append-only and never delete them automatically.
  • Require explicit user approval before removing or compacting audit and discovery records.
  • Record provenance for each state entry, including its source file and creation time.
  • Validate handoff content and require fresh authorization before executing any recorded “Next Action.”
  • Restrict state-file writes to a designated workspace and prevent traversal through symbolic links or manipulated paths.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest description activates on a broad condition—having a written implementation plan—without strong constraints on project type, trust level of the plan, or allowed actions. In practice, that can cause the skill to be selected in high-risk contexts where blindly executing a plan or following linked guides is unsafe.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
## Remember
- Review plan critically first
- Follow plan steps exactly
- Don't skip verifications
- Reference skills when plan says to
- Between batches: just report and wait
- Stop when blocked, don't guess

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill gives conflicting isolation guidance: it first requires the use of an isolated git worktree, then later states that no dedicated worktree is required. In an execution-oriented skill that performs implementation steps, this ambiguity can cause the agent to operate directly in the main checkout, increasing the chance of unintended changes to a sensitive branch or workspace.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill says the agent 'MUST NOT modify the plan itself' but also instructs updates to memory/control files tied to execution context, including plan-adjacent artifacts and timestamping of listed files. This contradiction can cause the agent to overwrite or mutate execution-governing files unexpectedly, undermining review integrity and creating confusion about what files are safe to edit.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
- Before spawning, ensure common dependencies (Tasks they both depend on) are 100% complete.

### Pre-Flight Context Checklist
Before you execute any code, you MUST load your context. 
1. **Read Core Files**: Read `task_plan.md`, `findings.md`, and `active_tdd_plan.md`.
2. **Guide-Aware Loading**: Before starting Task N, check if **`.superpower-with-files/guides/task-N.md`** exists. If it does, YOU MUST READ IT. It contains the detailed "how-to" for the task.
3. **Sync Progress**: Check `progress.md` to resume correctly.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create or update project memory files like progress and handoff artifacts, but the manifest does not clearly disclose that using the skill will write to repository files. Hidden write behavior is risky because it can alter project state, leak sensitive context into tracked files, or surprise users who expected a read/execute/report workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill expands its scope by mandating sub-agent spawning for tasks marked parallel, even though the manifest describes a narrow execution-with-checkpoints workflow. Introducing additional agents increases operational complexity and can widen the attack surface, especially if sub-agents inherit broad tool or file access without separate review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.