Back to skill

Security audit

anyone-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is openly designed to build persona packs, but it handles sensitive private communications and local skill files with several under-scoped safety controls.

Review before installing. Use this only with data you are authorized to process, avoid building personas from private third-party communications without consent, run it in a restricted working directory, and pin or preinstall the OpenPersona tool instead of using live `npx` commands. Do not use rollback, update, or init commands with untrusted slug/version values until path validation is added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:361
Finding

Unpinned npm Package Is Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skill_writer.py:40
Finding

Unsanitized Persona Slug Permits Path Traversal Outside the Skills Directory

Content
View full analysis
Remediation
View remediation
str: if not SLUG_PATTERN.fullmatch(slug): raise ValueError("Invalid persona slug") return slug ``` 2. Explicitly reject absolute paths, path separators, empty values, `.` and `..`. 3. Resolve the base and target paths and enforce containment: ```python base = base_dir.resolve() target = (base / validate_slug(slug)).resolve() if target.parent != base: raise ValueError("Persona path escapes the configured base directory") ``` 4. Reject symlinked persona directories or safely resolve and validate them before every write. 5. Create files with exclusive semantics where overwriting is not intended. 6. Apply one shared validation routine to `skill_writer.py`, `version_manager.py`, and any generated shell commands that use the slug. 7. Add regression tests for traversal strings, absolute paths, platform-specific separators, encoded separators, and symlink escapes. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/version_manager.py:57
Finding

Rollback Path Traversal Can Recursively Delete and Replace Unintended Directories

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents an end-to-end persona distillation and packaging skill. This code chunk does not perform persona analysis, cloning, profile extraction, or OpenPersona pack creation. Instead, it is a support script for preprocessing input data: detecting SQLite databases, extracting message text from known schemas, parsing generic JSON/text exports, filtering by target sender, and reducing large files via sampling. These behaviors may support the broader skill, but the code itself materially differs from the declared primary purpose and omits the headline capabilities described.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a full persona-distillation pipeline: ingesting various content sources, extracting a persona representation, and producing an OpenPersona skill pack. The supplied code does none of that. It only supports three CLI actions: listing existing skills by reading meta.json files, initializing a directory with a template meta.json, and updating metadata via a provided JSON patch. While this may be a small supporting component of a larger system, this chunk's actual behavior is materially narrower and different from the declared end-user purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill creates persona packs from source materials about a person or character. The actual code does none of that. It implements local filesystem version control for an existing skill by reading meta.json, copying directories into a .versions snapshot folder, updating version numbers and timestamps, restoring snapshots, and printing history. This is a materially different primary purpose and includes undeclared file-management capabilities unrelated to persona creation. Therefore the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is explicitly designed to collect chats, documents, and public content to build portable persona artifacts, but it does not provide a prominent upfront privacy warning commensurate with the sensitivity of that data. In this context, users may submit intimate third-party communications and personal archives without understanding retention, repackaging, and downstream training/export consequences.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill explicitly encourages creating personas of friends, family, partners, and ex-partners from their chats and documents. Even with a brief 'personal use only' note, this materially facilitates impersonation, non-consensual profiling, and privacy invasion of third parties based on intimate communications.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to retain source communications and repackage them into training data, persona files, and reusable skill artifacts. This is dangerous because it operationalizes long-term storage and transformation of sensitive personal content into assets that can be replayed, redistributed, or trained on beyond the original context of disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

These instructions direct the agent to immediately save processed source material into training/raw/ while only mentioning redaction of obvious PII, without an explicit user warning that highly sensitive personal data will be persistently stored and reused. Because the skill targets chats, diaries, email, and social archives, the storage behavior materially increases privacy and consent risk, especially for third-party data.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/skill_writer.py (reported line 14)May include surrounding context.

python
from datetime import datetime, timezone
from pathlib import Path

DEFAULT_BASE = Path(".claude/skills")


def _meta_path(slug: str, base_dir: Path) -> Path:

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/version_manager.py (reported line 14)May include surrounding context.

python
from datetime import datetime, timezone
from pathlib import Path

DEFAULT_BASE = Path(".claude/skills")


def _meta_path(slug: str, base_dir: Path) -> Path:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

bash
# Check at start of Phase 3 — if this directory exists, use persona-knowledge integration
ls skills/persona-knowledge/SKILL.md 2>/dev/null && echo "persona-knowledge detected"

When detected, data flow becomes: source → persona-knowledge ingest → MemPalace + KG + wiki → persona-knowledge export → training/

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad natural-language activations such as "create a persona for X," "make a skill pack for X," and "I want to talk to X as an AI," which could match ordinary user requests outside an explicit invocation context. The file does not provide negative examples or clear constraints on when these phrases should or should not activate the skill.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
## Tools


| Task                                         | Tool                                                                                   |
| -------------------------------------------- | -------------------------------------------------------------------------------------- |
| Read any text / JSON / CSV / PDF / image     | `Read` (native — use for most chat exports)                                            |
| Search public figures / fictional characters | `WebSearch`                                                                            |

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 358)May include surrounding context.

Step 6-B: Generate skill pack via skills/open-persona

Load skills/open-persona/SKILL.md and run with the persona.json from Step 6-A:

bash
npx openpersona create --config persona.json --output ./{slug}-skill

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill invokes npx openpersona create without pinning a package version or verifying integrity, which can fetch and execute whatever version is current at runtime. In a skill that processes sensitive persona/training data and writes artifacts to disk, this creates a supply-chain execution risk if the package is compromised or changed unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

Using npx openpersona install without a pinned version allows unreviewed remote code to be resolved and executed at install time. Because this skill already handles highly sensitive local data and generated persona packs, a compromised or drifting package could exfiltrate data or alter outputs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The unpinned npx openpersona switch command has the same supply-chain risk as the other npx calls: it may execute a newer or compromised package version than intended. In context, this is risky because the command affects active persona state and may interact with local persona artifacts.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 481)May include surrounding context.

When the user says /list-anyone:

bash
python3 ${CLAUDE_SKILL_DIR}/scripts/skill_writer.py --action list --base-dir ./.claude/skills

Display: codename · version · last updated · subject type.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The document instructs users to execute npx openpersona create without pinning an exact package version, which allows retrieval of whatever package version is current at execution time. If the upstream package is compromised, typosquatted, or publishes a malicious update, running the command can execute attacker-controlled code on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The unpinned npx openpersona install command executes code from the latest resolved package version at runtime rather than a reviewed, fixed release. In this skill, the command is framed as a routine installation step, which increases the chance a user will run it directly and expose their environment to supply-chain compromise.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The npx openpersona switch {slug} instruction is another live package execution path with no version pinning, so it may fetch and run an unintended or malicious package version. Because this file is an operational reference for generating and activating persona packs, the command is likely to be followed as written, making the supply-chain risk practical rather than theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The evolution update path tells users to re-run npx openpersona create during ongoing maintenance, repeatedly reintroducing exposure to whatever package version is current at that time. Recurrent unpinned execution expands the attack window and makes later compromise more likely even if the initial setup was safe.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code writes potentially sensitive message content from chat exports and databases to a JSON file, but there is no explicit warning in the code comments, CLI help, or user-facing output that the operation creates a new local copy of private data. Although the write is intentional, the file lacks a disclosure about the privacy impact of persisting extracted conversations to disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.