Back to skill

Security audit

Isp Throttle Detective

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent internet speed-test and reporting tool, but users should understand that scheduled use creates recurring third-party network traffic and local logs.

Install only if you are comfortable running speed tests that contact external services, download up to the configured byte limits, upload about 5 MB to Cloudflare per run, and store timestamped results locally. Do not enable the cron or launchd schedule on metered, enterprise, or sensitive networks unless recurring traffic every 30 minutes is acceptable; review or delete ~/.isp-throttle-detective when you no longer need the history.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This second mismatch likewise indicates the skill's declared purpose does not match actual code behavior, including missing analysis/reporting features and different endpoint behavior. Such discrepancies can conceal what the skill really accesses or fails to do, undermining least privilege decisions and making review, consent, and monitoring less reliable.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This second mismatch likewise indicates the skill's declared purpose does not match actual code behavior, including missing analysis/reporting features and different endpoint behavior. Such discrepancies can conceal what the skill really accesses or fails to do, undermining least privilege decisions and making review, consent, and monitoring less reliable.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and orchestrates shell execution, network access, and persistent file logging, but it does not declare any explicit tool scope or permissions boundaries. This creates an overbroad execution surface where an agent may invoke sensitive capabilities without clear policy review, increasing the risk of unintended filesystem changes or network activity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description says to use the skill when the user mentions phrases like "internet slow" and "internet speed," which are broad everyday expressions and could match many general troubleshooting conversations. The file does not provide exclusion conditions or tighter scope boundaries to clarify when the skill should not activate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 21)May include surrounding context.

Copy the example config and customize:

bash
mkdir -p ~/.isp-throttle-detective
cp assets/config.example.json ~/.isp-throttle-detective/config.json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide instructs users to schedule recurring speed tests every 30 minutes but does not warn that this will continuously generate network traffic to third-party endpoints and may consume bandwidth, affect data-capped plans, or create privacy-relevant telemetry. Because the purpose of the skill is to repeatedly contact external services, omitting this warning can lead users to unknowingly enable persistent outbound activity.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 41)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 45)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 46)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 61)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 66)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 45)May include surrounding context.

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 66)May include surrounding context.

Load it:

bash
launchctl load ~/Library/LaunchAgents/com.isp-throttle-detective.plist

Linux (cron) — every 30 minutes

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 72)May include surrounding context.

Linux (cron) — every 30 minutes

bash
crontab -e
# Add:
*/30 * * * * python3 /path/to/skills/isp-throttle-detective/scripts/speedtest.py | python3 /path/to/skills/isp-throttle-detective/scripts/log_result.py >> ~/.isp-throttle-detective/cron.log 2>&1

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/report.py (reported line 24)May include surrounding context.

python
def run_analysis(log_path: str, days: int) -> dict:
    result = subprocess.run(
        [sys.executable, ANALYZE_SCRIPT, "--log", log_path, "--days", str(days), "--json"],
        capture_output=True, text=True
    )

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest describes a speed-testing and reporting skill, which justifies network access, but it does not justify spawning external processes. Using subprocess.run to invoke curl adds an execution capability beyond the obvious needs of the stated purpose and broadens the runtime attack surface compared with using in-process HTTP libraries alone.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/speedtest.py (reported line 81)May include surrounding context.

python
"-A", "isp-throttle-detective/1.0",
            url
        ]
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout + 5)
        if result.returncode not in (0, 63):  # 63 = max-filesize exceeded (expected)
            return {"speed_mbps": None, "error": result.stderr.strip() or f"curl exit {result.returncode}"}
        parts = result.stdout.strip().split()

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/speedtest.py (reported line 98)May include surrounding context.

python
def curl_available() -> bool:
    try:
        subprocess.run(["curl", "--version"], capture_output=True, timeout=5)
        return True
    except Exception:
        return False

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The function performs a real 5 MB upload to a third-party endpoint automatically, which transmits user network traffic externally without an explicit warning or opt-in at execution time. In a skill that users may run for diagnosis, this can create privacy, policy, or cost concerns, especially on metered, enterprise, or sensitive networks where outbound testing may be unexpected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill persists test results under the user's home directory but does not clearly disclose that retention behavior in the user-facing description. Undisclosed local logging can surprise users, create privacy concerns, and leave historical network performance data on disk longer than expected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The module usage docstring describes only direct log-file and day-range analysis options, but the code also accepts --config and reads an arbitrary JSON config file to override log_path at L234-L240. For a skill described as analyzing speed-test history, reading a separate configuration file is adjacent to its purpose but still an undocumented behavior mismatch between the file's stated interface and actual operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This code accepts a --config path and opens the specified file, which is a file-read operation affecting user data, but there is no prompt, comment, or usage text explaining that the script will read configuration content from disk. The only documented usage examples mention --log, --out, and --days, so the file access behavior is not disclosed in the visible interface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

When no output path is provided, the script silently writes a detailed report to a persistent directory under the user's home folder and then prints the report contents. In the context of a network-diagnostics skill, that report may contain timestamps, usage patterns, endpoint data, and filesystem paths, creating a privacy leak and unexpected local data retention if the user expected analysis-only behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.