Back to skill

Security audit

Isp Throttle Detective

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its optional scheduled tests can keep running every 30 minutes and consume significant bandwidth without enough warnings or removal guidance.

Install only if you are comfortable with active speed tests contacting Cloudflare, npm/Fastly, GitHub/Fastly, and optionally CloudFront, and writing logs under ~/.isp-throttle-detective. Be especially cautious before enabling the launchd or cron examples: they keep running every 30 minutes until removed and may use substantial bandwidth on capped or mobile plans.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T06 · System Persistence

Warning
Location
references/setup-guide.md:41
Finding

Optional LaunchAgent and Cron Configuration Creates Cross-Session Scheduled Execution

Content
View full analysis
Label com.isp-throttle-detective ProgramArguments /bin/sh -c python3 /path/to/skills/isp-throttle-detective/scripts/speedtest.py | python3 /path/to/skills/isp-throttle-detective/scripts/log_result.py StartInterval 1800 RunAtLoad ``` ```bash launchctl load ~/Library/LaunchAgents/com.isp-throttle-detective.plist ``` ```bash crontab -e # Add: */30 * * * * python3 /path/to/skills/isp-throttle-detective/scripts/speedtest.py | python3 /path/to/skills/isp-throttle-detective/scripts/log_result.py >> ~/.isp-throttle-detective/cron.log 2>&1 ``` ### Technical Analysis The setup guide instructs the user to register either a macOS LaunchAgent or a Linux cron job that executes the Skill every 30 minutes. These registrations survive the initiating shell and continue operating across user sessions, meeting the definition of a system-persistence mechanism. Periodic execution is functionally relevant because detecting time-dependent bandwidth patterns requires multiple measurements. The mechanism is also openly documented and is not installed automatically by the Python scripts. Nevertheless, it exceeds the privileges and duration required for a single speed test or report-generation operation. Once configured, every scheduled run performs multiple external downloads, uploads approximately 5 MB to Cloudflare, and appends results to p ...[truncated 2111 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This second description-behavior mismatch reinforces that the skill's declared purpose overstates persistent logging, throttling analysis, evidence generation, and endpoint coverage. Misrepresentation of capabilities can cause overbroad activation, unjustified permission grants, and operational misuse, particularly for a skill that performs network diagnostics and stores local artifacts.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

This second description-behavior mismatch reinforces that the skill's declared purpose overstates persistent logging, throttling analysis, evidence generation, and endpoint coverage. Misrepresentation of capabilities can cause overbroad activation, unjustified permission grants, and operational misuse, particularly for a skill that performs network diagnostics and stores local artifacts.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises and instructs use of shell commands, network access, and file-writing behavior, but it does not declare any explicit tool scope or permissions. That creates a least-privilege and transparency problem: an agent may invoke broader capabilities than a user or platform reviewer expects, especially because the skill writes logs under the user's home directory and performs active network measurements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad enough to match ordinary conversation such as 'internet slow' or 'speed history,' which can cause the skill to trigger unexpectedly. In context, that matters because the skill is designed to use network, shell, and file-writing capabilities, so accidental activation could launch diagnostics or create local logs without sufficiently deliberate user intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 21)May include surrounding context.

Copy the example config and customize:

bash
mkdir -p ~/.isp-throttle-detective
cp assets/config.example.json ~/.isp-throttle-detective/config.json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs users to schedule speed tests every 30 minutes and to download up to 25 MB per test from multiple endpoints, but it does not warn about cumulative bandwidth consumption, possible metered-data charges, or self-induced network load. This can cause unintended operational and financial impact, especially on capped, mobile, or congested connections.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 41)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 45)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 46)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 61)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 66)May include surrounding context.

macOS (launchd) — every 30 minutes

Create ~/Library/LaunchAgents/com.isp-throttle-detective.plist:

xml
<?xml version="1.0" encoding="UTF-8"?>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 45)May include surrounding context.

xml
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
  <key>Label</key>

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 66)May include surrounding context.

Load it:

bash
launchctl load ~/Library/LaunchAgents/com.isp-throttle-detective.plist

Linux (cron) — every 30 minutes

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/setup-guide.md (reported line 72)May include surrounding context.

Linux (cron) — every 30 minutes

bash
crontab -e
# Add:
*/30 * * * * python3 /path/to/skills/isp-throttle-detective/scripts/speedtest.py | python3 /path/to/skills/isp-throttle-detective/scripts/log_result.py >> ~/.isp-throttle-detective/cron.log 2>&1

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/report.py (reported line 24)May include surrounding context.

python
def run_analysis(log_path: str, days: int) -> dict:
    result = subprocess.run(
        [sys.executable, ANALYZE_SCRIPT, "--log", log_path, "--days", str(days), "--json"],
        capture_output=True, text=True
    )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/speedtest.py (reported line 81)May include surrounding context.

python
"-A", "isp-throttle-detective/1.0",
            url
        ]
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout + 5)
        if result.returncode not in (0, 63):  # 63 = max-filesize exceeded (expected)
            return {"speed_mbps": None, "error": result.stderr.strip() or f"curl exit {result.returncode}"}
        parts = result.stdout.strip().split()

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/speedtest.py (reported line 98)May include surrounding context.

python
def curl_available() -> bool:
    try:
        subprocess.run(["curl", "--version"], capture_output=True, timeout=5)
        return True
    except Exception:
        return False

Static analysis

No suspicious patterns detected.