Back to skill

Security audit

VSD Craft Operations

Security checks for vulnerabilities and agentic risk

Overview

This skill gives user-directed VSD Craft setup, backup, plugin update, and troubleshooting procedures with proportionate safeguards and a read-only helper script.

Install this only if you want an agent to help manage local VSD Craft/StreamDock settings and plugins. Before allowing file-based updates, confirm the active data folder in the app UI, keep the timestamped backups, and review any proposed plugin or cache changes before they are applied.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The code chunk’s actual function is narrow and read-only: it validates a supplied root directory, checks for specific subdirectories/files, counts profile directories, and parses plugin manifests to report metadata. That is materially different from the declared purpose, which presents a full management and troubleshooting capability for StreamDock/VSD Craft, including configuration changes, plugin installation/updates, backups, and USB/KVM recovery diagnosis. While inventorying plugins/profiles could be a supporting diagnostic subtask, this code alone does not substantiate the broader declared functionality and instead reflects a much more limited purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description centers on actively configuring StreamDock/VSD Craft devices and plugins, backing up settings, and diagnosing USB/KVM recovery issues. The actual code does none of that. It is test code validating a separate inspection routine: creating temporary plugin/profile/config files, invoking inspect(root), and asserting that only plugin inventory is read, profiles/config contents are not surfaced, malformed manifests generate warnings, symlinks are skipped, and files are not modified. This is a materially different primary purpose from device configuration or plugin management, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L28 states that the user-facing README is in Japanese, but the skill does not indicate that language choice is optional or that the locale restriction is required for a region-specific purpose. This is a natural-language locale policy concern because it may force users into a specific language without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file gives operational instructions involving cache manipulation (clearing Storeache / moving contents aside) that could affect application behavior or user state, but it does not explicitly warn about possible loss of cached data, need for backups, or service interruption beyond advising not to delete everything first. Because SQP-2 applies to markdown files when safety-relevant behaviors affecting user data or system integrity are described without warnings, this merits a low-severity finding.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The docstring says the tool is a read-only inventory that "never prints profile contents or runtime logs." While it does not dump profile files, it does print the resolved root path via the root field, which is profile-related filesystem metadata. This is not a code/manifest scope issue, but it is a mild contradiction between the documentation's privacy-oriented claim and actual output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.