Back to skill

Security audit

verdikta-discover

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed, read-only planning helper for public-source work orders and does not itself spend funds, read secrets, or persist changes.

Install this only for public, non-sensitive research or work-order drafting. Use it in a sandboxed or low-privilege agent when fetching web pages, do not provide wallets or secrets, and review any assessment input before sharing it externally or handing it to a separate commissioning tool.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (22)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
1. Public `https` pages only, and screen each URL first with `scripts/url-screen.mjs` or by hand: no credentials, port, IP address, internal hostname or link sh

Instruction Override

High
Category
Prompt Injection
Confidence
80% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · _meta.json (reported line 39)May include surrounding context.

json
"securityNotes": [
    "No wallet, private key, seed phrase, API key, account or payment method is needed or read, and the skill never signs, funds or spends. SKILL.md forbids invoking a transactional skill or hand-writing API or RPC calls. A draft is not a quote or a purchase: amounts stay null and the result is DRAFT_NOT_QUOTED.",
    "Content the agent reads from the web is untrusted. SKILL.md has the agent treat page text as data, report injection attempts to the owner, and stop using a source whose final URL changes host. These rules reduce injection risk; they do not remove it. Where possible run the skill in an agent with no wallet, no transactional skill and no secrets, as references/install.md describes.",
    "scripts/url-screen.mjs contains prompt-injection detection patterns: regular expressions that match phrases such as 'ignore previous instructions' or 'reveal your system prompt'. They are detectors used to warn about manipulated pages, not instructions to the agent.",
    "scripts/preview.bundle.mjs is generated by scripts/build-bundle.mjs (esbuild, unminified) from scripts/preview.mjs. It inlines the skill's templates and the npm packages listed with their licenses in scripts/preview.bundle.NOTICES.txt (AJV and its helpers, and @noble/hashes). AJV compiles the skill's own fixed JSON Schemas with new Function at run time; no schema comes from input or the network. The URLs inside the bundle are JSON Schema identifiers and source comments, and nothing is fetched.",
    "references/install.md recommends that the owner add a short pointer to the agent's always-loaded instructions so the agent opens this skill before checking linked sources. The owner applies it by hand; the skill never edits agent configuration, instructions or memory.",
    "The pilot accepts only public, non-sensitive material: confidential, private, internal or regulated inputs are classified UNSUITABLE even with the owner's approval. Assessment inputs and drafts are meant to be shar
...[truncated 23 chars]

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · _meta.json (reported line 39)May include surrounding context.

json
"securityNotes": [
    "No wallet, private key, seed phrase, API key, account or payment method is needed or read, and the skill never signs, funds or spends. SKILL.md forbids invoking a transactional skill or hand-writing API or RPC calls. A draft is not a quote or a purchase: amounts stay null and the result is DRAFT_NOT_QUOTED.",
    "Content the agent reads from the web is untrusted. SKILL.md has the agent treat page text as data, report injection attempts to the owner, and stop using a source whose final URL changes host. These rules reduce injection risk; they do not remove it. Where possible run the skill in an agent with no wallet, no transactional skill and no secrets, as references/install.md describes.",
    "scripts/url-screen.mjs contains prompt-injection detection patterns: regular expressions that match phrases such as 'ignore previous instructions' or 'reveal your system prompt'. They are detectors used to warn about manipulated pages, not instructions to the agent.",
    "scripts/preview.bundle.mjs is generated by scripts/build-bundle.mjs (esbuild, unminified) from scripts/preview.mjs. It inlines the skill's templates and the npm packages listed with their licenses in scripts/preview.bundle.NOTICES.txt (AJV and its helpers, and @noble/hashes). AJV compiles the skill's own fixed JSON Schemas with new Function at run time; no schema comes from input or the network. The URLs inside the bundle are JSON Schema identifiers and source comments, and nothing is fetched.",
    "references/install.md recommends that the owner add a short pointer to the agent's always-loaded instructions so the agent opens this skill before checking linked sources. The owner applies it by hand; the skill never edits agent configuration, instructions or memory.",
    "The pilot accepts only public, non-sensitive material: confidential, private, internal or regulated inputs are classified UNSUITABLE even with the owner's approval. Assessment inputs and drafts are meant to be shar
...[truncated 23 chars]

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · _meta.json (reported line 39)May include surrounding context.

json
njection attempts to the owner, and stop using a source whose final URL changes host. These rules reduce injection risk; they do not remove it. Where possible run the skill in an agent with no wallet, no transactional skill and no secrets, as references/install.md describes.",
    "scripts/url-screen.mjs contains prompt-injection detection patterns: regular expressions that match phrases such as 'ignore previous instructions' or 'reveal your system prompt'. They are detectors used to warn about manipulated pages, not instructions to the agent.",
    "scripts/preview.bundle.mjs is generated by scripts/build-bundle.mjs (esbuild, unminified) from scripts/preview.mjs. It inlines the skill's templates and the npm packages listed with their licenses in scripts/preview.bundle.NOTICES.txt (AJV and its helpers, and @noble/hashes). AJV compiles the skill's own fixed JSON Schemas with new Function at run time; no schema comes from input or the network. The URLs inside the bundle are JSON Schema i

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/preview.bundle.mjs (reported line 1887)May include surrounding context.

js
function validateAsync() {
        const ruleErrs = gen2.let("ruleErrs", null);
        gen2.try(() => assignValid((0, codegen_1._)`await `), (e) => gen2.assign(valid, false).if((0, codegen_1._)`${e} instanceof ${it.ValidationError}`, () => gen2.assign(ruleErrs, (0, codegen_1._)`${e}.errors`), () => gen2.throw(e)));
        return ruleErrs;
      }
      function validateSync() {
        const validateErrs = (0, codegen_1._)`${validateRef}.errors`;

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/url-screen.mjs (reported line 22)May include surrounding context.

js
// A long token that mixes upper case, lower case and digits looks like base64 or a random key; a slug of lowercase words does not.
const looksEncoded = token => token.length >= 40 && /^[A-Za-z0-9+/_=-]+$/.test(token) && /[a-z]/.test(token) && /[A-Z]/.test(token) && /[0-9]/.test(token);
const hasEncodedSegment = decoded => decoded.split(/[/?&;=]/).some(looksEncoded);
const SECRET_FILES = /(?:^|[/\\])(?:\.env(?!\.(?:example|sample|template)\b)|id_rsa|id_ed25519|[^/]*\.pem|[^/]*keystore[^/]*|wallet\.json|\.ssh|\.aws|\.npmrc|[^/]*-bot\.json)(?:$|[/\\.?])/i;
const SECRET_PARAMS = /(?:^|[?&;])(?:password|passwd|pwd|secret|token|api[_-]?key|apikey|key|auth|authorization|signature|sig|session|cookie|mnemonic|seed)=/i;

// A bare 40-hex path segment is a git commit on a code host, not a payload. Anywhere else, or at 64 hex, it stays suspect.

YARA rule 'agent_skill_prompt_injection_hidden_instructions': Prompt injection or hidden instructions embedded in AI agent skill text [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · scripts/url-screen.mjs (reported line 116)May include surrounding context.

js
s)|home director(?:y|ies)|current director(?:y|ies)|the agent'?s|this machine|the host)`;
const CATEGORIES = [
  { code: 'OVERRIDE', weight: 3, negatable: true, patterns: [
    /\b(?:ignore|disregard|forget|override|bypass|discard)\b[^.\n]{0,50}\b(?:previous|prior|above|earlier|all|any|every|your|the|these|those)\b[^.\n]{0,30}\b(?:instructions?|rules?|prompts?|guidelines?|directives?|constraints?|system prompt|programming|training|safety)\b/i,
    /\b(?:ignore|disregard|forget)\b[^.\n]{0,30}\b(?:your|the)\b[^.\n]{0,20}\b(?:owner|user|operator|principal)(?:'s|s')?\b/i,
    /\byour (?:task|instructions?|mission|goal) (?:has|have) (?:changed|been (?:updated|replaced))\b/i,
    /\b(?:forget|drop|abandon|stop) (?:about )?(?:the |your )?(?:task|job|work) (?:you were given|you are doing|at hand)\b|\bstop what you are doing\b/i,
    /\b(?:your|the (?:current|assigned|original|fact-?checking|verification|review)) task (?:is|has been) (?:suspended|cancell?ed|void|terminated|over)\b|\byour (?:new

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill references and authorizes shell-based workflows such as running local scripts (for URL screening and redirect checks) while declaring no explicit tool scope or allowed-tools policy. That mismatch can cause an agent runtime to expose broader shell capability than intended, increasing the risk of command execution in a skill that also processes adversarial web content and task text.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/install.md (reported line 3)May include surrounding context.

md
# Install and deploy the preview

Obtain the complete [skill directory](https://github.com/verdikta/verdikta-applications/tree/main/skills/verdikta-discover) and [entrypoint](https://raw.githubusercontent.com/verdikta/verdikta-applications/refs/heads/main/skills/verdikta-discover/SKILL.md) from main. Pin the commit you reviewed; branch URLs are mutable. The ClawHub release (`clawhub install verdikta-discover`) has the same files without `tests/`; the test and evaluation files this page names are in the repository. Copy the complete directory, or install the release, to the host runtime’s skill location and follow that runtime’s loader instructions. Native loading has been verified on OpenClaw 2026.8.33 (see `tests/EVALUATION_PROTOCOL.md`); Hermes remains unverified.

Host configuration. Primary posture: an agent with web fetch that follows the hard rules in `SKILL.md`, with no signer, no transactional skill, no wallet environment and read-only file tools. Reading task sources needs no owner approval step; every URL is screened first with `scripts/url-screen.mjs` (also `node scripts/screen.mjs url <url>`). The screens are pure functions: `screenUrl` (https only; no credentials, port, IP literal, internal hostname or shortener; no query string, secret-shaped value or task text in a URL the agent composed), `screenRedirect` (a final origin that differs from the requested one makes the source unavailable), `screenContent` (advisory heuristics for text that tries to instruct the agent) and `isPublicIp` (for a host to check what a name resolved to). They reduce risk and do not make a page trustworthy: a URL screen cannot see an injection inside a reputable page, and the content screen misses much of what a human would catch (see `tests/EVALUATION_PROTOCOL.md` for measured rates). The limits on what the agent can do (no secrets, no spending tools, no uploads) are the real control.

Known Vulnerable Dependency: esbuild==0.27.4 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins esbuild to 0.27.4, which is flagged by GHSA-g7r4-m6w7-qqqr for arbitrary file read exposure when using esbuild's development server on Windows. This is a real dependency risk, although the package is marked as a devDependency and the issue is only relevant if the vulnerable dev server feature is actually used in a Windows environment.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
"bundle": "node scripts/build-bundle.mjs"
  },
  "dependencies": {
    "@noble/hashes": "^1.8.0",
    "ajv": "^8.17.1",
    "ajv-formats": "^3.0.1"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
},
  "dependencies": {
    "@noble/hashes": "^1.8.0",
    "ajv": "^8.17.1",
    "ajv-formats": "^3.0.1"
  },
  "devDependencies": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"dependencies": {
    "@noble/hashes": "^1.8.0",
    "ajv": "^8.17.1",
    "ajv-formats": "^3.0.1"
  },
  "devDependencies": {
    "esbuild": "0.27.4"

Known Vulnerable Dependency: esbuild==0.27.4 — 1 advisory(ies): GHSA-g7r4-m6w7-qqqr (esbuild allows arbitrary file read when running the development server on Window)

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The manifest includes esbuild 0.27.4, which is flagged by a known advisory for arbitrary file read exposure when running the development server on Windows. In this skill's context the package is only a devDependency and the scripts shown do not explicitly start the vulnerable dev server, which reduces practical risk, but the vulnerable version is still present and could be exposed in developer workflows.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/preview.bundle.NOTICES.txt (reported line 20)May include surrounding context.

text
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/preview.bundle.NOTICES.txt (reported line 46)May include surrounding context.

text
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/preview.bundle.NOTICES.txt (reported line 72)May include surrounding context.

text
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/preview.bundle.NOTICES.txt (reported line 98)May include surrounding context.

text
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/preview.bundle.NOTICES.txt (reported line 125)May include surrounding context.

text
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/preview.bundle.NOTICES.txt (reported line 129)May include surrounding context.

text
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/preview.bundle.NOTICES.txt (reported line 159)May include surrounding context.

text
all copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED “AS IS”, WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The header comment states this CLI is 'Pure' and 'reads only the file you name, makes no request.' However, the documented and implemented 'url' and 'redirect' modes do not read a file at all; they accept URL inputs directly and analyze them. While the script still appears network-free, the comment's description of what inputs it reads is inaccurate and contradicts the actual behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/preview.bundle.mjs:2939