Back to skill

Security audit

4090ctl

Security checks for vulnerabilities and agentic risk

Overview

This skill is a server-control cheat sheet that is not malicious, but it exposes ready-to-run SSH and Docker restart commands for a specific host without safety gates.

Install this only in an environment where the user is authorized to administer the referenced 4090 server. Treat restart commands as disruptive operations and require explicit confirmation before running them; read-only status and log commands are lower risk but still use the configured SSH identity.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill provides direct SSH-based operational commands to control a remote 4090 server and restart production-like services, but it gives no warnings, approval gates, or safety guidance about service disruption or misuse. In an agent-skill context, documenting ready-to-run administrative commands against a specific host materially increases the chance of accidental or unauthorized disruptive actions.

Static analysis

No suspicious patterns detected.