Back to skill

Security audit

OneScience-Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed OneScience workflow helper, but it grants broad remote execution, SSH metadata access, cloud upload, and destructive install authority without enough scoping or confirmation.

Review before installing. Only use this skill in a dedicated workspace and with a clearly selected DCU host. Do not allow it to print your full SSH config, upload broad project directories, delete existing remote directories, or run unpinned install scripts unless you have independently reviewed the target host, file list, repository commit, and commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
onescience-installer/SKILL.md:13
Finding

Mandatory Reading and Disclosure of the Entire SSH Configuration

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
onescience-installer/SKILL.md:69
Finding

Unpinned Remote Code and Dependencies Are Downloaded and Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
onescience-installer/SKILL.md:80
Finding

Recursive Deletion Uses an Unvalidated Relative Path

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
onescience-debug/references/e2e_pipeline_test.md:54
Finding

Broad Project File Collection and Upload to an External SCnet Service

Content
View full analysis
.sh ``` The specified upload manifest includes: ```text train.py reference.py or inference.py configuration files dataset or data-loading modules model files or dependency modules test_train_.py test_.sh ``` The top-level debug Skill reinforces the behavior at `onescience-debug/SKILL.md:115`: ```text Submit execution through the scnet MCP and collect .out and .err files. ``` ### Technical Analysis The workflow sends project files to an external platform without requiring: - A sensitivity or secret scan - A strict minimal-file allowlist - Per-file user approval - Destination identity and tenant verification - Data-classification checks - Exclusion of datasets, credentials, proprietary source, or model weights - Confirmation of retention and access-control policy The phrase “all files” creates an unnecessarily broad collection boundary. Full path disclosure can also expose local usernames, directory names, project identifiers, and workstation layout even when the file contents are benign. Testing may legitimately require selected source files, but indiscriminate directory collection exceeds that requirement. ### Attack Path 1. A generated task directory contains required test files and one or more sensitive or unrelated artifacts. 2. The debug workflow reads all files in the directory. 3. It constructs a broad manifest using full local path ...[truncated 852 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
onescience-runtime/SKILL.md:82
Finding

Untrusted Runtime Configuration Is Interpolated into Executable Shell Context

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (84)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The workflow goes beyond testing and directs the agent to analyze failures, implement code fixes, and rerun tests. For a routing/management skill, this is a material privilege expansion: an attacker could leverage the testing flow to induce unauthorized source-code changes under the guise of 'repair', causing integrity loss or insertion of unsafe logic.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document contains contradictory instructions: one section says not to modify the code under test, while another directs the agent to implement repairs. In practice, such conflicts create unsafe ambiguity that can be exploited to justify unauthorized code edits, especially when failures occur and the agent chooses the more permissive path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s declared behavior is a remote installation and system administration workflow, which materially exceeds the parent skill’s stated role as a content/router manager for models, datasets, and components. This kind of capability expansion is dangerous because it can cause the agent to perform privileged actions on local and remote systems under a misleading trust boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates reading ~/.ssh/config from the user’s local machine, which exposes sensitive connection metadata such as host aliases, usernames, ports, and infrastructure layout. That access is not justified by the parent skill’s stated routing/content role, so it creates an unnecessary privacy and reconnaissance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs the agent to perform remote system administration over SSH, including environment modification, package installation, code retrieval, and validation on a remote host. This is a substantial privileged action set unrelated to the parent skill’s described orchestration purpose and could be abused to alter remote systems or deploy unreviewed software.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to run rm -rf on the remote onescience directory is destructive and provides no warning, backup step, or confirmation flow. If the path contains modified work, local patches, or valuable data, the action can cause irreversible data loss on the remote system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Several routing categories use overlapping, underspecified keywords without clear scope boundaries, which makes misclassification likely. Because this manager orchestrates other skills rather than only answering textually, ambiguous matching can invoke the wrong capability chain and cause unintended code generation, runtime execution, or debugging against the wrong context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill describes reading runtime configuration, generating SLURM scripts, and submitting training or data-processing jobs, but it does not require an explicit user-facing warning or confirmation about compute costs, cluster side effects, queue usage, or data exposure. In this context, the omission is materially risky because the skill is designed to bridge from natural-language requests into actual job execution on shared infrastructure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger keywords are broad enough that ordinary requests such as 'research', 'project', 'predict', or 'data' could activate workflows that generate code, prepare jobs, or route into runtime execution unintentionally. In this skill, that risk is amplified because routing can lead to downstream SLURM submission and other side-effecting operations, so ambiguous intent classification can escalate a harmless query into operational actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The environment installation flow includes reading SSH configuration, establishing a remote DCU connection, and installing dependencies, yet no explicit safety notice, trust boundary, or confirmation requirement is stated. This is dangerous because remote installation can modify external systems, consume privileged access, and create persistence or configuration drift if triggered from an ambiguous or manipulated prompt.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is framed as analysis and planning, but its instructions explicitly extend into code generation, debugging orchestration, and file output. That broadens the skill from advisory behavior into acting on the environment, which can cause unintended code changes or persistence without clear user consent or scoped safeguards.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill mandates use of a separate debugging skill in a loop until tests pass, effectively creating delegated execution and iterative modification behavior. This is risky because it can trigger repeated external actions and code changes outside a pure planning role, increasing the chance of unsafe tool use, runaway loops, or unauthorized task execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs that generated plans and code should be saved to the current case directory by default, but it does not require an explicit user warning or consent for filesystem writes. Implicit writes are dangerous because they create persistent side effects, may overwrite existing artifacts, and can be abused when the working directory contains sensitive or unexpected files.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file uses Chinese throughout the operational description, parameter explanations, and risk notes, and does not indicate that the user can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless a locale-specific constraint is clearly justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file uses Chinese throughout its natural-language instructions and descriptions, with no indication that the user can choose another language or that the skill is intentionally region-specific. Per the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all operational instructions and constraints in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. That creates a natural-language policy concern because the file effectively forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains all substantive instructions and contract details in Chinese, with no indication that users may choose another language or that the Chinese-only format is required for a specific regional context. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file uses Chinese throughout its headings and content, which effectively forces a specific language for users reading the contract. The policy allows locale constraints only when user choice is offered or the constraint is clearly documented and justified, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural-language documentation entirely in Chinese, including headings and operational descriptions. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation, and this file does not indicate that Chinese is required or that alternate language support is available.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing documentation entirely in Chinese, including headings and operational descriptions, with no indication that the user can choose another language or that the skill is intentionally restricted to a Chinese-speaking audience. That can violate language/locale policy because it effectively forces one language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file uses Chinese throughout its headings and operational descriptions, which can force a specific language on users or maintainers without opt-in. The policy permits locale constraints only when choice or clear justification is provided, neither of which appears here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file contains user-facing natural-language content only in Chinese, including headings, parameter descriptions, and risk notes. Under the policy, forcing a specific language without user opt-in or a documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file contains its operational description exclusively in Chinese, including headings, parameter explanations, risks, and usage notes. Under the policy for natural-language violations, forcing a specific language without user opt-in or justification is a locale/language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file is written entirely in Chinese and states a naming convention as the current preferred standard, but it does not provide an opt-in language choice or explain why a Chinese-only convention is required. This can violate language/locale policy when users or contributors may reasonably expect language flexibility.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file presents all substantive operational guidance in Chinese, including headings, parameter descriptions, risks, and usage notes. Under the policy, forcing a specific language without user opt-in or a documented locale-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.