Back to skill

Security audit

Ontology

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local shared-memory ontology tool, but its persistent graph writes and validation gap deserve user review before installation.

Review this before installing if you expect strict memory safety. Use it only for workspace data you are comfortable storing in persistent JSONL history, avoid entering passwords/tokens/API keys, and treat validation as a manual check rather than a write-time guarantee unless the implementation is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ontology.py:110
Finding

Graph constraints are not enforced before mutations are committed

Content
View full analysis
dict: """Create a new entity.""" entity_id = entity_id or generate_id(type_name) timestamp = datetime.now(timezone.utc).isoformat() entity = { "id": entity_id, "type": type_name, "properties": properties, "created": timestamp, "updated": timestamp } record = {"op": "create", "entity": entity, "timestamp": timestamp} append_op(graph_path, record) return entity ``` Updates are also persisted without applying the schema: ```python def update_entity(entity_id: str, properties: dict, graph_path: str) -> dict | None: """Update entity properties.""" entities, _ = load_graph(graph_path) if entity_id not in entities: return None timestamp = datetime.now(timezone.utc).isoformat() record = {"op": "update", "id": entity_id, "properties": properties, "timestamp": timestamp} append_op(graph_path, record) entities[entity_id]["properties"].update(properties) entities[entity_id]["updated"] = timestamp return entities[entity_id] ``` Relations are persisted without checking endpoint existence, endpoint types, cardinality, or acyclicity: ```python def create_relation(from_id: str, rel_type: str, to_id: str, properties: dict, graph_path: str): """Create a relation between entities.""" timestamp = datetime.now(timezone.utc).isoformat() record = { "op": "relate", "from": from_id, "rel": rel_type, "to": to_id, "properties": properties, "timestamp": timestamp } append_o ...[truncated 3898 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/schema.md (reported line 165)May include surrounding context.

forbidden_properties: [password, secret, token, key, api_key] properties: service: string secret_ref: string # Reference to secret store (e.g., "keychain:github-token") expires: datetime? scope: string[]?

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill explicitly instructs the agent to read and write persistent workspace files (memory/ontology/graph.jsonl and memory/ontology/schema.yaml) but does not declare any tool or permission scope. That mismatch weakens safety boundaries because the agent may perform file writes without an explicit least-privilege contract, increasing the chance of unintended persistence or abuse by downstream prompts using this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes broad phrases such as "remember," "what do I know about," and generic entity CRUD or cross-skill data access, which can cause the skill to activate in situations the user did not intend. Because this skill writes persistent shared state, over-broad invocation can silently store, link, or expose information across tasks and skills, making accidental data retention or cross-context contamination more likely.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest's description, triggers, and config descriptions are written entirely in Chinese, while the file does not state that the skill is region-specific or offer any language/locale option. This can violate language/locale policy expectations when users are not given an explicit choice or justification for the enforced language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger list is broad and overlaps with common knowledge-management phrases, which can cause the skill to activate in contexts the user did not explicitly intend. For a skill that provides shared structured memory and cross-skill state access, unintended activation increases the chance of inappropriate data creation, retrieval, or linkage across workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description and guidance do not prominently warn users that using the skill will create and update persistent workspace files. Without a clear warning, users may unknowingly cause durable storage of personal, project, or cross-skill state, which raises privacy and surprise-risk concerns even if the writes are functionally intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.