Back to skill

Security audit

Ontology

Security checks for vulnerabilities and agentic risk

Overview

This is a local ontology memory skill, but its persistent writes are broader and less reliably validated than its documentation promises.

Review before installing. Do not store passwords, tokens, API keys, or other secrets in this ontology, and treat validation as advisory unless the mutation paths are fixed to validate before writing. Be aware that deletes are logical and old values can remain in the append-only graph file.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ontology.py:121
Finding

Schema Validation and Secret-Storage Restrictions Are Bypassed During Mutations

Content
View full analysis
dict: """Create a new entity.""" entity_id = entity_id or generate_id(type_name) timestamp = datetime.now(timezone.utc).isoformat() entity = { "id": entity_id, "type": type_name, "properties": properties, "created": timestamp, "updated": timestamp } record = {"op": "create", "entity": entity, "timestamp": timestamp} append_op(graph_path, record) return entity ``` Entity updates are also appended without schema validation: ```python def update_entity(entity_id: str, properties: dict, graph_path: str) -> dict | None: """Update entity properties.""" entities, _ = load_graph(graph_path) if entity_id not in entities: return None timestamp = datetime.now(timezone.utc).isoformat() record = {"op": "update", "id": entity_id, "properties": properties, "timestamp": timestamp} append_op(graph_path, record) entities[entity_id]["properties"].update(properties) entities[entity_id]["updated"] = timestamp return entities[entity_id] ``` Relations are committed without confirming th ...[truncated 4301 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 92)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 212)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 221)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 222)May include surrounding context.

md
python3 scripts/ontology.py create --type Person --props '{"name":"Alice","email":"alice@example.com"}'

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/schema.md (reported line 165)May include surrounding context.

forbidden_properties: [password, secret, token, key, api_key] properties: service: string secret_ref: string # Reference to secret store (e.g., "keychain:github-token") expires: datetime? scope: string[]?

text

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly describes local file write behavior, including creating directories and writing to memory/ontology/graph.jsonl and memory/ontology/schema.yaml, but it does not declare any tool scope such as permissions or allowed-tools. That mismatch weakens least-privilege controls and can let an orchestrator invoke a state-mutating skill without clear policy gating, increasing the chance of unauthorized or unintended workspace modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger language is very broad, including generic phrases like "remember," entity CRUD, planning, and cross-skill data access, which could cause the skill to activate in many unrelated contexts. Because this skill persists shared state and links objects across skills, accidental invocation can lead to unintended memory creation, incorrect graph mutations, or privacy-sensitive data being stored when the user did not clearly intend durable retention.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.