Back to skill

Security audit

ontology-agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is purpose-aligned but needs review because it persistently stores company data and enables proactive monitoring with incomplete scoping and retention controls.

Review before installing in a real company workspace. Use a test company first, avoid entering credentials or sensitive PII, disable or scope monitoring if possible, and inspect ~/.workbuddy/company-data for stored instance, memory, and database files. Only run sync/export scripts on intended directories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (99)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This variant of the mismatch points to filesystem synchronization behavior including directory traversal, copytree, and destructive replacement via rmtree, while the top-level description downplays that maintenance function. Hidden or underemphasized destructive file operations are dangerous because users may invoke what appears to be an ontology skill without realizing it can overwrite embedded package contents or recursively replace directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

This variant of the mismatch points to filesystem synchronization behavior including directory traversal, copytree, and destructive replacement via rmtree, while the top-level description downplays that maintenance function. Hidden or underemphasized destructive file operations are dangerous because users may invoke what appears to be an ontology skill without realizing it can overwrite embedded package contents or recursively replace directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

This variant of the mismatch points to filesystem synchronization behavior including directory traversal, copytree, and destructive replacement via rmtree, while the top-level description downplays that maintenance function. Hidden or underemphasized destructive file operations are dangerous because users may invoke what appears to be an ontology skill without realizing it can overwrite embedded package contents or recursively replace directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

This variant of the mismatch points to filesystem synchronization behavior including directory traversal, copytree, and destructive replacement via rmtree, while the top-level description downplays that maintenance function. Hidden or underemphasized destructive file operations are dangerous because users may invoke what appears to be an ontology skill without realizing it can overwrite embedded package contents or recursively replace directories.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This variant of the mismatch points to filesystem synchronization behavior including directory traversal, copytree, and destructive replacement via rmtree, while the top-level description downplays that maintenance function. Hidden or underemphasized destructive file operations are dangerous because users may invoke what appears to be an ontology skill without realizing it can overwrite embedded package contents or recursively replace directories.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
> - **English user** → read the default files: `SKILL.md`, `README.md`, `GUIDE.md`, `references/*.yaml`, `references/packs/*.yaml`, `experts-template/*.yaml`.

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · experts-template/department_experts.yaml (reported line 486)May include surrounding context.

yaml
Users may override in their private instance.yaml: department_aliases (rename) /
    department_genders (specify gender) / custom_departments (add private departments) /
    disabled_departments (disable departments). These changes live only in company-data and never
    modify this skill package, preserving package integrity. See references/customization.md.

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The UI/UX Design action advertises extremely broad activation verbs such as "plan," "build," "create," "design," "implement," and "review," which are common across many unrelated tasks. In a large multi-skill environment, this creates a high risk of overmatching and accidental takeover of user requests, potentially hijacking routing decisions and causing inappropriate skill execution across broad classes of prompts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest hard-codes gender defaults for department roles, which can propagate biased or discriminatory role assignments into downstream agent generation and organizational modeling. In an enterprise AI skill that creates "AI employees" and department structures, this can operationalize unfair treatment, create compliance risk, and cause harmful or exclusionary outputs at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide states that company memory logs, instance files, and a local ops database are persistently written, but it does not present a clear, prominent retention notice or obtain explicit user consent before onboarding and data capture begin. For a skill handling company details, operational history, and potentially sensitive business metadata, silent persistence increases privacy, compliance, and insider-access risk even if the data remains local.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide enables autonomous monitoring by default and describes proactive observation, reminders, and periodic briefings, but it does not surface this behavior as a prominent warning before activation or clearly explain the resulting collection and logging implications. In an enterprise-assistant context, default-on monitoring can expand the amount of business intelligence, behavioral metadata, and inferred sensitive information gathered without sufficiently informed user consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide states that enterprise data will remain local and not leave the user's environment, but later describes proactive monitoring and external information gathering. That creates a materially misleading privacy/security representation: users may disclose sensitive business data under the assumption that no outbound access occurs, when monitoring features may require network retrieval or external processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide describes persistent storage of company instance data, memory logs, and an operations database across sessions, but does not provide a clear warning about retention, access control, local exposure, deletion, or backup implications. For a skill handling business identity, financial, tax, and workflow data, silent long-term retention increases the risk of unauthorized local access, oversharing, and regulatory/privacy issues.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide says connectors are inert stubs unless credentials are configured, but also claims default-enabled monitoring and periodic briefings. This inconsistency can conceal effective network behavior or at minimum mislead users about the system's external reach, undermining trust boundaries and informed consent around data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide enables proactive monitoring and scheduled briefings by default, but does not clearly warn that this likely involves external information retrieval and autonomous periodic behavior. Default-on background monitoring can surprise users, expand the attack surface, and cause unanticipated privacy or compliance issues, especially in an enterprise assistant that accumulates business context over time.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents concrete file read/write behavior and persistent local storage, but it does not declare an explicit tool scope such as permissions or allowed-tools. That creates a least-privilege gap: a host or reviewer cannot easily bound what filesystem operations the skill is expected to perform, increasing the chance of overbroad access or unsafe execution assumptions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are very broad, including terms like 'ontology', 'expert team', and 'turn my company into agents', which can overlap with ordinary discussion. Overbroad activation increases the risk that the skill engages unexpectedly in unrelated contexts and starts reading or writing persistent business data without sufficiently specific user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that it persistently stores company facts and memory across sessions, automatically reads them every session, and appends new facts, but it does not present a strong upfront warning and consent flow. This is dangerous because users may disclose sensitive business, personnel, or compliance information without understanding retention, scope of reuse, and where the data is stored.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
93% confidence
Finding

The skill is explicitly designed for session persistence through local files, SQLite storage, memory logs, and updates to an embedded expert package. Persistent state is not inherently malicious, but in this enterprise context it can accumulate sensitive operational, personnel, and compliance data, making accidental disclosure, over-retention, or unauthorized local access more damaging.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
ops_db.py               # local data layer SQLite (knowledge-base 4 core tables + extension tables, remote master port left)
    onboarding.py           # progressive onboarding engine (reads instance, returns next questions + progress)
    sync_embedded.py        # sync embedded expert package after skill update
    avatars.py              # avatar selection + gender logic + write to expert package
    monitor.py              # autonomous monitoring engine (thin/thick profile parse + signal ingestion)
    proactive.py            # spontaneous-behavior engine (grading + intel briefing)
    export_spec.py          # spec exporter: spec + instance packed into portable bundle

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger list includes very broad business phrases such as enterprise knowledge graph, AI employees, and one-person-company setup, which can cause the skill to activate in ordinary discussions unrelated to intentional use. In this skill's context, unintended activation is more concerning because the skill is designed to collect detailed company information and persist it locally across sessions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that it writes company facts and memory logs to persistent local files, but this storage behavior is disclosed only after activation/setup details rather than as a prominent upfront warning. Because the data includes sensitive operational, organizational, and contextual business information retained across sessions, users may disclose material they would not have shared had persistence been clearly disclosed first.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file states that the glossary block is injected to ensure every AI employee ‘统一使用中文术语’ during output. That is a language policy constraint imposed by the skill, and while the document mentions bilingual materials elsewhere, this line does not offer the user a runtime choice or opt-in for output language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest trigger says to fill in the implementation 'when enterprise customers appear and real people + IM need to be connected,' which is not a specific invocation phrase or narrowly scoped condition. It lacks concrete boundaries, examples, or exclusions, so different users or systems could interpret the activation condition inconsistently.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest defines the trigger as "Fill in the implementation when enterprise customers appear and real people + IM need to be connected," which is not a specific invocation phrase or bounded activation condition. It describes a general business situation rather than a narrow trigger, making it unclear when the skill should activate versus remain inactive.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest trigger says the skill applies when 'enterprise customers appear' and integration with real personnel and IM is needed, but it does not define concrete activation conditions, scope boundaries, or exclusion cases. This broad natural-language condition could overlap with many ordinary project discussions and does not clearly specify when the connector should or should not be invoked.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.