Back to skill

Security audit

Control D

Security checks for vulnerabilities and agentic risk

Overview

This Control D skill is mostly coherent, but its first-time setup tells agents to run remote installer scripts directly in a shell without verification or explicit approval.

Review the installer step carefully before installing. Prefer installing the oo CLI through documented, verifiable package-manager or checksum-verified steps, and only allow destructive Control D actions after checking the exact profile, rule targets, and payload.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
95% confidence
Finding

The skill instructs the agent to install software by piping a remotely fetched script directly into a shell, which is a classic supply-chain and remote-code-execution risk. If the install endpoint, transport, hosting, or upstream release process is compromised, arbitrary code would execute immediately on the user's machine without inspection.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

Static analysis

No suspicious patterns detected.