Back to skill

Security audit

cyberscope

Security checks for vulnerabilities and agentic risk

Overview

CyberScope is a disclosed offline reference/search tool for public cyber and censorship-method descriptions, with dual-use content but no hidden execution, networking, persistence, or credential access.

Install only if you want a local dual-use cyber reference catalog. Treat results as research pointers, not instructions; avoid using the catalog to plan unauthorized attacks, surveillance, censorship, disruption, or target selection, and verify linked sources independently when accuracy matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The catalog is framed as reference-only, but many entries describe offensive, surveillance, censorship, and disruption methods with enough specificity to aid discovery, targeting, or conceptual planning. While it does not include step-by-step exploit code, the combination of categorized offensive methods, searchable metadata, and curated sources increases dual-use risk and undermines the non-operational safety claim.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The stated usage rules prohibit weaponization, but some method records still encode actionable concepts such as infiltration, exfiltration, blocking, disruption, proxy coordination, and target-list distribution. That mismatch can make policy controls ineffective because the content itself remains useful for operational understanding despite the disclaimers.

Static analysis

No suspicious patterns detected.