Back to skill

Security audit

Super SOP Node OS: Node Era Protocol

Security checks for vulnerabilities and agentic risk

Overview

This skill is a workflow template that creates local markdown run folders, with no evidence of hidden credentials, networking, persistence, or destructive behavior.

Before installing, understand that this skill may create local markdown workflow folders when the helper script is run. Use the script's --root option if you want those artifacts kept in a specific project directory.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill’s safety claim says the helper script should only write under a user-chosen run root, but the documented invocation exposes no parameter to constrain that path. This creates a documentation-to-behavior mismatch: users may assume writes are safely scoped when the script may instead choose its own output location or derive paths implicitly, increasing the risk of unintended filesystem writes if the script is later invoked by an agent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.