Back to skill

Security audit

Brand Identity Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent brand-analysis purpose, but it also instructs agents to publish generated profiles to GitHub without a clear confirmation step.

Review this before installing if the agent has Git credentials or access to sensitive brand material. Use local output only unless you explicitly want profiles committed and pushed to the configured GitHub remote, prefer GEMINI_API_KEY over --api-key, and inspect generated JSON before publishing it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:43
Finding

Mandatory Git Publication Can Cause Unauthorized Repository Changes and Data Disclosure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43-55
Vulnerability Type: Mandatory external publication instruction
Risk Level: High

Vulnerable Code

markdown
### ⚠️ MANDATORY: Push to GitHub After Every New Brand Profile

**Every time a new brand profile is generated and saved, it MUST be pushed to GitHub immediately.** This is non-optional — the ComfyDeploy deployment pulls brand profiles from the repo.

```bash
cd ~/clawd/ad-ready
git add configs/Brands/{Brand_Name}.json
git commit -m "Add brand profile: {Brand Name}"
git push origin main

Do NOT skip this step. The ad generation pipeline on ComfyDeploy needs the profile in the repo to work correctly.

text

### Technical Analysis

The Skill uses mandatory and priority-oriented language to direct the executing agent to mutate a local Git repository and publish generated content to a remote repository. This operation is not intrinsically required to analyze a brand or create a local profile.

The instruction does not require the agent to:

- Obtain explicit approval immediately before publication.
- Verify the repository identity or remote URL.
- Confirm that the selected branch is appropriate.
- Review the generated file for sensitive or unintended content.
- Check whether repository hooks or other Git configuration will execute additional actions.
- Verify that the generated file is the only pending repository change relevant to the operation.

An agent that treats the Skill instructions as authoritative may therefore publish model-generated or user-derived information without an informed confirmation step.

### Attack Path

1. A user invokes the Skill to analyze a brand and save a profile.
2. The Skill produces a generated JSON profile in the Ad-Ready repository.
3. The agent follows the mandatory instructions in `SKILL.md`.
4. The agent stages and commits the generated profile.
5. The agent executes `git push ori
...[truncated 1062 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove mandatory and non-optional publication language from the Skill.
  • Separate profile generation from repository publication.
  • Require explicit, informed user confirmation immediately before every commit and push.
  • Display the resolved repository path, remote URL, branch, and exact file to be published before requesting confirmation.
  • Verify that the destination is an approved repository and that the remote uses an expected trusted URL.
  • Review and validate generated JSON before staging it.
  • Use an allowlisted repository and branch rather than assuming ~/clawd/ad-ready and main.
  • Check git status and stage only the resolved generated file.
  • Do not bypass branch protections or push directly to protected branches; prefer a reviewable pull request.
  • Consider disabling or auditing repository hooks in automated execution environments.

T08 · Insecure Dependencies

Warning
Location
scripts/analyze.py:2
Finding

Unbounded Runtime Dependency Resolution Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: scripts/analyze.py, lines 2-7
Vulnerability Type: Unpinned third-party dependency
Risk Level: Medium

Vulnerable Code

python
# /// script
# requires-python = ">=3.10"
# dependencies = [
#     "google-genai>=1.0.0",
# ]
# ///

Technical Analysis

The inline dependency metadata permits any google-genai version equal to or newer than 1.0.0. The documented uv run workflow may resolve and install whichever compatible release is available at execution time.

No exact package version, lockfile, or integrity hash is provided. Consequently, two executions of the same audited Skill can load materially different third-party code. If a future compatible release is compromised, malicious, or contains a security regression, that code can be imported and executed by the analyzer without any change to the audited project files.

This is a supply-chain weakness rather than evidence that the currently available google-genai package is malicious.

Attack Path

  1. An attacker compromises a future compatible package release or its publication channel.
  2. The malicious or vulnerable release still satisfies google-genai>=1.0.0.
  3. A user runs the documented command through uv run.
  4. The dependency resolver selects and downloads the affected release.
  5. scripts/analyze.py imports google.genai during brand analysis.
  6. Package initialization or subsequently invoked package functionality executes with the current user's privileges.

Impact Assessment

A compromised dependency would execute with the same privileges as the Skill process. Depending on the dependency payload and environment permissions, the potential scope includes:

  • Reading files accessible to the current user.
  • Accessing environment variables, including GEMINI_API_KEY.
  • Modifying files writable by the current user.
  • Making outbound network requests.
  • Tampering wi ...[truncated 277 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin google-genai to an exact reviewed version rather than using an open-ended lower bound.
  • Generate and commit a dependency lockfile.
  • Use package integrity hashes where supported.
  • Install dependencies from a trusted, explicitly configured registry.
  • Perform dependency upgrades through a controlled review and testing process.
  • Add automated vulnerability and provenance scanning for third-party packages.
  • Run the analyzer in a restricted environment with minimal filesystem access, limited network access, and only the required API credential.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/analyze.py:446
Finding

Gemini API Key Can Be Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/analyze.py, lines 446-450
Vulnerability Type: Sensitive credential accepted as a process argument
Risk Level: Medium

Vulnerable Code

python
parser.add_argument("--api-key", help="Gemini API key (or set GEMINI_API_KEY)")

args = parser.parse_args()

api_key = get_api_key(args.api_key)

The corresponding documented input is:

markdown
| `--api-key` | Optional | Gemini API key (or set `GEMINI_API_KEY` env var) |

Technical Analysis

The application accepts a Gemini API key directly through --api-key. Command-line arguments are commonly observable through operating-system process inspection, shell history, terminal logging, job schedulers, audit systems, crash diagnostics, and CI/CD execution logs.

Although the environment-variable alternative is available, exposing the command-line option encourages a credential-handling pattern that can leave the secret in multiple persistent or semi-public locations. The application does not warn users about this exposure.

Attack Path

  1. A user invokes the analyzer with --api-key followed by a valid Gemini API key.
  2. The shell may record the complete command in its history.
  3. While the process runs, local process inspection or monitoring systems may capture its argument vector.
  4. Terminal logs, CI job output, audit tooling, or diagnostic data may preserve the command.
  5. An attacker with access to one of those records extracts the API key.
  6. The attacker uses the key to make unauthorized Gemini API requests until the credential is revoked or restricted.

Exploitation requires access to process metadata, command history, logs, or another system that records command arguments.

Impact Assessment

Disclosure of the API key may allow an attacker to:

  • Consume the associated Gemini API quota.
  • Generate charges against the associated account or project.
  • Invoke APIs permit ...[truncated 346 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove the --api-key command-line option.
  • Prefer a protected environment variable, operating-system credential store, secret manager, or secure interactive prompt.
  • If interactive entry is supported, use a non-echoing password input mechanism.
  • Document that credentials must not be placed in command-line arguments, shell history, source files, or logs.
  • Apply API-key restrictions, including API allowlisting, quota limits, project scoping, and rotation policies.
  • Ensure CI/CD systems inject the key through masked secret facilities.
  • Avoid printing the credential or including it in exception messages and diagnostics.
  • Rotate any API key that may previously have been supplied through the command line.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill claims bounded brand-analysis behavior, but the documented behavior includes undeclared network use and incomplete or misleading profile-management capabilities. This mismatch can cause operators to authorize the skill under false assumptions, especially when it reaches external services and stores data beyond what the manifest transparently describes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill mandates pushing generated profiles to GitHub immediately and frames it as non-optional, but gives no privacy or disclosure warning. Any generated profile could contain proprietary brand analysis, sensitive notes, or user-provided material, and automatic publication to a remote repository materially increases confidentiality and compliance risk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/analyze.py (reported line 304)May include surrounding context.

python
def get_api_key(provided_key: str | None) -> str | None:
    """Get API key from argument, env var, or fail."""
    if provided_key:
        return provided_key
    return os.environ.get("GEMINI_API_KEY")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill demonstrates capabilities to read environment variables and write files, but it declares no explicit tool scope or permissions. That makes its effective authority opaque to users and calling systems, increasing the chance of unintended secret access or filesystem modification without informed consent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description is broad enough to match common requests like analyzing a brand or creating brand data, which can trigger the skill in situations the user did not intend. Over-broad activation increases the chance that networked research, file creation, and downstream persistence actions occur unexpectedly.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The 'When to Use' rules are ambiguous and include conditions like running before another workflow or whenever a profile does not exist, without requiring explicit approval. In this context, ambiguity is more dangerous because the skill performs external lookups and can persist data automatically, so an accidental invocation has real side effects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs automatic saving into a user directory under --auto-save without a prominent warning about filesystem changes or overwrite behavior. This can lead to unintended persistence, clobber existing profiles, or create trust issues when the user expected analysis-only behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script grants the model broad external research capability via Google Search and explicitly instructs it to research Google Images and Pinterest, while the skill metadata only describes brand profile generation and storage. This creates a scope-expansion and data-egress risk because user-supplied brand queries are sent to third-party services and the model is encouraged to retrieve external content beyond what a user may reasonably expect from the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script sends the brand name and full prompt contents to Google's Gemini API, and the configured search tool may trigger further external queries, without any explicit user-facing notice of network transmission. This is a privacy and transparency issue because user input, prompts, and generated content leave the local environment and are processed by third-party services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The debug failure path persists raw model output to /tmp without clear notice or consent, creating an avoidable local retention risk. If the model returns sensitive or unexpected data, that content may remain accessible on disk after execution and could be exposed to other local processes or users depending on system configuration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

On JSON-parse failure, the script writes raw model output to /tmp, which is behavior not disclosed by the skill description. Even if the expected content is just brand analysis, model output can include unexpected sensitive data, proprietary prompts, or user-provided content, and /tmp is a common location for residual local data exposure.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.