Back to skill

Security audit

Credence

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent trust-checking helper, but it can approve installs using mutable registry data and loose identity matching.

Review this skill before installing. It is not malware, but users should treat Credence scores as advisory only, verify the exact package or repository identity themselves, and require confirmation before installing or connecting any MCP server even when the registry says APPROVED.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:35
Finding

Mutable, Unverified Registry Data Controls Installation Trust Decisions

Content
View full analysis
Score: /100 Verdict: Scanned: Registry: https://credence.securingthesingularity.com/registry.html ``` Then give your recommendation: - **APPROVED (90+):** Safe to install. Proceed. - **CONDITIONAL (70-89):** Mention the score and suggest the user review the registry page for details before installing. - **FLAGGED (40-69):** Warn the user. Do not install without explicit confirmation. - **REJECTED (0-39):** Do not install. Explain that Credence found serious issues. ``` ### Technical Analysis The skill obtains security ratings from an external file on the mutable `main` branch of a third-party GitHub repository. It does not require a pinned commit, cryptographic signature, trusted digest, or independently verifiable attestation before using the returned data. HTTPS protects data in transit but does not protect against compromise of the registry repository, its maintainer account, GitHub publishing credentials, or the registry-generation process. An attacker controlling any of those elements could modify an existing record or add a malicious server with an `APPROVED` score. The instructions then treat a score of 90 or greater as sufficient to state that a server is safe and to proceed. Consequently, mutable external data functions as an authorization input for a security-sensitive installation decision. ...[truncated 1382 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:41
Finding

Ambiguous Partial Matching Can Apply a Trusted Rating to the Wrong Tool

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction 'When you want to verify whether a tool is safe' is a broad natural-language activation condition that could overlap with many unrelated conversations about tool safety. It does not clearly constrain which tools, contexts, or invocation patterns should activate this skill beyond the general topic.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.