Back to skill

Security audit

autoagent

Security checks for vulnerabilities and agentic risk

Overview

The skill is purpose-aligned but sets up recurring background optimization that writes files and spawns subagents without enough bounds or cleanup controls.

Review this before installing if you are comfortable with an automated cron job that keeps running every five minutes, edits sandbox files, logs results, and forwards full guidance and test data to subagents. Use only a new dedicated sandbox with non-sensitive content, avoid absolute paths, inspect the cron entry before enabling it, and make sure you know exactly how to stop and remove the job.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:106
Finding

Unbounded Recurring Cross-Session Execution Through Cron

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:190
Finding

Untrusted Guidance and Fixture Content Is Delegated to a Subagent Without Isolation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:40
Finding

Arbitrary Sandbox Paths Permit Unsafe File Creation and Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill directs the agent to set up cron as part of normal operation without an explicit warning that this creates a persistent background scheduled task. Persistent automation is more dangerous than a one-time action because it can continue executing repeatedly, consume resources, modify data over time, or become difficult for the user to notice and remove if created unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description highlights optimization convenience but does not clearly warn that the skill performs repeated automated file modifications and sets up cron-triggered execution. Because this skill continuously edits guidance and may copy external scripts into a sandbox, the lack of upfront warnings can mislead users about persistence, write activity, and operational risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README advertises a bare /autoagent trigger with no scope constraints, even though the skill can create sandboxes, copy files, and schedule recurring optimization runs. A generic invocation increases the chance of accidental activation and makes it easier for users or downstream agents to start a powerful workflow without first narrowing target paths, schedules, or modification boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill creates directories at user-specified paths, copies files, edits working guidance, and schedules recurring cron execution, but its description does not prominently warn about these persistent side effects. Users may invoke it expecting a one-shot advisory skill and unintentionally authorize ongoing file writes and repeated automated actions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly expands its behavior from prompt/guidance optimization into locating, reading, and evaluating arbitrary external scripts or tools referenced by the user. That broadens the trust boundary and can lead the agent to inspect or reason about unrelated codebases, proprietary tooling, or sensitive local artifacts without a clear scope limitation, increasing the chance of unintended data exposure or unsafe recommendations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill goes beyond recommending prompt improvements and suggests modifying open-source scripts to improve functionality. This creates scope creep from text optimization into code-change guidance, which can drive the agent to propose or facilitate changes to executable logic that the user did not originally intend to entrust to this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The iteration phase instructs the agent to send the full contents of current-guidance.md and inline test cases to a spawned subagent, but does not warn users that potentially sensitive prompts, fixtures, or embedded data will be propagated to another execution context. This can expose confidential instructions, proprietary evaluation data, or secrets accidentally stored in guidance/test files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs the agent to overwrite current-guidance.md as part of its loop without requiring user confirmation or a dry-run step. Even if intended behavior is optimization, autonomous file modification can silently alter important guidance and create integrity and auditability risks, especially when the edits are derived from model-generated judgments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document specifies creation of a cron job that runs every 5 minutes, but it does not mention obtaining explicit user consent, notifying the user about persistent background execution, or explaining how to inspect and remove the job. Persistent scheduled execution increases risk because it can continue consuming resources, modifying files, or invoking subagents after the initial interaction has ended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup flow instructs the agent to create directories and multiple files on the user's filesystem, including allowing absolute paths, but does not require an explicit warning or a final confirmation immediately before making those changes. This creates a real risk of unintended writes in sensitive locations, especially because users may not understand the path resolution behavior or may provide ambiguous input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs the agent to append entries to scores.md persistently on each run without notifying the user or obtaining consent. While lower impact than overwriting guidance, silent log growth can cause unwanted state changes, pollute project history, and make automated experimentation harder to review or roll back.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.