Back to skill

Security audit

Server Audit

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible server-audit helper, but it asks agents to use unrestricted root SSH and later save sensitive infrastructure reports to a fixed vault path without adequate scoping or disclosure.

Install only if you intend to let an agent run server diagnostics over SSH and you are comfortable with the agent seeing sensitive infrastructure data. Prefer using a dedicated audit account or constrained sudo rules instead of direct root SSH, and treat the Obsidian report-writing steps as optional only after confirming the destination, file permissions, sanitization, and retention policy.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:3
Finding

Audit Commands Are Executed Through an Unrestricted Root SSH Session

Content
View full analysis
'<команда>'` --- ## Крок 0 — Визначення типу сервера ``` exec: ssh root@HOST 'pveversion 2>/dev/null && echo TYPE=PROXMOX || echo TYPE=LINUX' ``` ``` The same root SSH execution pattern is subsequently used for all audit commands in `SKILL.md`. ### Technical Analysis The Skill mandates direct SSH authentication as `root` for the complete audit. Some hardware and kernel diagnostics may require elevated permissions, but many commands in the workflow—such as `free`, `lsblk`, `ip`, `ss`, `ps`, `uptime`, and portions of `systemctl` inspection—do not require unrestricted root access. This design violates the principle of least privilege. The statement that the audit is read-only is only an instruction-level restriction; it is not enforced by SSH authorization, shell restrictions, command allowlisting, mandatory access controls, or a constrained privilege boundary. Once the root SSH session is established, the execution channel technically has permission to read, modify, or delete any data accessible to the host's root account. The risk is amplified by the use of command templates containing replaceable host, disk, and interface identifiers. Any future command-generation error, unsafe extension, malicious modification of the Skill, or shell metacharacter introduced into a dynamically composed command would execute with complete system privileges. ### Attack Path 1. A user requests an audit of a Linux or Proxmox server. 2. The agent follows the required template and authenticates directly as `root`. 3. The Skill opens a remote shell execution channel without a server-side command allowlist. 4. Commands are gene ...[truncated 1116 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/linux-audit.md:188
Finding

Read-Only Audit Promise Is Contradicted by Persistent Plaintext Report Writes

Content
View full analysis
" DOC_DIR="/DATA/local_database/${PROJECT}/Servers/${HOSTNAME}" mkdir -p "$DOC_DIR" ``` It then instructs the agent to save: ```text $DOC_DIR/server-info.md ``` The Proxmox reference contains the equivalent write operation: ```bash PROJECT="<назва проєкту від Сергія>" DOC_DIR="/DATA/local_database/${PROJECT}/Proxmox/${HOSTNAME}" mkdir -p "$DOC_DIR" ``` It likewise instructs the agent to save: ```text $DOC_DIR/server-info.md ``` The report templates include hostnames, IP addresses, operating-system or Proxmox versions, hardware inventory, disk models and health, RAID and storage layout, network interfaces, services, VM/container inventory, and discovered problems. ### Technical Analysis The documented behavior contradicts the Skill's top-level read-only guarantee. Both reference workflows direct the agent to create directories and persist a report after collecting sensitive infrastructure information. No file-permission policy, encryption requirement, retention rule, redaction procedure, destination validation, or access-control check is specified. Consequently, the report may be created using ambient permissions and remain reada ...[truncated 2637 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description is written as 'Skill для повної діагностики серверів', indicating the skill is presented in Ukrainian with no stated option for another language or locale. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill collects potentially sensitive operational data from remote hosts, including login history, failed login attempts, listening services, routing state, journal logs, and package update status, without requiring an explicit warning or confirmation. In a real deployment this can expose usernames, IP addresses, hostnames, internal topology, service inventory, and security-relevant events to the agent or downstream systems, increasing confidentiality risk.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/linux-audit.md (reported line 106)May include surrounding context.

bash
systemctl list-units --type=service --state=running --no-pager
systemctl list-units --type=service --state=failed --no-pager
systemctl list-unit-files --type=service --state=enabled --no-pager

8. Аналіз логів

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The audit prompt goes beyond read-only diagnostics and instructs the agent to create and save a server inventory document in an external Obsidian vault on another server. That introduces data exfiltration and persistence of sensitive infrastructure details without any access-control checks, minimization, or explicit user confirmation for the transfer target.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown directs saving detailed audit results including hostname, IPs, hardware, services, logs, and security posture into a local documentation vault, but provides no warning that this content is sensitive. Centralizing such data in plaintext documentation increases the blast radius of any vault compromise and may expose internal topology and weaknesses.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill title and instructions are written entirely in Ukrainian, and it specifically instructs the agent to ask 'Сергія' for the project name. This imposes a language/locale and user-context assumption without documenting that the skill is intended only for that audience or offering an alternative language choice.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill goes beyond read-only auditing by instructing the agent to create directories and save a report into an external Obsidian vault. That introduces write-side effects on persistent storage, and because the destination path includes user-provided project data, it can cause unintended modification of files or systems outside the audited host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The prompt instructs saving collected audit results to persistent storage on another server without prominently warning about the write operation or cross-system data movement. This can leak sensitive infrastructure details such as hostnames, IPs, hardware inventory, RAID state, and operational issues into a secondary location that may have different access controls or retention policies.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The natural-language instructions are written as mandatory Ukrainian guidance without offering any language choice or documenting that the skill is intentionally locale-specific. This creates a language policy concern because the skill effectively constrains interaction to one language without explicit user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The line states that the audit should only read and must not execute certain commands, but the very next line defines the audit mechanism as exec: ssh ... '<command>', and the rest of the file consists of remote command execution. While these commands are read-only, the wording "тільки читати. НЕ виконувати" literally contradicts the implementation approach of executing commands to gather data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language instructions throughout the file are entirely in Ukrainian, including operational prompts and output expectations, with no indication that the user may choose another language. Under SQP-3, forcing a specific language without user opt-in is a policy concern unless the locale constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.