Back to skill

Security audit

mellos-mapping

Security checks for vulnerabilities and agentic risk

Overview

This skill maintains local dependency maps and opens local viewers, with disclosed state changes and no evidence of deception, exfiltration, or destructive behavior.

Install this only if you want development work mapped in project files. Expect .mellos files, a saved mapping preference, and local UI or terminal viewer actions; choose on-request if you do not want automatic map opening, and treat registration commands as install or repair actions only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation criteria are broad enough to trigger on most non-trivial implementation or architecture work, which makes the skill likely to run in many contexts without a narrowly scoped user request. In combination with its file persistence and viewer-opening behavior, this broad trigger increases the chance of unexpected side effects and overreach.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description does not upfront disclose that it persists state in project files and may automatically open local viewers or panels. This weakens informed consent and makes otherwise non-malicious automation more dangerous because users may not realize the skill changes files and launches local UI/processes.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

The skill authorizes autonomous declaration of structure and opening of panes without asking first based on a stored policy. Although framed as standing consent, it still permits side-effecting actions in future sessions without contemporaneous confirmation, which is risky when the skill can write files and manipulate local UI.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
- `on-request` — open a map only when the user explicitly asks.

Under `always` and `complex`, the recorded policy is STANDING CONSENT: on a
task it covers, declare the ghost design and open the pane yourself, without
asking first. Re-asking for permission the user has already given is the
failure mode this policy exists to remove.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to run a registration script that changes host/plugin configuration, which exceeds the narrow task of maintaining a dependency map. Even though framed as installation/repair guidance, this enables persistent environment modification and can be triggered in a development workflow where the user may not expect config changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill directs the agent to invoke local Node CLIs and host UI-opening tools as fallback behavior, expanding its authority from bookkeeping into process execution and local UI manipulation. That increases the attack surface because a compromised or overly broad skill can cause side effects on the user's machine beyond the expected mapping function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes commands to start and stop a local web service for the viewer, which is local service lifecycle management unrelated to the minimum necessary function of maintaining a map. Starting/stopping services can affect system state, expose ports, or interfere with other local workflows if done automatically or unexpectedly.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

This instruction tells the agent to immediately open a pane when none is visible, without asking first. Because opening panes can launch tools or alter the user's local interface state, automatic execution increases the risk of unwanted side effects and reduces user control in a skill that already has broad activation rules.

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
declare, update, remove and view answers with a `pane:` line telling you
   who is actually looking. Read it and act on it:
   - `pane: CLOSED` — nobody is. Call `mmap_open {page: "<slug>"}` at once,
     without asking first: a recorded mapping policy IS the user's standing
     consent to see the map. Confirm it is live only after the tool succeeds.
     If automatic opening already failed, relay the reason and copyable command
     once; retry only after the environment changes or the user asks.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill tells the agent to emit or run watcher commands and set up tmux/terminal processes, which can spawn persistent local processes and alter the user's terminal environment. For a mapping skill, this is an unnecessary escalation of operational scope and could be abused to create confusion, persistence, or unwanted resource consumption.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.