Back to skill

Security audit

oss-dev

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly OSS workflow guidance, but it forces use of an external review scanner that is not declared in metadata and is under-scoped for a process-only skill.

Review before installing. This skill may be useful for structured OSS contribution workflows, but only use it if you are comfortable installing and running the referenced external open-code-review tool yourself. Prefer a pinned, verified version and avoid letting the skill trigger for ordinary coding or debugging tasks.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list uses broad terms such as development workflow, CI configuration, review response, branch strategy, and version management, which can match many ordinary engineering requests. Overbroad activation increases the chance this skill is selected outside its intended niche, exposing users to its hard-gated workflow rules and external-tool requirements unexpectedly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file claims the skill only governs process, but later prescribes concrete code/test/document diff checks and defect scanning behavior. This mismatch can mislead operators and higher-level routing into invoking the skill in broader contexts than intended, causing it to influence code-review/security decisions while appearing low-risk and process-only.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill mandates installation and use of an external code-review/security scanning CLI and explicitly hard-fails if it is absent. That expands the skill from documentation about process into tool-directed security analysis and dependency acquisition, which can cause unreviewed package installation, broaden trust boundaries, and force users into executing third-party binaries during normal workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.