Back to skill

Security audit

Ai Monitor Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly an advisory monitoring/runbook package, but it includes broad production-changing incident commands without strong approval or scoping controls.

Install only as an advisory SRE/reference skill, not as an autonomous operations agent. Do not allow it to execute shell, database, Docker, Kubernetes, firewall, or rollback commands without a human reviewing the exact target and command; also expect the included install/build/smoke-test scripts to need repair before use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
build.sh:11
Finding

PowerShell Command Injection Through Unvalidated Version Input

Content
View full analysis
/dev/null 2>&1 || command -v powershell >/dev/null 2>&1; then PSH="$(command -v powershell.exe 2>/dev/null || command -v powershell)" WIN_SRC="$(cygpath -w "$(pwd)/$(basename "$STAGE_DIR")" 2>/dev/null || echo "$(pwd)/$(basename "$STAGE_DIR")")" WIN_OUT="$(cygpath -w "$OUT_DIR/$ZIP_NAME" 2>/dev/null || echo "$OUT_DIR/$ZIP_NAME")" "$PSH" -NoProfile -Command "Compress-Archive -Path '${WIN_SRC}' -DestinationPath '${WIN_OUT}' -Force" fi ``` ### Technical Analysis The first positional argument is accepted as `VER` without validating that it is a valid semantic version. This value becomes part of `OUT_DIR`, `ZIP_NAME`, and ultimately `WIN_OUT`. Although Bash variable expansions are quoted, `WIN_OUT` is subsequently embedded directly into PowerShell source code passed through `-Command`. The value is surrounded by PowerShell single quotes, but embedded single-quote characters are not escaped. Consequently, an attacker-controlled version can terminate the `-DestinationPath` string and append arbitrary PowerShell statements. This is a code-versus-data separation failure. Bash quoting protects the initial shell invocation but does not make the resulting value safe for interpretation by the second command language. ### Attack Path 1. An attacker obtains the ability to influence the version argument supplied to `build.sh`, such as through a release parameter, CI input, or a developer copying an untrusted build ...[truncated 1394 chars]
Remediation
View remediation
&2 exit 1 fi ``` If prerelease and build metadata are not needed, use the narrower `^[0-9]+\.[0-9]+\.[0-9]+$` expression. 2. Do not concatenate untrusted data into PowerShell program text. Pass paths through environment variables or a parameterized script: ```bash WIN_SRC="$WIN_SRC" WIN_OUT="$WIN_OUT" \ "$PSH" -NoProfile -Command \ 'Compress-Archive -LiteralPath $env:WIN_SRC -DestinationPath $env:WIN_OUT -Force' ``` 3. Use `-LiteralPath` so wildcard characters in generated paths are not interpreted. 4. Apply the validation to both command-line and manifest-derived versions because repository content may also be attacker-controlled in a compromised pull request. 5. Add regression tests that reject versions containing quotes, semicolons, newlines, command substitutions, path separators, and PowerShell metacharacters. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:81
Finding

Destructive Production Runbook Actions Lack Mandatory Approval and Scope Controls

Content
View full analysis
INTERVAL '5 minutes' AND state = 'active'; ``` ```text 3. Быстрая очистка: - find /var/log -name "*.gz" -mtime +7 -delete - journalctl --vacuum-size=500M - docker system prune -f - apt-get clean / yum clean all ``` ```text НЕМЕДЛЕННЫЕ МЕРЫ: 1. Блокировка подозрительных IP: iptables -A INPUT -s [IP] -j DROP ``` ### Technical Analysis The Skill is designed to guide infrastructure incident response and states that incident steps should be performed strictly in order. Several runbooks contain commands that modify production state or delete resources: - `rm -rf /tmp/*` removes all non-hidden entries from a shared temporary directory without checking ownership, age, active use, or application scope. - `docker system prune -f` removes unused Docker objects without presenting the affected resources or requesting confirmation. - `pg_terminate_backend` terminates every active PostgreSQL session matching a broad duration condition, without limiting the command to a specific application, database, user, query type, or verified blocker. - `iptables -A INPUT ... -j DROP` modifies host firewall state without validating the address, preserving administrative access, setting an expiration, or documenting rollback. The instructions do not consistently impose a mandatory human-approval gate, dry-run phase, backup requirement, bounded target set, maintenance-window check, or rollback verification. The word equivalent to “carefully” beside the temporary-directory de ...[truncated 1995 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (82)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose describes an operational AI monitoring system with monitoring, alerting, reporting, and control features. The supplied code does none of that. It is purely a packaging/build script for creating a distributable ZIP from source files and optionally validating it with a smoke test. This is a materially different primary purpose, not merely a supporting implementation detail of monitoring functionality. No monitoring logic, dashboards, alerts, incident handling, photo processing, SLA checks, or capacity control are present in the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code does not implement monitoring, dashboards, alerts, incident handling, photo reporting, SLA control, or infrastructure/site analysis. Instead, it performs a local smoke test for the skill/package itself, verifying file presence and text patterns in documentation and config files. This is a materially different primary purpose from the declared end-user functionality. While such tests may support development of the skill, this code chunk’s actual behavior is packaging/compliance validation, not AI monitoring operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill includes production-impacting actions such as restarts, rollback steps, query termination, IP blocking, pruning, and recursive deletion, but does not prominently warn that these steps can cause service disruption, data loss, or irreversible changes. In an agent-assisted environment, omission of explicit safety gating materially increases the risk of unsafe execution by users or automation.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The documented use of 'rm -rf /tmp/*' is a dangerous operational action because wildcard deletion can remove active sockets, temporary state, or files needed by running services, especially if executed on the wrong system or under elevated privileges. Given the skill's lack of strict tool scoping and broad triggers, this becomes materially riskier than a normal prose example.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

thresholds: payment-service: cpu_warning: 70 cpu_critical: 90 response_time_warning: 500ms response_time_critical: 1000ms error_rate_warning: 0.5 error_rate_critical: 2.0 db-primary: ram_warning: 80 ram_critical: 90 connections_warning: 60 connections_critical: 80

text
**Триггеры:** «инцидент: [тип]», «сервис упал», «что делать при [проблема]» Пошаговые инструкции для каждого типа инцидента. Выполнять строго по порядку. --- #### СЦЕНАРИЙ 3.1 — СЕРВИС ПОЛНОСТЬЮ УПАЛ ```
ДИАГНОСТИКА (первые 2 минуты): 1. ping [hostname] — проверить доступность сети 2. ssh [server] "systemctl status [service]" — статус процесса 3. ssh [server] "journalctl -u [service] -n 50" — последние логи 4. Проверить дашборд: CPU/RAM/Disk на момент падения КЛАССИФИКАЦИЯ ПРИЧИНЫ: □ OOM (Out of Memory) → см. шаг 3.1.A □ Disk Full → см. шаг 3.1.B □ Ошибка конфигурации → см. шаг 3.1.C □ Падение зависимости → см. шаг 3.1.D □ Неизвестно → см. шаг 3.1.E 3.1.A — OOM: 1. free -h — убедиться в нехватке памяти 2. Определить процесс: ps aux --sort=-%mem | head -10 3. Рестарт сервиса: systemctl restart [service] 4. Временное увеличение swap если нужно 5. Планировать постоянное решение: оптимизация / upgrade сервера 3.1.B — Disk Full: 1. df -h — какой раздел полный 2. du -sh /var/log/* | sort -rh | head -10 — найти тяжёлые файлы 3. Очистить логи: journalctl --vacuum-size=500M 4. Удалить tmp: rm -rf /tmp/* (осторожно!) 5. Рестарт сервиса 3.1.C — Ошибка конфигурации: 1. Найти последнее изменение: git log --oneline -10 2. Откатить конфиг на последнюю рабочую версию 3. Validate конфига перед применением: [service] --test-config 4. Рестарт 3.1.D — Падение зависимости: 1. Определить зависимость из логов 2. Проверить её статус в дашборде 3. Поднять зависимость или переключить на fallback 4. Рестарт основного сервиса 3.1.E — Неизвестная причина: 1. Сохранить core dump если есть 2. Рестарт с детальным логированием: [service] --log-level=debug 3. Наблюдение 15 минут 4. Если повторяется — 
...[truncated 26 chars]

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The documented use of 'rm -rf /tmp/*' is a dangerous operational action because wildcard deletion can remove active sockets, temporary state, or files needed by running services, especially if executed on the wrong system or under elevated privileges. Given the skill's lack of strict tool scoping and broad triggers, this becomes materially riskier than a normal prose example.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

thresholds: payment-service: cpu_warning: 70 cpu_critical: 90 response_time_warning: 500ms response_time_critical: 1000ms error_rate_warning: 0.5 error_rate_critical: 2.0 db-primary: ram_warning: 80 ram_critical: 90 connections_warning: 60 connections_critical: 80

text
**Триггеры:** «инцидент: [тип]», «сервис упал», «что делать при [проблема]» Пошаговые инструкции для каждого типа инцидента. Выполнять строго по порядку. --- #### СЦЕНАРИЙ 3.1 — СЕРВИС ПОЛНОСТЬЮ УПАЛ ```
ДИАГНОСТИКА (первые 2 минуты): 1. ping [hostname] — проверить доступность сети 2. ssh [server] "systemctl status [service]" — статус процесса 3. ssh [server] "journalctl -u [service] -n 50" — последние логи 4. Проверить дашборд: CPU/RAM/Disk на момент падения КЛАССИФИКАЦИЯ ПРИЧИНЫ: □ OOM (Out of Memory) → см. шаг 3.1.A □ Disk Full → см. шаг 3.1.B □ Ошибка конфигурации → см. шаг 3.1.C □ Падение зависимости → см. шаг 3.1.D □ Неизвестно → см. шаг 3.1.E 3.1.A — OOM: 1. free -h — убедиться в нехватке памяти 2. Определить процесс: ps aux --sort=-%mem | head -10 3. Рестарт сервиса: systemctl restart [service] 4. Временное увеличение swap если нужно 5. Планировать постоянное решение: оптимизация / upgrade сервера 3.1.B — Disk Full: 1. df -h — какой раздел полный 2. du -sh /var/log/* | sort -rh | head -10 — найти тяжёлые файлы 3. Очистить логи: journalctl --vacuum-size=500M 4. Удалить tmp: rm -rf /tmp/* (осторожно!) 5. Рестарт сервиса 3.1.C — Ошибка конфигурации: 1. Найти последнее изменение: git log --oneline -10 2. Откатить конфиг на последнюю рабочую версию 3. Validate конфига перед применением: [service] --test-config 4. Рестарт 3.1.D — Падение зависимости: 1. Определить зависимость из логов 2. Проверить её статус в дашборде 3. Поднять зависимость или переключить на fallback 4. Рестарт основного сервиса 3.1.E — Неизвестная причина: 1. Сохранить core dump если есть 2. Рестарт с детальным логированием: [service] --log-level=debug 3. Наблюдение 15 минут 4. Если повторяется — 
...[truncated 26 chars]

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill content materially differs from the stated product scope: it is an instruction-only IT/SRE methodology asset, not an AI monitoring skill for construction sites and infrastructure operations. This mismatch can mislead users, downstream agents, or procurement workflows into selecting an inapplicable skill, causing unsafe operational assumptions and incorrect automated recommendations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly states that it is oriented to US SaaS/IT services and not to construction sites, directly contradicting the broader manifest positioning. In a safety- or operations-adjacent environment, such contradiction increases the chance that users rely on irrelevant incident, alerting, and readiness guidance in the wrong domain.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented behavior is materially inconsistent with the manifest: instead of construction-site or IT-infrastructure monitoring, it describes an OpenClaw agent operations console with messaging, task orchestration, and automation. This mismatch is dangerous because users may approve or deploy the skill under false assumptions, enabling unrelated capabilities that expand access and attack surface beyond the stated purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

Creating system-level services and exposing the application through Tailscale are powerful host and network changes that are not justified by the manifest's stated purpose. In this context, the mismatch makes the behavior more dangerous because a supposedly simple monitoring skill is requesting privileged persistence and remote reachability, increasing the risk of unauthorized access and long-lived compromise.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 30)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про настройку

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про настройку

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 32)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про настройку

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про настройку
echo ""

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document is written entirely in Russian and the quick-start instructions specify Russian trigger phrases such as "дашборд", "мониторинг стройки", and "инцидент: [описание]". This indicates a language-specific interaction model without any stated opt-in, alternative locale, or justification that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill contains numerous shell commands and operational runbooks but declares no explicit tool scope or permissions boundary. In an agent environment, that can lead to over-broad tool access and unsafe execution of destructive or production-impacting commands when the skill is invoked.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description states «Русский язык нативно», presenting a fixed language constraint as a product differentiator. There is no user opt-in, multilingual option, or clear policy justification that this skill must operate only in Russian.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Trigger phrases such as dashboard/system-status style requests are broad and overlap with ordinary operational conversation. In an agent setting, that raises the chance of unintended invocation, which is more dangerous here because the skill also contains actionable production runbooks and escalation workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Alerting triggers are generic enough to match normal troubleshooting discussion, creating accidental activation risk. Because the skill pairs these triggers with guidance that can lead to operational changes or notifications, ambiguous matching could cause disruptive actions or misleading incident handling.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Incident playbook triggers like 'service is down' or 'what to do when [problem]' are very general and likely to appear during ordinary discussion of outages. In this skill, accidental invocation is particularly risky because the associated playbooks include restart, cleanup, rollback, blocking, and database-kill actions against production systems.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The natural-language comments and usage guidance are written in Russian only, including imperative text such as the build constraints and instructions. This can constitute a language/locale policy violation when no alternative language or opt-in is offered and no region-specific justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.