Back to skill

Security audit

Estimator Pro

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Russian construction-estimating instruction package with no hidden exfiltration or persistence found, but its helper scripts are malformed and its estimates should be independently verified.

Install only if you want a Russian-language estimating assistant and are comfortable reviewing its outputs. Treat generated prices, Russian norms, KS-2/KS-3 forms, and audit recommendations as drafts requiring current official sources and a qualified estimator or legal/commercial review. Do not rely on the bundled shell scripts until they are fixed and reviewed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
build.sh:11
Finding

PowerShell Command Injection Through Unvalidated Version Argument

Content
View full analysis
/dev/null 2>&1 || command -v powershell >/dev/null 2>&1; then PSH="$(command -v powershell.exe 2>/dev/null || command -v powershell)" WIN_SRC="$(cygpath -w "$STAGE_DIR" 2>/dev/null || echo "$STAGE_DIR")" WIN_OUT="$(cygpath -w "$OUT_DIR/$ZIP_NAME" 2>/dev/null || echo "$OUT_DIR/$ZIP_NAME")" "$PSH" -NoProfile -Command "Compress-Archive -Path '${WIN_SRC}' -DestinationPath '${WIN_OUT}' -Force" echo " packed via: powershell Compress-Archive" ``` The same unsafe construction is also used by the `Expand-Archive` PowerShell fallback on line 43: ```bash "$PSH2" -NoProfile -Command "Expand-Archive -Path '${WIN_ZIP}' -DestinationPath '${WIN_DEST}' -Force" ``` ### Technical Analysis The first positional argument is assigned directly to `VER` without format validation. This value is subsequently embedded in directory and ZIP names and therefore reaches `WIN_SRC`, `WIN_OUT`, and `WIN_ZIP`. These paths are interpolated into textual PowerShell programs passed through `powershell -Command`. Although Bash quotes the overall command argument, the attacker-controlled values are placed inside PowerShell single-quoted string literals. A version containing a single quote followed by PowerShell syntax can terminate the intended string literal, introduce an additional statement, and comment out or otherwise neutralize the remaining text. Bash argument quoting only protects the transi ...[truncated 1972 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (79)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill performs construction estimating and related document/calculation tasks. However, the supplied code does not implement any estimating, BOQ, KS-2/KS-3 handling, defect inspection, material calculation, or estimate audit logic. Its purpose is operational/dev tooling: building a release ZIP from source files and optionally validating it with a smoke test. This is a materially different primary purpose from the declared skill behavior, so it is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents the skill as performing construction-estimating tasks. However, the supplied code chunk only performs local installation and setup of the skill package. While installation can be a supporting detail for distribution, this specific code does not actually carry out any of the declared estimating functions, and its primary purpose is materially different from the declared operational purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says the skill provides construction estimating functionality for the Russian market. However, the supplied code chunk only validates the skill package layout and metadata for release/readiness: it inspects files, YAML-like manifest fields, trigger counts, tags, marketing assets, and config sections. There is no logic for generating estimates, BOQ, KS-2/KS-3 documents, defect inspection, material calculations, or estimate auditing. This is a material purpose mismatch, not merely supporting implementation detail, because the code’s primary behavior is QA/compliance testing of the skill package rather than construction estimating.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
79% confidence
Finding

The build script creates a ZIP, extracts it to a temporary directory, and then executes test/smoke-test.sh from the freshly unpacked archive. That turns packaging into a code-execution step over archive contents, so if source files or packaged test content are modified by an attacker or untrusted contributor, running build.sh will execute attacker-controlled shell code on the builder machine.

Content

Scanner excerpt · build.sh (reported line 43)May include surrounding context.

sh
if command -v unzip >/dev/null 2>&1; then echo "Contents:" unzip -l "$OUT_DIR/$ZIP_NAME" | tail -35
elif command -v 7z >/dev/null 2>&1; then echo "Contents:" 7z l "$OUT_DIR/$ZIP_NAME" | tail -35
fi # Smoke-test на свежераспакованном ZIP (пропускается если SMOKE_TEST=0)
if [[ "${SMOKE_TEST:-1}" != "0" ]]; then echo "" echo "==> Running smoke-test on fresh ZIP..." TEST_DIR="$(mktemp -d)" if command -v unzip >/dev/null 2>&1; then unzip -q "$OUT_DIR/$ZIP_NAME" -d "$TEST_DIR" elif command -v 7z >/dev/null 2>&1; then 7z x "$OUT_DIR/$ZIP_NAME" -o"$TEST_DIR" -y >/dev/null elif command -v powershell.exe >/dev/null 2>&1 || command -v powershell >/dev/null 2>&1; then PSH2="$(command -v powershell.exe 2>/dev/null || command -v powershell)" WIN_ZIP="$(cygpath -w "$OUT_DIR/$ZIP_NAME" 2>/dev/null || echo "$OUT_DIR/$ZIP_NAME")" WIN_DEST="$(cygpath -w "$TEST_DIR" 2>/dev/null || echo "$TEST_DIR")" "$PSH2" -NoProfile -Command "Expand-Archive -Path '${WIN_ZIP}' -DestinationPath '${WIN_DEST}' -Force" fi cd "$TEST_DIR/${SLUG}-v${VER}" if [[ -f test/smoke-test.sh ]]; then bash test/smoke-test.sh || { echo "SMOKE-TEST FAILED"; rm -rf "$TEST_DIR"; exit 1; } else echo " (smoke-test.sh not found — skipped)" fi rm -rf "$TEST_DIR"
fi

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill content is explicitly centered on US construction estimating standards and pricing sources such as CSI MasterFormat and RSMeans, while the declared skill purpose is estimating for the Russian market. This mismatch can cause users to rely on materially incorrect regulatory, costing, and documentation frameworks in a domain where accuracy affects contracts, budgets, and compliance.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The limitations section directly states that Russia is not covered and that Russian pricing procedures and standards are unsupported, which contradicts the claimed Russian-market capability. In practice, this creates a strong risk of user deception or operational misuse because the skill may be selected precisely for a market it admits it cannot handle.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation materially misrepresents the skill's capabilities relative to the stated Russian-market estimating purpose: it is primarily an open/US-oriented estimator with limited Russian regional coefficients, while lacking official Russian pricing bases and core Russian output formats. This can mislead users into relying on unsuitable estimates, causing procurement, compliance, or financial errors in a construction workflow.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 30)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 32)May include surrounding context.

sh
cp "$SRC_DIR/SKILL.md" "$SRC_DIR/config.yaml" "$SRC_DIR/README.md" "$SRC_DIR/install.sh" "$SRC_DIR/.env.example" "$TARGET/"
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · install.sh (reported line 31)May include surrounding context.

sh
cp -r "$SRC_DIR/docs" "$SRC_DIR/examples" "$SRC_DIR/proof" "$SRC_DIR/test" "$TARGET/"
chmod +x "$TARGET/install.sh" "$TARGET/test/smoke-test.sh" 2>/dev/null || true
echo "[✓] Файлы скопированы в $TARGET" # 3. Создать .env из шаблона если нет
if [[ ! -f "$TARGET/.env" ]]; then cp "$SRC_DIR/.env.example" "$TARGET/.env" echo "[✓] Создан $TARGET/.env (заполнять только если нужны интеграции)"
else echo "[i] $TARGET/.env уже существует — не перезаписываю"
fi # 4. Напомнить про OBLIGATORY-поля
echo ""

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The changelog content is written in Russian, including explanatory notes, with no indication that the skill is region-specific or that users may choose another language. This can violate language/locale policy when a skill implicitly requires a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill defines very broad trigger phrases like 'смета', 'материалы', 'работы', 'сравни', and 'график' that are common words in ordinary construction conversations. This can cause accidental activation of the wrong mode, leading the agent to perform unintended estimating, document-generation, or audit workflows on user input that was not meant as a command.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill’s instructions and role definition are written entirely in Russian and explicitly frame the assistant around the Russian market, including "Говоришь на языке прорабов, заказчиков и проверяющих." There is no indication that users may choose another language or locale, so the skill appears to impose a specific language/locale by default.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language comments and usage text are written exclusively in Russian, including emphatic instructions, with no indication that another language is supported or that Russian is required for a region-specific reason. This creates a language/locale policy issue because the file effectively imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list includes generic phrases such as "Estimate this project," "Check my quantities," "Review my estimate," and "Generate bid summary." In a markdown skill description, these broad natural-language commands do not define clear boundaries or exclusions, so the skill could be matched unintentionally during normal conversation about construction work.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file claims Russian regional support but later admits it lacks official Russian pricing sources and standard Russian estimating formats. This internal contradiction creates a deceptive reliability signal that may cause users to overtrust the skill for Russia-specific estimating, leading to invalid cost calculations or noncompliant deliverables.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.