Back to skill

Security audit

AI LogicTune: Better decisions, less wasted time 0.1.4

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill that clearly asks to modify workspace instructions only when the user explicitly requests persistent activation.

Review the bundled AGENTS.md before activation because it will affect future sessions in that workspace. Prefer task-only use if you only want temporary guidance, and check the AGENTS.md diff before keeping the persistent merge.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly instructs users to install the skill and merge its principles into the active AGENTS.md, which changes persistent operating instructions across sessions, but it does not prominently warn about the security and behavioral implications of doing so. Because AGENTS.md affects future agent behavior, encouraging users to copy or merge remote instruction content without strong caution increases the risk of persistent prompt/instruction injection and accidental trust of unreviewed third-party logic.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
93% confidence
Finding

The skill explicitly authorizes a persistent modification to the active AGENTS.md based on a broad user phrase ('install and activate AI LogicTune') and instructs the agent to complete both steps without re-confirmation. This creates autonomous decision-making around state-changing actions in the workspace, which can lead to unintended persistent instruction changes if the destination context is mistaken or the user's request is ambiguous in practice.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
- When the requested task already uses helpers, pass the relevant principles in their task context and check their effective instructions where observable. Do not assume inheritance or edit their workspaces. Do not create helpers solely to check setup.
- Report the destination, version, merge result and observed loading status. If writing is unavailable, provide the proposed addition without claiming installation succeeded.

Loading, installing or invoking this skill alone does not authorize a persistent edit. A request to "install and activate AI LogicTune" authorizes the merge into the active AGENTS.md. Complete both steps without asking again unless the destination is unclear or a material conflict needs the user's decision.

## Check behavior when needed

Static analysis

No suspicious patterns detected.