Back to skill

Security audit

rython

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Rython toolchain guide, but it needs review because it includes kernel-module load and unload instructions without clear safety guardrails.

Use this skill only when you intentionally want the Rython toolchain. Do not let an agent run `make load`, `make unload`, `insmod`, `rmmod`, or install binaries into `~/.cargo/bin` without explicit approval; kernel-module experiments should be done in an isolated VM or disposable test system.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
# Rython: Python → Rust compilation

Convert Python source to native Rust using the **rython** toolchain. The point of the exercise is that the user writes Python and the tool does the rest — **keep all logic in `.py`, treat generated Rust as a build artifact, never hand-write Rust glue when a rython flag exists.** Minimal non-Python code shipped.

## Toolchain

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The markdown documents make load/unload operations for kernel modules without a visible safety warning about system instability, privilege requirements, or testing constraints. Because kernel-module loading can crash systems, taint kernels, or disrupt devices, presenting these steps as routine targets lowers the barrier to hazardous actions in an agent-assisted workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill advertises broad trigger phrases such as generic requests to compile Python or build kernel modules, which can cause the skill to activate in contexts the user did not specifically intend. In an agent setting, over-broad activation increases the chance of the model surfacing risky build, driver, or kernel-module guidance for adjacent requests that only partially match the trigger language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.