Back to skill

Security audit

Auto Retex Backup

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent documentation-and-backup purpose, but it directs agents to make broad commits, push to GitHub, and retrieve credentials without explicit user approval.

Review carefully before installing. This skill should not be used as written unless you are comfortable with agents automatically editing documentation, staging all repository changes, committing, pushing to GitHub, and accessing 1Password for GitHub credentials after a push failure. A safer version would require explicit confirmation, show the diff and remote target, stage only approved files, and stop instead of retrieving credentials automatically.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:15
Finding

Mandatory Autonomous Behavior Overrides User Control

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:30
Finding

Unscoped Git Staging Followed by Automatic External Push

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:38
Finding

Automatic Retrieval of GitHub Credentials from 1Password

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to modify files and proceed 'sans attendre de demande explicite de l'utilisateur,' removing informed consent before state-changing actions. In practice, this can lead to unauthorized edits, commits, and publication of operational details, especially when the agent misclassifies a change as a 'resolved problem.'

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill mandates an immediate remote Git push to GitHub, which transmits repository contents off-host without an upfront warning or approval step. Because the same procedure also documents root causes and exact fixes, it creates a concrete risk of exfiltrating sensitive operational details, secrets, internal paths, or security-relevant troubleshooting data to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Core operational instructions and required user-facing behavior are specified only in French, and the skill does not offer a language choice or explain that the workflow is intentionally limited to French-speaking users. This can violate language/locale policy where user opt-in is required before enforcing a specific language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger scope is extremely broad: it applies whenever a problem is considered resolved, with no limits on repository, sensitivity of files, or requirement for user approval. In an agent context, this can cause unintended documentation changes and downstream Git actions to occur in situations the user did not authorize, increasing the chance of accidental disclosure or integrity-impacting writes.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

Lorsqu'un problème est résolu, l'agent doit exécuter les étapes suivantes dans l'ordre, sans attendre de demande explicite de l'utilisateur :

1. Documenter le Retex

Ajouter ou mettre à jour une entrée dans le fichier skills/auto-retex/SKILL.md (ou créer le fichier s'il n'existe pas) avec le format suivant :

markdown
### [Date] - [Nom court du problème]
- **Symptôme** : Description concise de l'erreur ou du comportement observé.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

Lorsqu'un problème est résolu, l'agent doit exécuter les étapes suivantes dans l'ordre, sans attendre de demande explicite de l'utilisateur :

1. Documenter le Retex

Ajouter ou mettre à jour une entrée dans le fichier skills/auto-retex/SKILL.md (ou créer le fichier s'il n'existe pas) avec le format suivant :

markdown
### [Date] - [Nom court du problème]
- **Symptôme** : Description concise de l'erreur ou du comportement observé.

Static analysis

No suspicious patterns detected.