Back to skill

Security audit

SMFOI-KERNEL

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed every-turn orientation and local audit-log helper with no executable code, network access, credentials, or system-level authority.

Before installing, be comfortable with a skill that activates on every interaction and keeps a local audit log under ./memory/kernel/state.md. Review or clear that file if you do not want orientation outcomes retained across turns.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is configured with an every_turn trigger, which causes it to activate on all interactions regardless of user intent. This expands the skill’s reach, increases the chance of unintended side effects such as repeated logging or policy interference, and makes any future unsafe behavior in the skill run far more often than necessary.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
60% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
1\. \*\*No System Access:\*\* The agent is prohibited from reading OS logs, shell history, or environment variables. "Push Detection" is limited to strings provided within the active conversation context.

2\. \*\*Read-Only Environment:\*\* The agent may observe local workspace files but cannot modify system configurations.

3\. \*\*Mandatory Approval:\*\* Level 3 (Recursion) proposals are \*\*non-executable\*\*. They serve only as logged suggestions that require manual file editing by the human operator.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs the agent to record outcomes to ./memory/kernel/state.md, which is a persistent file write, but this modification is not surfaced as a clear user-facing warning at the point of behavior. Silent or ambient persistence can surprise users, create privacy concerns, and lead to repeated accumulation of conversation-derived data across turns.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This plain-text skill file describes a mandatory behavior ('Before responding, perform this mental check') but does not define when the skill is invoked or what exact triggers activate it. Without explicit scope, trigger phrases, or exclusion conditions, the instructions are overly broad and could be applied to ordinary interactions unintentionally.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is configured with an every_turn trigger, which causes it to run on every interaction rather than only in narrowly scoped contexts. This broad invocation increases the attack surface and the chance of unintended interference, prompt injection exposure, or policy-shaping behavior across unrelated conversations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.