Back to skill

Security audit

MLX Swift LM Expert

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only skill for using MLX Swift language-model APIs, with expected model downloads, local model/data access, and cache/checkpoint examples disclosed in context.

Before using the examples, expect outbound downloads from HuggingFace and local caching of large model files. Treat downloaded models, prompt-cache files, adapter checkpoints, and training datasets as potentially sensitive, and pin trusted model IDs or revisions when reproducibility or supply-chain control matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Unvalidated Output Injection

High
Category
Output Handling
Confidence
90% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · references/concurrency.md (reported line 238)May include surrounding context.

swift
await container.perform { context in
    let result = context.model(input)
    eval(result)  // Evaluate before crossing boundary
    return result.item(Float.self)  // Return primitive
}

Unvalidated Output Injection

High
Category
Output Handling
Confidence
90% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · references/concurrency.md (reported line 275)May include surrounding context.

swift
await container.perform { context in
    let result = context.model(input)
    eval(result)  // Evaluate before crossing boundary
    return result.item(Float.self)  // Return primitive
}

Unvalidated Output Injection

High
Category
Output Handling
Confidence
90% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · skill.md (reported line 349)May include surrounding context.

swift
await container.perform { context in
    let result = context.model(input)
    eval(result)  // Evaluate before crossing boundary
    return result.item(Float.self)  // Return primitive
}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/model-container.md (reported line 52)May include surrounding context.

md
// Access configuration (async property)
let config = await container.configuration

// Access tokenizer
let tokenizer = await container.tokenizer

// Access processor

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/model-container.md (reported line 199)May include surrounding context.

md
1. **Download**: Model weights fetched from HuggingFace (cached locally)
2. **Parse config.json**: Determine `model_type` and configuration
3. **Create model**: TypeRegistry maps type to initializer
4. **Load weights**: `.safetensors` files loaded into model
5. **Load tokenizer**: From `tokenizer.json` / `tokenizer_config.json`
6. **Load EOS tokens**: From `generation_config.json` (overrides config.json)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly states that models are downloaded from HuggingFace automatically, but it does not warn the user that invoking the example will trigger outbound network access and fetch third-party artifacts. In an agent skill context, hidden network access can violate operator expectations, bypass allowlist controls, and increase supply-chain risk if remote model identifiers are changed or untrusted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes examples for saving and loading prompt caches to a file and notes that metadata is stored in the .safetensors file. Because prompt caches and metadata can contain user-derived content, the documentation should warn that serialization persists data to disk and may have privacy implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file documents adapter.fuse(with:) as a permanent merge and says weights are "baked in," but it does not include a clear caution advising users that this changes model state and may require reloading the base model to undo. For markdown files, destructive or integrity-affecting behaviors should be accompanied by an explicit warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file includes executable example code that reads training data from local .txt and .jsonl files, but the surrounding documentation does not explicitly warn users that the example accesses filesystem contents. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or privacy; here the example processes user-provided local data without any disclosure note.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.