Back to skill

Security audit

debug detective

Security checks for vulnerabilities and agentic risk

Overview

This debugging skill is purpose-aligned, but some example commands can expose sensitive data or run unpinned tools if copied carelessly.

Install only as a debugging reference, and review any command before running it. Avoid real tokens in curl commands, protect and redact packet captures, prefer pinned or isolated package installs, and inspect scaffold.sh before letting it write VS Code settings or helper scripts into a project.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:879
Finding

Unpinned Third-Party Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:445, SKILL.md:486, SKILL.md:503, SKILL.md:879; references/profiling-tools-guide.md:9, references/profiling-tools-guide.md:59, references/profiling-tools-guide.md:75, references/profiling-tools-guide.md:128, references/profiling-tools-guide.md:156
Vulnerability Type: Supply-chain exposure through unpinned package installation and immediate package execution
Risk Level: Medium

Vulnerable Code

bash
npm install why-is-node-running
pip install py-spy
pip install memory-profiler
npx lighthouse https://example.com --output=html --output-path=report.html
bash
# references/profiling-tools-guide.md

# py-spy
pip install py-spy

# Scalene
pip install scalene

# memray
pip install memray

# 0x
npm install -g 0x

# clinic.js
npm install -g clinic

Technical Analysis

The instructions install packages without exact versions, hashes, lockfiles, or other integrity controls. The npx lighthouse command is particularly sensitive because npx can retrieve and immediately execute a package when it is not already installed locally.

Package installation and lifecycle scripts execute with the privileges of the invoking user. Global npm installation can also place executable files in shared command paths. Although the named packages are relevant to the Skill's declared debugging and profiling functionality, the installation method grants upstream package contents more trust than is strictly necessary.

This does not establish that any named package is malicious. The vulnerability is the absence of controls against compromised releases, unexpected future updates, registry manipulation, or dependency-chain compromise.

Attack Path

  1. An upstream package, one of its transitive dependencies, or a newly published package release is compromised.
  2. A user follows an unpinned pip install, npm install -g, or npx instru ...[truncated 1127 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin every recommended package to a reviewed exact version, such as lighthouse@X.Y.Z, py-spy==X.Y.Z, or equivalent.
  2. For npm tools, add the dependency to a project lockfile and invoke the locked local binary. Prefer npx --no-install lighthouse after a controlled installation.
  3. Avoid global npm installation. Install profiling tools in a dedicated project or isolated tooling environment.
  4. For Python tools, use an isolated virtual environment or pipx and require hash verification through a locked requirements file.
  5. Enable package-manager integrity and provenance checks, audit transitive dependencies, and retrieve packages only from explicitly trusted registries.
  6. Document that package installation must not be performed with sudo or from an administrator shell.
  7. Periodically review and update pinned versions through a controlled dependency-update process.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:727
Finding

TLS Certificate Verification Disabled in Network Debugging Example

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:727-728
Vulnerability Type: TLS certificate validation bypass
Risk Level: Medium

Vulnerable Code

bash
# Ignore TLS errors (debugging only!)
curl -k https://self-signed.example.com

Technical Analysis

The -k option, also known as --insecure, instructs curl not to verify the remote server's certificate chain or hostname. Encryption may still be negotiated, but the client no longer has reliable authentication of the server.

The example is labeled as debugging-only and uses a placeholder domain, which limits immediate exposure. However, users may substitute a real service URL or combine the command with authorization headers, cookies, request bodies, or other sensitive diagnostic data. In that context, disabling verification makes interception and active response modification possible.

The behavior is not required for general network debugging. A trusted development certificate authority or an explicitly supplied CA certificate provides the same diagnostic access without removing server authentication.

Attack Path

  1. A user adapts the example to a real development, staging, or production endpoint.
  2. The user runs the command on a network where an attacker can intercept or redirect traffic.
  3. Because -k suppresses certificate and hostname validation, curl accepts the attacker's certificate.
  4. The attacker terminates the TLS connection and proxies or modifies the request and response.
  5. Any attached bearer token, cookie, request payload, or sensitive response data can be observed or altered.

Impact Assessment

Exploitation may disclose API credentials, session material, diagnostic payloads, and response data transmitted in the affected request. An active attacker could also return manipulated diagnostic results, causing incorrect operational decisions or prompting further unsafe commands.

This command does not itself grant ...[truncated 255 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace curl -k with certificate-based trust configuration:
    bash
    curl --cacert ./development-ca.pem https://self-signed.example.com
    
  2. Install the development CA into a dedicated test trust store rather than disabling all certificate validation.
  3. Add an explicit warning that bearer tokens, cookies, credentials, personal data, and production payloads must never be sent when verification is disabled.
  4. If retaining the example is unavoidable, constrain it to an isolated local test environment and use a non-sensitive endpoint with synthetic data.
  5. Document certificate-chain inspection commands, such as openssl s_client, as the preferred way to diagnose certificate failures before changing client verification behavior.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents this as a general-purpose debugging help skill that provides methodological guidance and covers a wide range of debugging and profiling topics. The supplied code instead performs concrete filesystem-scaffolding actions in a target project: it detects project type and writes debugging-related configuration and helper scripts. That is a materially different primary behavior from an advisory/reference skill. While the generated files are debugging-related and overlap with a few declared topics (git bisect, structured logging, Node/Python debugger usage, some network timing), the code does not implement or provide the broad set of capabilities claimed in the description. Most importantly, the undeclared file-creation/modification behavior is a significant capability absent from the declared purpose, so this should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 700)May include surrounding context.

9. Network Debugging

9.1 curl deep dive

bash
# Verbose output — see full request/response headers

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill clearly contains shell-oriented guidance and environment-sensitive commands, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, that mismatch can cause the agent to apply shell-capable instructions without an upfront policy gate, increasing the chance of unsafe command execution during debugging workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says to activate the skill whenever a user needs help debugging, diagnosing, or profiling issues, which is a very broad condition likely to overlap with many ordinary troubleshooting requests. It does not define clear boundaries, specific trigger phrases, or exclusion conditions, increasing the risk of unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The packet-capture and HTTP debugging guidance can expose credentials, session cookies, API tokens, and private traffic contents, yet the section lacks explicit safety warnings or redaction guidance. In a debugging skill, users may copy these commands into production or shared environments and inadvertently capture sensitive data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 700)May include surrounding context.

9. Network Debugging

9.1 curl deep dive

bash
# Verbose output — see full request/response headers

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 704)May include surrounding context.

bash
# Verbose output — see full request/response headers
curl -v https://api.example.com/health

# Show timing breakdown
curl -w "\

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

The example demonstrates sending an Authorization: Bearer $TOKEN header in a debugging command, which can leak secrets through shell history, terminal logs, process inspection, or copied transcripts if used incautiously. In an agent-assisted debugging context, such examples normalize handling live credentials in ways that can expose them outside intended boundaries.

Content

Scanner excerpt · SKILL.md (reported line 715)May include surrounding context.

md
Total:      %{time_total}s\n\
  HTTP Code:  %{http_code}\n\
  Size:       %{size_download} bytes\n" \
  -o /dev/null -s https://api.example.com/health

# Test specific HTTP method with headers
curl -X POST https://api.example.com/data \

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

This same POST debugging example encourages use of bearer credentials in command lines against external endpoints, which can expose secrets and sensitive payloads during troubleshooting. The context makes it more dangerous because debugging often happens under pressure and in production-adjacent environments where operators may use real tokens.

Content

Scanner excerpt · SKILL.md (reported line 718)May include surrounding context.

md
-o /dev/null -s https://api.example.com/health

# Test specific HTTP method with headers
curl -X POST https://api.example.com/data \
  -H "Content-Type: application/json" \
  -H "Authorization: Bearer $TOKEN" \
  -d '{"key": "value"}' \

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

The Docker example invokes an image name without an explicit tag or digest, which can cause different images to be used over time and undermines reproducibility. While presented as debugging guidance, unpinned container references can expose users to unexpected or compromised images if copied into practice.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

Using npx lighthouse without pinning a version makes execution nondeterministic and may pull whatever package version is current at runtime. In an automated agent environment, this increases supply-chain risk and can introduce breaking changes or malicious upstream package compromise into a debugging session.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 596)May include surrounding context.

bash
# Record CPU profile of a process
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 608)May include surrounding context.

bash
# Record CPU profile of a process
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 203)May include surrounding context.

bash
# Record CPU profile of a process
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 221)May include surrounding context.

bash
# Record CPU profile of a process
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 244)May include surrounding context.

bash
# Record CPU profile of a process
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 245)May include surrounding context.

bash
# Record CPU profile of a process
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 599)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 605)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 206)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 209)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 212)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 215)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 216)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/profiling-tools-guide.md (reported line 239)May include surrounding context.

md
sudo perf record -g -p PID

# Record a specific command
sudo perf record -g -- node app.js

# Show report (interactive TUI)
sudo perf report

Static analysis

No suspicious patterns detected.