Back to skill

Security audit

Oejts Personality Tuner

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently runs a personality questionnaire and can update two workspace preference files, with no hidden networking, credential access, or destructive behavior found.

Before installing, understand that this skill can persistently add or replace managed personality-tuning blocks in USER.md and SOUL.md. Use the dry-run mode first and only apply if you want those assistant preference files changed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs use of a script that reads and writes workspace files, specifically proposing and applying updates to USER.md and SOUL.md, but the manifest declares no explicit tool scope or permissions boundary. This creates an avoidable least-privilege failure: an agent may invoke file-capable actions without a clear, reviewable declaration of what files are intended to be touched, increasing the chance of unintended or overly broad modification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The apply command performs file writes that modify workspace documentation files directly via write_text(). While the command name suggests updates, the code provides no confirmation prompt or explicit warning immediately before making persistent changes, and these writes can overwrite existing managed blocks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.