Back to skill

Security audit

Sparkey

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed temporary SSH-access tool, but it includes root-level account management and command-restriction weaknesses that users should review before installing.

Install only if you are comfortable running root-level SSH access tooling. Prefer the default diagnostic profile, avoid the full profile, do not add keys to root unless absolutely necessary, protect the CA private key, and review/fix the remediation dispatcher and revoke-access.sh --user validation before using this on important hosts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/grant-access.sh:350
Finding

Remediation Profile Allows Arbitrary Command Execution Through Allowed Interpreters

Content
View full analysis
/dev/null || printf '%s' "${arg}") local matched=false for prefix in "${allowed_prefixes[@]}"; do if [[ "${resolved}" == "${prefix}"* ]]; then matched=true break fi done if [[ "${matched}" == false ]]; then log_event "BLOCKED" printf 'ERROR: Path '\''%s'\'' outside allowed directories.\n' "${arg}" exit 1 fi fi done } ``` The remediation dispatch profile then permits both remote download tools and general-purpose interpreters: ```bash ALLOWED_READ_PATHS=("/var/log/" "/proc/" "/sys/" "/run/" "/tmp/" "/etc/" "/home/") ALLOWED_WRITE_PATHS=("/etc/" "/var/" "/tmp/" "/home/") dispatch() { local sub case "${COMMAND}" in uptime|hostname|whoami|id|w|uname|df|free|lsblk|mount|ps|kill|pkill|journalctl|dmesg|ss|netstat|lsof|curl|wget) run_cmd ;; dig|nslookup|ping|traceroute|mtr) run_cmd ;; top) if [[ " ${ARGS[*]:-} " == *" -b "* ]] || [[ "${ARGS[0]:-}" == "-bn"* ]]; then run_cmd else log_event "DENIED"; printf 'ERROR: '\''top'\'' requires -b (batch mode).\n'; exit 1 fi ;; cat|head|tail|less|wc|grep|sed|awk|ls) check_paths ALLOWED_READ_PATHS "${ARGS[@]}" run_cmd ;; cp|mv| ...[truncated 2741 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/revoke-access.sh:30
Finding

Revocation Script Can Delete an Arbitrary Local User Account

Content
View full analysis
/dev/null && printf ' Locked.\n' || printf ' Already locked or not found.\n' printf ' [2/7] Terminating active sessions...\n' if pkill -u "${target_user}" 2>/dev/null; then sleep 2 pkill -9 -u "${target_user}" 2>/dev/null || true printf ' Sessions terminated.\n' else printf ' No active sessions found.\n' fi printf ' [3/7] Removing file protections...\n' local target_home target_home=$(getent passwd "${target_user}" 2>/dev/null | cut -d: -f6) || target_home="/home/${target_user}" chattr -i "${target_home}/.ssh/authorized_keys" 2>/dev/null || true chattr -i "${target_home}/.ssh" 2>/dev/null || true printf ' Done.\n' printf ' [4/7] Archiving session logs...\n' mkdir -p "${ARCHIVE_DIR}" if [[ -f "${LOG_FILE}" ]] && grep -q "${target_sid}" "${LOG_FILE}" 2>/dev/null; then grep "${target_sid}" "${LOG_FILE}" > "${ARCHIVE_DIR}/${target_sid}.log" printf ' Archived to %s/%s.log\n' "${ARCHIVE_DIR ...[truncated 2648 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (91)

Chaining Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

Debian / Ubuntu:

bash
sudo apt-get update && sudo apt-get install -y openssh-client coreutils passwd at e2fsprogs procps

Alpine Linux:

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The documented workflow instructs appending an SSH public key into authorized_keys, which grants remote login capability to the target account. Even though the intent is legitimate temporary access, key installation is inherently credential provisioning and becomes dangerous if misapplied to privileged accounts, wrong hosts, or without strict expiry and audit.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

  1. Ask for the connect username — default to the current user on the target, not root. Ask: "What username should I connect as? (default: your current user)". If the task requires root, inform the user: "This task requires root. Please add the key to root's authorized_keys (or use sudo)."
  2. Present public key with expiry — provide a one-liner with expiry-time for crash safety. The one-liner creates ~/.ssh/ if absent and is tailored to the target username:
    text
    mkdir -p ~/.ssh && chmod 700 ~/.ssh && echo 'expiry-time="YYYYMMDDHHMMSS" ssh-ed25519 AAAA... agent-session-SID' >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys
    
    expiry-time (OpenSSH 8.2+) ensures the key is server-rejected after the timestamp, even if the agent crashes and never cleans up.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
93% confidence
Finding

The YARA match is contextually legitimate but still points to a powerful capability: injecting an SSH key into authorized_keys to establish access. In a skill intended to grant remote shell access, this is expected behavior, yet it remains dangerous because the same mechanism is indistinguishable from persistence/backdoor tradecraft if restrictions fail, expiry is ignored, or the wrong account is targeted.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

s? (default: your current user)"*. If the task requires root, inform the user: "This task requires root. Please add the key to root's authorized_keys (or use sudo)." 5. Present public key with expiry — provide a one-liner with expiry-time for crash safety. The one-liner creates ~/.ssh/ if absent and is tailored to the target username:

text
mkdir -p ~/.ssh && chmod 700 ~/.ssh && echo 'expiry-time="YYYYMMDDHHMMSS" ssh-ed25519 AAAA... agent-session-SID' >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys

expiry-time (OpenSSH 8.2+) ensures the key is server-rejected after the timestamp, even if the agent crashes and never cleans up.

Important: The one-liner must run as the target user so ~/.ssh/ resolves to the correct home directory. If adding the key for a different account (e.g., root), either su - root first or use the absolute path (e.g., /root/.ssh/authorized_keys). 6. User adds the key — the user decides where and how to g

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The text explicitly discusses adding the key to another account such as root via /root/.ssh/authorized_keys. This materially increases risk because misconfiguration or misuse can directly grant privileged remote shell access.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

text
   `expiry-time` (OpenSSH 8.2+) ensures the key is server-rejected after the timestamp, even if the agent crashes and never cleans up.

   **Important:** The one-liner must run as the target user so `~/.ssh/` resolves to the correct home directory. If adding the key for a different account (e.g., root), either `su - root` first or use the absolute path (e.g., `/root/.ssh/authorized_keys`).
6. **User adds the key** — the user decides where and how to grant access (maintains control).
7. **Verify connection** — connect as the agreed username: `ssh -i /tmp/agent_access_key USER@TARGET 'echo ok'`
8. **Schedule dead-man cleanup** — immediately after connecting, schedule automatic key removal on the target:

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

  1. Verify connection — connect as the agreed username: ssh -i /tmp/agent_access_key USER@TARGET 'echo ok'
  2. Schedule dead-man cleanup — immediately after connecting, schedule automatic key removal on the target:
    bash
    echo "sed -i '/agent-session-SID/d' ~/.ssh/authorized_keys" | at now + 4 hours
    
    This fires independently of the agent. If the agent finishes early, it cancels the job and cleans up itself.
  3. Run fast recon — OS, key packages, screen/tmux availability. Under 10 seconds.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 166)May include surrounding context.

md
sudo bash scripts/revoke-access.sh --session SESSION_ID

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 308)May include surrounding context.

md
sudo bash scripts/revoke-access.sh --session SESSION_ID

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 310)May include surrounding context.

md
sudo bash scripts/revoke-access.sh --session SESSION_ID

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

md
sudo bash scripts/revoke-access.sh --session SESSION_ID

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

md
sudo bash scripts/revoke-access.sh --session SESSION_ID

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 481)May include surrounding context.

md
sudo bash scripts/revoke-access.sh --session SESSION_ID

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 423)May include surrounding context.

md
4. **Scope creep** — start with `diagnostic`; escalate to `remediation` or `full` only when explicitly needed

5. **Symlink traversal** — path validation resolves symlinks via `readlink -f` before checking directory prefixes; a symlink from `/var/log/evil` → `/etc/shadow` is resolved and rejected

### Break-Glass Recovery

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The manifest understates sensitivity by listing writes to authorized_keys while simultaneously claiming no data leaves the local machine and no external endpoints are involved. Because authorized_keys modification enables remote authentication on another system, inaccurate disclosure can cause reviewers to underestimate credential and lateral-access risk.

Content

Scanner excerpt · SKILL.md (reported line 497)May include surrounding context.

md
| **Environment variables** | None accessed |
| **External endpoints** | None — this skill makes zero network calls |
| **Local files read** | `/etc/passwd` (user lookup), `/etc/ssh/agent_ca` (CA signing), agent public key (if provided) |
| **Local files written** | `/etc/ssh/agent_ca{,.pub}` (setup-ca.sh), `/usr/local/bin/agent-support-shell-SID` (per-session), `/usr/local/sbin/agent-cleanup-SID.sh` (per-session), `/tmp/agent_session_SID{,.pub,-cert.pub}` (ephemeral keys), `/var/log/agent-support.log` (audit), `~agent/.ssh/authorized_keys` (no-ca mode) |
| **OS state mutated** | Creates/deletes Linux user accounts (`useradd`/`userdel`), schedules cleanup timers (`at`/`systemd-run`) |
| **Data transmitted** | No data leaves the local machine. All operations are local to the host. |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · diagrams/sparkey_access_lifecycle.svg (reported line 4)May include surrounding context.

text
<svg width="100%" viewBox="0 0 680 740" xmlns="http://www.w3.org/2000/svg">
<defs><marker id="arrow" viewBox="0 0 10 10" refX="8" refY="5" markerWidth="6" markerHeight="6" orient="auto-start-reverse"><path d="M2 1L8 5L2 9" fill="none" stroke="context-stroke" stroke-width="1.5" stroke-linecap="round" stroke-linejoin="round"/></marker><mask id="imagine-text-gaps-b07zxx" maskUnits="userSpaceOnUse"><rect x="0" y="0" width="680" height="740" fill="white"/><rect x="138.3600311279297" y="12.305451393127441" width="63.27993392944336" height="21.47235679626465" fill="black" rx="2"/><rect x="455.3648681640625" y="12.305451393127441" width="109.27030181884766" height="21.47235679626465" fill="black" rx="2"/><rect x="107.81661224365234" y="61.26382064819336" width="124.36676788330078" height="21.472354888916016" fill="black" rx="2"/><rect x="113.029541015625" y="80.44438934326172" width="113.94091033935547" height="19.111226081848145" fill="black" rx="2"/><rect x="85.1313247680664" y="137.26382446289062" width="169.73733520507812" height="21.472354888916016" fill="black" rx="2"/><rect x="123.93500518798828" y="156.4443817138672" width="92.1299819946289" height="19.111226081848145" fill="black" rx="2"/><rect x="97.47929382324219" y="213.26382446289062" width="145.04141235351562" height="21.472354888916016" fill="black" rx="2"/><rect x="98.98451232910156" y="232.4443817138672" width="142.0309600830078" height="19.111226081848145" fill="black" rx="2"/><rect x="441.0025634765625" y="213.26382446289062" width="137.9949188232422" height="21.472354888916016" fill="black" rx="2"/><rect x="436.9259338378906" y="232.4443817138672" width="146.148193359375" height="19.111226081848145" fill="black" rx="2"/><rect x="123.3152084350586" y="299.2638244628906" width="93.36957550048828" height="21.472354888916016" fill="black" rx="2"/><rect x="103.78424835205078" y="318.44439697265625" width="132.43150329589844" height="19.111226081848145" fill="black" rx="2"/><rect x="99.95110321044922" y="375.2
...[truncated 26 chars]

Hidden Instructions

High
Category
Prompt Injection
Confidence
87% confidence
Finding

The SVG embeds interactive onclick handlers that call sendPrompt(...) with prewritten prompts. If this diagram is rendered in a UI that wires sendPrompt into an agent/chat workflow, a user click can inject unreviewed prompts into the agent context, creating a prompt-injection surface even though the content appears instructional.

Content

Scanner excerpt · diagrams/sparkey_access_lifecycle.svg (reported line 16)May include surrounding context.

text
<text x="170" y="90" text-anchor="middle" dominant-baseline="central" style="fill:rgb(175, 169, 236);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:12px;font-weight:400;text-anchor:middle;dominant-baseline:central">nc -z -w 2 target 22</text>
</g>

<!-- Step 2: Generate keypair -->
<g onclick="sendPrompt('What key type does sparkey use?')" style="fill:rgb(0, 0, 0);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto">
<rect x="60" y="128" width="220" height="56" rx="8" stroke-width="0.5" style="fill:rgb(60, 52, 137);stroke:rgb(175, 169, 236);color:rgb(255, 255, 255);stroke-width:0.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>
<text x="170" y="148" text-anchor="middle" dominant-baseline="central" style="fill:rgb(206, 203, 246);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:14px;font-weight:500;text-anchor:middle;dominant-baseline:central">2. Generate Ed25519 key</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · diagrams/sparkey_access_lifecycle.svg (reported line 32)May include surrounding context.

text
</g>
<line x1="170" y1="184" x2="170" y2="202" marker-end="url(#arrow)" style="fill:none;stroke:rgb(156, 154, 146);color:rgb(255, 255, 255);stroke-width:1.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>

<!-- Arrow to operator -->
<line x1="280" y1="232" x2="398" y2="232" marker-end="url(#arrow)" style="fill:none;stroke:rgb(156, 154, 146);color:rgb(255, 255, 255);stroke-width:1.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>

<!-- Step 4: User adds key -->

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · diagrams/sparkey_access_lifecycle.svg (reported line 42)May include surrounding context.

text
<text x="510" y="242" text-anchor="middle" dominant-baseline="central" style="fill:rgb(239, 159, 39);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:12px;font-weight:400;text-anchor:middle;dominant-baseline:central">User controls placement</text>
</g>

<!-- Step 5: Verify connection -->
<g style="fill:rgb(0, 0, 0);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto">
<rect x="60" y="290" width="220" height="56" rx="8" stroke-width="0.5" style="fill:rgb(60, 52, 137);stroke:rgb(175, 169, 236);color:rgb(255, 255, 255);stroke-width:0.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>
<text x="170" y="310" text-anchor="middle" dominant-baseline="central" style="fill:rgb(206, 203, 246);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:14px;font-weight:500;text-anchor:middle;dominant-baseline:central">5. Verify SSH</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · diagrams/sparkey_access_lifecycle.svg (reported line 58)May include surrounding context.

text
</g>
<line x1="170" y1="346" x2="170" y2="364" marker-end="url(#arrow)" style="fill:none;stroke:rgb(156, 154, 146);color:rgb(255, 255, 255);stroke-width:1.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>

<!-- Step 7: Shared session -->
<g style="fill:rgb(0, 0, 0);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto">
<rect x="60" y="442" width="220" height="56" rx="8" stroke-width="0.5" style="fill:rgb(8, 80, 65);stroke:rgb(93, 202, 165);color:rgb(255, 255, 255);stroke-width:0.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>
<text x="170" y="462" text-anchor="middle" dominant-baseline="central" style="fill:rgb(159, 225, 203);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:14px;font-weight:500;text-anchor:middle;dominant-baseline:central">7. Create shared session</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · diagrams/sparkey_access_lifecycle.svg (reported line 75)May include surrounding context.

text
<text x="510" y="480" text-anchor="middle" dominant-baseline="central" style="fill:rgb(239, 159, 39);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:12px;font-weight:400;text-anchor:middle;dominant-baseline:central">screen -x agent-work</text>
</g>

<!-- Step 9: Work -->
<g style="fill:rgb(0, 0, 0);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto">
<rect x="60" y="518" width="220" height="56" rx="8" stroke-width="0.5" style="fill:rgb(60, 52, 137);stroke:rgb(175, 169, 236);color:rgb(255, 255, 255);stroke-width:0.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>
<text x="170" y="538" text-anchor="middle" dominant-baseline="central" style="fill:rgb(206, 203, 246);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:14px;font-weight:500;text-anchor:middle;dominant-baseline:central">9. Execute diagnostics</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · diagrams/sparkey_defense_in_depth.svg (reported line 7)May include surrounding context.

text
<text x="340" y="30" text-anchor="middle" style="fill:rgb(250, 249, 245);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:14px;font-weight:500;text-anchor:middle;dominant-baseline:auto">Four-layer defense in depth</text>
<text x="340" y="48" text-anchor="middle" style="fill:rgb(194, 192, 182);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:12px;font-weight:400;text-anchor:middle;dominant-baseline:auto">Each layer fails independently — no single point of failure</text>

<!-- Layer 1 -->
<g style="fill:rgb(0, 0, 0);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto">
<rect x="40" y="74" width="600" height="86" rx="14" stroke-width="0.5" style="fill:rgb(60, 52, 137);stroke:rgb(175, 169, 236);color:rgb(255, 255, 255);stroke-width:0.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>
<text x="60" y="102" dominant-baseline="central" style="fill:rgb(206, 203, 246);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:14px;font-weight:500;text-anchor:start;dominant-baseline:central">Layer 1 — SSH certificate TTL</text>

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · diagrams/sparkey_defense_in_depth.svg (reported line 25)May include surrounding context.

text
<text x="540" y="228" text-anchor="middle" dominant-baseline="central" style="fill:rgb(93, 202, 165);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:12px;font-weight:400;text-anchor:middle;dominant-baseline:central">Kernel denies login</text>
</g>

<!-- Layer 3 -->
<g style="fill:rgb(0, 0, 0);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto">
<rect x="40" y="278" width="600" height="86" rx="14" stroke-width="0.5" style="fill:rgb(113, 43, 19);stroke:rgb(240, 153, 123);color:rgb(255, 255, 255);stroke-width:0.5px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:16px;font-weight:400;text-anchor:start;dominant-baseline:auto"/>
<text x="60" y="306" dominant-baseline="central" style="fill:rgb(245, 196, 179);stroke:none;color:rgb(255, 255, 255);stroke-width:1px;stroke-linecap:butt;stroke-linejoin:miter;opacity:1;font-family:&quot;Anthropic Sans&quot;, -apple-system, &quot;system-ui&quot;, &quot;Segoe UI&quot;, sans-serif;font-size:14px;font-weight:500;text-anchor:start;dominant-baseline:central">Layer 3 — Safe command dispatch</text>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 496)May include surrounding context.

md
printf '[1/5] Checking for agent_support_* accounts...\n'
stale_users=$(getent passwd 2>/dev/null | grep '^agent_support_' | cut -d: -f1)
if [[ -z "${stale_users}" ]]; then
  stale_users=$(grep '^agent_support_' /etc/passwd 2>/dev/null | cut -d: -f1)
fi
if [[ -n "${stale_users}" ]]; then
  for u in ${stale_users}; do

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit.sh (reported line 21)May include surrounding context.

sh
printf '[1/5] Checking for agent_support_* accounts...\n'
stale_users=$(getent passwd 2>/dev/null | grep '^agent_support_' | cut -d: -f1)
if [[ -z "${stale_users}" ]]; then
  stale_users=$(grep '^agent_support_' /etc/passwd 2>/dev/null | cut -d: -f1)
fi
if [[ -n "${stale_users}" ]]; then
  for u in ${stale_users}; do

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/revoke-access.sh (reported line 49)May include surrounding context.

sh
printf '[1/5] Checking for agent_support_* accounts...\n'
stale_users=$(getent passwd 2>/dev/null | grep '^agent_support_' | cut -d: -f1)
if [[ -z "${stale_users}" ]]; then
  stale_users=$(grep '^agent_support_' /etc/passwd 2>/dev/null | cut -d: -f1)
fi
if [[ -n "${stale_users}" ]]; then
  for u in ${stale_users}; do

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/revoke-access.sh (reported line 172)May include surrounding context.

sh
printf '[1/5] Checking for agent_support_* accounts...\n'
stale_users=$(getent passwd 2>/dev/null | grep '^agent_support_' | cut -d: -f1)
if [[ -z "${stale_users}" ]]; then
  stale_users=$(grep '^agent_support_' /etc/passwd 2>/dev/null | cut -d: -f1)
fi
if [[ -n "${stale_users}" ]]; then
  for u in ${stale_users}; do

Static analysis

No suspicious patterns detected.