Back to skill

Security audit

Security Scan

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent lightweight security-scanning skill, but its scan output can include sensitive matched lines and should be kept private.

Install only if you want a lightweight local scanner and understand it is not comprehensive. Treat its output as sensitive, especially when scanning repositories that may contain real tokens, and manually review any findings before making publish or install decisions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scan.sh:32
Finding

Detected secrets and attacker-controlled scan results are disclosed verbatim

Content
View full analysis
/dev/null || true) if [ -n "$SECRETS" ]; then echo "WARNING: Potential hardcoded secrets found:" echo "$SECRETS" else echo "OK: No obvious hardcoded secrets detected." fi ``` The same unsafe rendering pattern is used for dangerous-call matches and world-writable filenames: ```bash if [ -n "$DANGEROUS_CALLS" ]; then echo "WARNING: Potential dangerous function calls found:" echo "$DANGEROUS_CALLS" fi ``` ```bash if [ -n "$WORLD_WRITABLE" ]; then echo "WARNING: World-writable files found:" echo "$WORLD_WRITABLE" fi ``` ### Technical Analysis Recursive `grep -n` output includes the matching source line in full. When that line contains a credential matching one of the scanner's expressions, `echo "$SECRETS"` reproduces the complete credential in terminal output. This can propagate sensitive material from the source tree into CI logs, audit transcripts, agent context, terminal history captures, or other retained output. The target project also controls matched source text and filenames. Printing these values without escaping non-printable characters permits embedded terminal control sequences, carriage returns, or multiline text to alter the visual presentation of results. This is an output-injection concern rather than shell command injection: quoting prevents ordinary shell expansion, but it does not make terminal control characters safe. ### Attack Path 1. A target repository contains a real credential matching on ...[truncated 1056 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/scan.sh:17
Finding

User-controlled target paths can be interpreted as command-line options

Content
View full analysis
/dev/null || true) ``` ```bash SECRETS=$(grep -rEn 'AIza[0-9A-Za-z_-]{35}|sk-[0-9A-Za-z]{32,}|gsk_[0-9A-Za-z]{16,}|nvapi-[0-9A-Za-z-]{16,}' \ "$TARGET_DIR" \ --exclude-dir=.git \ --exclude-dir=node_modules \ --exclude=SKILL.md 2>/dev/null || true) ``` ```bash WORLD_WRITABLE=$(find "$TARGET_DIR" -type f -perm -0002 2>/dev/null || true) ``` ### Technical Analysis `TARGET_DIR` is quoted, which prevents shell word splitting and shell metacharacter injection. However, quoting does not prevent the invoked utilities from interpreting an argument beginning with `-` as an option. The `grep` invocations place the target operand before additional options and do not use an end-of-options marker. On implementations that continue option parsing after non-option operands, a target directory name resembling a valid option can change `grep` behavior. Other implementations may reject the invocation, creating inconsistent scan coverage. The `find` invocation similarly receives the user-selected path without canonicalizing or safely prefixing it. A leading-dash path can be parsed as part of the expression or rejected instead of being treated as a search root. Errors are redirected to `/dev/null`, and `|| true` forces successful command substitution. Consequently, option-parsing failures can be hidden and represented by an empty result, after which the script prints an affirmative message such as `OK: No dangerous function calls detected.` This can create a misleading clean result. ### Attack Path 1. An attacker creates or supplies a v ...[truncated 1080 chars]
Remediation
View remediation
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Self-Modification

High
Category
Rogue Agent
Confidence
90% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
- outbound network access
- credential handling
- writes outside the working directory
- self-modifying or persistence-oriented behavior

### 4. Give a practical verdict

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 46)May include surrounding context.

md
The script currently checks for:
- suspicious function names such as `eval(`, `exec(`, `system(`, and `spawn(`
- simple hardcoded-secret patterns
- world-writable files

Because the script uses grep-style heuristics, expect both false positives and false negatives.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/scan.sh (reported line 58)May include surrounding context.

sh
The script currently checks for:
- suspicious function names such as `eval(`, `exec(`, `system(`, and `spawn(`
- simple hardcoded-secret patterns
- world-writable files

Because the script uses grep-style heuristics, expect both false positives and false negatives.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/scan.sh (reported line 52)May include surrounding context.

sh
echo ""
echo "[3/3] Analyzing file permissions..."
WORLD_WRITABLE=$(find "$TARGET_DIR" -type f -perm -0002 2>/dev/null || true)

if [ -n "$WORLD_WRITABLE" ]; then
    echo "WARNING: World-writable files found:"

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/scan.sh (reported line 54)May include surrounding context.

sh
echo ""
echo "[3/3] Analyzing file permissions..."
WORLD_WRITABLE=$(find "$TARGET_DIR" -type f -perm -0002 2>/dev/null || true)

if [ -n "$WORLD_WRITABLE" ]; then
    echo "WARNING: World-writable files found:"

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/scan.sh (reported line 56)May include surrounding context.

sh
echo ""
echo "[3/3] Analyzing file permissions..."
WORLD_WRITABLE=$(find "$TARGET_DIR" -type f -perm -0002 2>/dev/null || true)

if [ -n "$WORLD_WRITABLE" ]; then
    echo "WARNING: World-writable files found:"

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/scan.sh (reported line 55)May include surrounding context.

sh
WORLD_WRITABLE=$(find "$TARGET_DIR" -type f -perm -0002 2>/dev/null || true)

if [ -n "$WORLD_WRITABLE" ]; then
    echo "WARNING: World-writable files found:"
    echo "$WORLD_WRITABLE"
else
    echo "OK: No world-writable files detected."

Static analysis

No suspicious patterns detected.