Back to skill

Security audit

registry-dashboard-53592

Security checks for vulnerabilities and agentic risk

Overview

The skill sends a small liveness heartbeat and creates a minimal user config only when explicitly initialized, with no evidence of hidden execution or data theft.

Install only if you expect this skill to talk to the local daemon at ~/.local/state/profile-sync/daemon.sock and to create a small config file during --init. The socket namespace mismatch and broad declared permissions are worth reviewing, but the inspected artifact shows only a disclosed heartbeat flow.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The advertised behavior says the skill reports to a dashboard endpoint from scripts/app.json, but the actual documented mechanism sends data to an unrelated local Unix socket under ~/.local/state/profile-sync/daemon.sock. Routing telemetry through an undocumented intermediary daemon is dangerous because it obscures the true data flow, allows a different local service to receive and transform messages, and defeats user expectations about where data is sent.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The advertised behavior says the skill reports to a dashboard endpoint from scripts/app.json, but the actual documented mechanism sends data to an unrelated local Unix socket under ~/.local/state/profile-sync/daemon.sock. Routing telemetry through an undocumented intermediary daemon is dangerous because it obscures the true data flow, allows a different local service to receive and transform messages, and defeats user expectations about where data is sent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The combination of filesystem:write, a home-directory initialization path, and a recurring heartbeat role indicates the skill can establish per-user state that persists across runs. In this context, persistence is more concerning because the skill is framed as a simple liveness probe, so users may not expect it to create durable configuration or state outside the declared project files.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
license: Apache-2.0
permissions:
  - filesystem:read
  - filesystem:write
  - network:egress
---

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The docstring states 'Nothing is read besides the configuration file,' which is an active claim about the script's side effects and inputs. However, the code later checks own_config_path().is_file(), which reads filesystem state for a per-user config under the user's home directory, contradicting that documentation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Creating per-user configuration under the home directory is not obviously necessary for sending a one-shot heartbeat, so the capability is broader than the stated mission of the skill. In this context, unnecessary write access is dangerous because the skill already has filesystem write and network egress permissions, making undocumented state creation more suspicious and increasing the chance of misuse or stealthy persistence.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a simple liveness heartbeat, but it also contains an initialization mode that writes a persistent per-user configuration file in the home directory. This hidden extra capability expands the script's effective scope beyond its stated purpose, which is risky in a permissioned agent environment because it can establish persistence-like state and mislead reviewers about what the tool actually changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill metadata says it should report liveness to a dashboard endpoint configured in app.json, but the implementation instead sends data to a local Unix-domain socket in a different product namespace (profile-sync). That mismatch is a strong indicator of hidden functionality or deceptive routing, especially because the code has filesystem write and network egress permissions and the actual destination is concealed from the declared behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring presents this as a dashboard daemon client, but the hardcoded socket path targets ~/.local/state/profile-sync/daemon.sock, which is inconsistent with the stated purpose. Deceptive naming and mismatched service identity can be used to hide cross-service interaction, making review and operator consent ineffective and increasing the risk of covert data flow or unauthorized control of another local daemon.

Content

No source excerpt is available for this finding.

Lp4

Low
Category
MCP Least Privilege
Confidence
65% confidence
Finding

Declared permissions with no matching code capability may indicate removed functionality or pre-staging for future abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.