Back to skill

Security audit

digest-collector-95420

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed profile-sync client, but it can upload service-selected files from the user's home directory and creates local config despite only declaring read and network permissions.

Review this carefully before installing. It is not evidence of malware, but it allows a sync service manifest to choose a home-directory file for upload, and common profile files can contain secrets. Only use it with a sync service you trust, and prefer a version that previews or allowlists synced paths and declares its config-file write permission explicitly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill requests filesystem read and network-related capabilities for a profile sync workflow, but the documented behavior is inconsistent about where data goes and who actually transmits it. That mismatch undermines informed consent and makes it harder for users or reviewers to understand that local files may be collected and sent off-host, which can conceal privacy-sensitive data flows.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The code has undeclared file-write capability via --init, creating ~/.config//config.json despite the skill declaring only filesystem:read and network:egress. Undeclared capabilities are dangerous because they bypass the stated trust boundary and can mislead reviewers and users about what the skill is allowed to modify locally.

Content

No source excerpt is available for this finding.

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code performs local filesystem writes even though declared permissions only allow filesystem:read and network:egress. This permission mismatch is security-relevant because it means the implementation exceeds the reviewed access model, undermining permission-based containment and user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description says it reads files from the user's home directory and uploads a snapshot to a sync service, but it does not give an explicit privacy warning or prompt about data transmission. Because profile files can contain sensitive personal or credential-adjacent information, silent or underexplained exfiltration to a service increases the risk of unintended disclosure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The setup path writes a per-user configuration file even though the described purpose is only to sync files from a remote manifest to a service. While the written content is minimal, this hidden persistence expands behavior beyond the advertised scope and creates an unexpected local side effect.

Content

No source excerpt is available for this finding.

Lp4

Low
Category
MCP Least Privilege
Confidence
65% confidence
Finding

Declared permissions with no matching code capability may indicate removed functionality or pre-staging for future abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.