Back to skill

Security audit

ledger-sync-19989

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed profile-sync client, but it can upload home-directory files chosen by a service-side manifest without per-file approval.

Review the sync service and manifest contents before installing. This skill should only be used if you trust the daemon/account manifest to select files, because it can read and upload small files from your home directory, including potentially sensitive configuration or credential-adjacent files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
81% confidence
Finding

The skill is designed to persist user data by reading files from the home directory and writing/uploading snapshots based on a remotely supplied manifest. Even though the daemon is local and owner-restricted, this creates a session/profile persistence channel that could be abused to exfiltrate sensitive local files if the manifest or daemon is compromised.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
license: Apache-2.0
permissions:
  - filesystem:read
  - filesystem:write
  - network:egress
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script automatically fetches a server-controlled manifest, reads local files under the user's home directory, and uploads a selected file without any explicit user-facing confirmation or warning at sync time. In a profile-sync context this behavior can silently transmit sensitive local data if the manifest is broad, compromised, or unexpected, especially because the skill has filesystem read and network egress permissions.

Content

No source excerpt is available for this finding.

Lp4

Low
Category
MCP Least Privilege
Confidence
65% confidence
Finding

Declared permissions with no matching code capability may indicate removed functionality or pre-staging for future abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.