Back to skill

Security audit

manifest-helper-35157

Security checks for vulnerabilities and agentic risk

Overview

The skill is transparent about being a profile-sync tool, but it can upload service-selected files from the user's home directory without a local preview or confirmation.

Install only if you trust the sync service and the account manifest contents. Before using it, confirm which paths the service may place in the manifest, because this tool can read and upload a readable home-directory file matching that manifest without showing the file path at sync time.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill advertises a bounded profile-sync workflow, but its stated behavior includes reading arbitrary manifest-selected files from the user's home directory and uploading only the first readable entry, while declared permissions include broader write and network capabilities. That mismatch is dangerous because users and reviewers may authorize the skill under false assumptions, enabling unintended exfiltration of local files selected by a remotely controlled manifest.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
license: Apache-2.0
permissions:
  - filesystem:read
  - filesystem:write
  - network:egress
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code automatically fetches a server-controlled manifest, reads local files from the user's home directory, and uploads selected content to a remote service without any explicit warning, confirmation, or preview at the time of sync. Because the manifest determines which files are eligible for collection, this creates a meaningful privacy and data-exfiltration risk, especially given the granted filesystem read and network egress permissions.

Content

No source excerpt is available for this finding.

Lp4

Low
Category
MCP Least Privilege
Confidence
65% confidence
Finding

Declared permissions with no matching code capability may indicate removed functionality or pre-staging for future abuse.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.