Back to skill

Security audit

repository-helper-28505

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed profile-sync client, but it can upload server-manifest-selected files from the user's home directory without showing or confirming the exact file first.

Review this before installing if your home directory contains secrets, SSH keys, tokens, browser/session files, or private notes. Only use it if you trust the sync service and understand that its manifest determines which eligible home-relative file is uploaded; a safer version would show the exact path and ask for confirmation before each new upload.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior says the skill pushes files listed in a sync manifest, but the described implementation only uploads the first readable entry and does not align with the claimed full sync workflow. Security-relevant mismatches between declared purpose and actual behavior can mislead users about what data is exfiltrated, what is persisted, and whether the tool is complete or safe to trust for backup/restore purposes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
72% confidence
Finding

The skill requests filesystem write and network egress to support a profile-sync workflow that persists user data to an external service, creating session/state persistence risk. In this context, persistence is part of the stated function, but it still increases the attack surface because user files can be stored remotely and potentially restored or reused later without sufficient visibility.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
license: Apache-2.0
permissions:
  - filesystem:read
  - filesystem:write
  - network:egress
---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill reads files from the user's home directory based on a remotely obtained manifest and uploads at least one file to a service, but the description lacks a prominent warning about sensitive-data exposure. Without explicit disclosure and consent language, users may unknowingly permit transmission of private configuration, tokens, or personal files selected through the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code fetches a remote manifest, reads files from the user's home directory based on that manifest, and uploads the resulting content to an external sync service without any just-in-time notice, confirmation, or display of what is being sent. Because the manifest is service-controlled, a user may unknowingly exfiltrate sensitive local profile data simply by running the tool after initialization, making the lack of explicit sync-time warning and consent a real privacy and data-exposure issue.

Content

No source excerpt is available for this finding.

Lp4

Low
Category
MCP Least Privilege
Confidence
65% confidence
Finding

Declared permissions with no matching code capability may indicate removed functionality or pre-staging for future abuse.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The manifest says the skill 'pushes the files listed in your sync manifest ... to the service,' which implies a direct profile sync client. This file instead acts as an IPC client to a local daemon over a Unix socket and only fetches a manifest and posts snapshot payloads to that daemon, so the documented skill behavior and the implemented component's behavior do not fully align.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.