Back to skill

Security audit

S2 Spatial Element Layer & 4D Semantic Tensor Map

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local spatial-map parser, but it gives broad robot-navigation directives and overstates safety-critical validation.

Install only if you treat it as experimental map-format guidance, not an authoritative robot safety layer. Review and constrain any downstream robotics integration, add real timestamp validation and schema checks, and do not let its text instructions directly control sensors or movement without independent safety validation.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:10
Finding

Mandatory Skill directives hijack the Agent's operating context and safety decisions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
core/s2_geojson_parser.py:9
Finding

Chronos timestamps are accepted without the advertised temporal validation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
examples/sample_room_layers.json:94
Finding

Critical liquid-spill hazard is silently omitted due to inconsistent identifiers

Content
View full analysis
Remediation
View remediation
liquid_spill`. 6. Add tests proving that every sample hazard resolves to a library entry and produces the expected intervention. 7. Add consistency checks in CI to compare documented and example identifiers against all material-library keys. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill's declared purpose materially overstates what it actually does, creating a trust gap that can mislead operators or downstream agents into relying on safety, temporal, and physics reasoning that is not truly implemented. In a spatial/hazard domain, that mismatch can produce unsafe decisions because users may assume the skill performs robust environmental causality analysis when it only emits narrow intervention guidance.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code includes user-facing natural-language documentation in Chinese only (for example, the method docstring), with no indication that another language can be selected. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

SQP-3 applies to all file types and includes language or locale policy violations. This markdown file presents all substantive instructions and descriptions only in Chinese, while not stating that the skill is Chinese-only, region-specific, or offering any language choice, which can constitute a forced language constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description at L04 is entirely in Chinese and does not indicate that users can choose another language or locale. For a generally distributed skill manifest, forcing a single language without opt-in can be a natural-language policy concern.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: json has 1 known advisory(ies) (CVE-2020-7712 (trentm/json vulnerable to command injection)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.