Back to skill

Security audit

YES.md 日本語版

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a quality checklist, but it contains mandatory steps that could expose secrets through online searches and unmanaged backup files.

Review this skill before installing. It is not clearly malicious, but users should modify or constrain it so agents search only redacted, minimal error fragments and avoid creating in-tree backups of secret-bearing files unless permissions, exclusions, and cleanup are defined.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:145
Finding

Mandatory Web Search May Disclose Sensitive Error Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 145
Vulnerability Type: Sensitive information exposure through external search
Risk Level: Medium

Complete Code Snippet:

markdown
| | | ② WebSearchで完全なエラーメッセージを検索 |

Technical Analysis

The debugging escalation procedure requires the agent to search for the complete error message after three failed attempts. Error messages can contain credentials, access tokens, internal hostnames, private filesystem paths, database query values, customer information, source-code fragments, or other operational metadata.

A web search transmits its query outside the local execution environment. The instruction does not require the agent to inspect or redact the error before transmission, minimize the query to a nonsensitive fragment, or obtain authorization when sensitive information remains. Consequently, following the instruction literally can disclose confidential information to a search provider and any associated logging or analytics systems.

Attack Path

  1. An application produces an error containing a secret or other internal data.
  2. The agent makes three unsuccessful debugging attempts, activating the mandatory five-step audit.
  3. The agent follows line 145 and submits the complete error message through WebSearch.
  4. The search provider receives and may retain the sensitive query.
  5. Anyone with access to provider logs, browser history, proxy logs, or organizational search telemetry may obtain the disclosed information.

Impact Assessment

Exploitation does not grant additional local privileges or directly execute code. Its primary impact is confidentiality loss outside the project boundary. Depending on the error contents, exposure may affect credentials, internal infrastructure identifiers, proprietary implementation details, or user data. Leaked credentials could subsequently enable access with the privileges assigned to those credentials.

Remediation
View remediation

Remediation Suggestions

Replace the requirement to search the complete error message with a privacy-preserving workflow:

  1. Inspect the error locally before using an external search service.
  2. Remove credentials, tokens, cookies, personal data, query values, internal hostnames, IP addresses, filesystem paths, and proprietary identifiers.
  3. Search only the shortest generic fragment needed to identify the error.
  4. Prefer official documentation and local source inspection before external search.
  5. Require explicit authorization if meaningful sensitive content cannot be removed.
  6. Document which redactions were applied without recording the original secret.

A hardened instruction would be: “Search a minimal, redacted, nonsensitive fragment of the error message; never submit the complete raw error to an external service.”

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:72
Finding

Mandatory Adjacent Backups Can Create Unmanaged Copies of Secrets

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 72–82
Vulnerability Type: Insecure backup handling for sensitive configuration files
Risk Level: Medium

Complete Code Snippet:

markdown
### ゲート:まずバックアップ

**トリガー:** 設定ファイル、環境ファイル、docker-compose、package.json、またはシステム動作に影響するファイルの変更。

**アクション:** 編集前にファイルをコピー。回答の最初の行は必ず:「まずバックアップします。」

```bash
cp file.yaml file.yaml.bak-{説明}

バックアップなし=編集禁止。交渉の余地なし。

text

### Technical Analysis

The policy explicitly applies to environment files and configuration files, which commonly contain passwords, API keys, private endpoints, and other secrets. It mandates creating an adjacent backup with a predictable `.bak-*` name but provides no requirements for restrictive permissions, secure storage, version-control exclusion, retention limits, or deletion after successful verification.

Although `cp` commonly derives destination permissions from the source subject to platform behavior and process configuration, the instruction does not verify the resulting owner or mode. More importantly, the backup becomes an additional persistent copy that may be collected by broad file globs, committed to version control, included in build contexts, copied into deployment artifacts, served by a misconfigured web server, or left readable to other users with directory access.

### Attack Path

1. The agent prepares to edit an environment or configuration file containing secrets.
2. Following the mandatory gate, it creates a predictable adjacent backup such as `.env.bak-update`.
3. The backup remains after the task because no cleanup or retention procedure is specified.
4. A later version-control operation, build-context glob, deployment process, backup collector, local user, or exposed static-file handler discovers the backup.
5. The secret values are disclosed and may be used with the permissions granted to the affected credentials.

### Impact Assessment

This issue does not it
...[truncated 378 chars]
Remediation
View remediation

Remediation Suggestions

Implement a backup policy appropriate to the sensitivity of the target file:

  1. Do not create redundant copies when recovery is already available through trusted version control, snapshots, or a managed secret store.
  2. Never place backups of secret-bearing files in the project tree or web-accessible directories.
  3. If a backup is necessary, create it in a protected temporary directory with access limited to the current user.
  4. Preserve or strengthen ownership and permission restrictions, then verify them explicitly.
  5. Use unpredictable filenames and prevent symlink-following or unintended overwrites.
  6. Exclude backup patterns from version control, build contexts, packaging, and deployment.
  7. Delete the backup securely after validation, unless an approved retention policy requires otherwise.
  8. Record only the backup location and lifecycle status, never its secret contents.

The rule should distinguish ordinary source files from secret-bearing environment and configuration files instead of mandating the same adjacent-copy operation for all targets.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation criteria are intentionally expansive and cover many common behaviors across debugging, implementation, configuration, deployment, API integration, and data-processing tasks. This can cause the skill to trigger in a very large fraction of sessions, effectively overriding narrower skills and changing agent behavior unexpectedly, which increases operational and safety risk even though the content is governance-oriented rather than overtly malicious.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.