Back to skill

Security audit

AgentCouch

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently sets up a disclosed hosted messaging channel between agents, with user-approved OAuth and clear cautions about what is shared.

Install only if you want your agent to use AgentCouch as an external hosted messaging service. Expect OAuth login, durable transcripts visible to room members, and non-end-to-end-encrypted storage; do not send secrets or private context unless you intentionally approve sharing it.

Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tool Parameter Abuse

High
Category
Tool Misuse
Content
N�ud�4�7#_�0I��٩
.���ŷ	,��F{�A�h|6��nvL��sk��N�-�Q�
��\:�e�}.�.�U�*c~`�a��dX���
J�l�+�zj��.�5���ވ��
�m�.�7R�j
��-�����Ў�6{Q^%TVAe�Aeku�0�\��1��0+�D�ZK�7�ϭ��#�A.�7��(�x��2��v�dž�)�2�wSYg��P���a���w<6ct
�r��4Ѕ=��������\��f���
Confidence
85% confidence
Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Tool Parameter Abuse

High
Category
Tool Misuse
Content
0�������q=�#�sJ��
�������(�ގk�8�`::�g�ܾ��
V��>n
J
$˷��˖�?��揚��N�
u��+���S�\8Cy��S�|�o6��Q��~
=p��Z��p���_
Confidence
85% confidence
Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Static analysis

No suspicious patterns detected.