Back to skill

Security audit

skills coach

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent skill optimizer, but it automatically executes and installs code influenced by untrusted target skills, so it needs careful Review before installation.

Install only if you intend to run a high-trust local optimization harness. Use it in a disposable container or VM, pass only a narrow target skill directory, disable auto_install_deps, avoid exposing API keys or secrets in the environment, and review every generated or extracted command before execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
subskills/exec-agent/env_checker.py:160
Finding

Automatic Retrieval and Shell Execution of a Mutable Remote Installer

Content
View full analysis
str: """Get installation command for missing dependency.""" install_commands = { 'uv': 'brew install uv', 'python': 'brew install python', 'python3': 'brew install python', 'node': 'brew install node', 'npm': 'brew install node', 'yarn': 'npm install -g yarn', 'go': 'brew install go', 'cargo': 'curl --proto \'=https\' --tlsv1.2 -sSf https://sh.rustup.rs | sh', 'java': 'brew install openjdk', 'ruby': 'brew install ruby', 'php': 'brew install php' } return install_commands.get(command, None) ``` ```python install_cmd = self.get_installation_command(command) if not install_cmd: print(f" ✗ No automatic installation available for {command}") return False print(f" Installing {command}...") print(f" Command: {install_cmd}") try: result = subprocess.run( install_cmd, shell=True, capture_output=True, text=True, timeout=300 ) ``` The behavior is enabled by the default configuration: ```yaml execution: timeout_per_task: 300 max_retries: 2 parallel_execution: false auto_install_deps: true ``` The orchestrator propagates that setting automatically: ```python if exec_config.get('auto_install_deps', False): cmd.append('--auto-install') print(" → Auto-install dependencies enabled") ``` ### Technical Analysis When `cargo` is considered a required but missing command, the dependency checker downloads the current response from `https://sh.rustup.rs` and immediately pipes it into a shell. The payload is neither pinned to a specific immutable version nor verified using a cryptogra ...[truncated 1860 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
subskills/exec-agent/executor.py:88
Finding

Arbitrary Shell Command Execution from Untrusted Target Skill Documentation

Content
View full analysis
str: """Extract executable command from task markdown.""" import re # Look for command in code block match = re.search(r'```(?:bash|shell|sh)\n(.*?)\n```', task_content, re.DOTALL) if match: return match.group(1).strip() # For documentation tasks, return empty string (no command to execute) return "" ``` The extracted text is then passed to the system shell: ```python try: result = subprocess.run( command, shell=True, capture_output=True, text=True, timeout=300, # 5 minute timeout cwd=work_dir ) exec_time = time.time() - start_time status = "SUCCESS" if result.returncode == 0 else "ERROR" stdout = result.stdout stderr = result.stderr ``` ### Technical Analysis The target Skill is an audit and optimization input and must therefore be treated as unt ...[truncated 2435 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
subskills/optimize-agent/command_optimizer.py:122
Finding

Unvalidated LLM-Generated Commands Cross the Model-to-Shell Trust Boundary

Content
View full analysis
Dict: """Execute a command and capture results.""" try: result = subprocess.run( command, shell=True, capture_output=True, text=True, timeout=timeout, cwd=self.work_dir ) ``` Command optimization is invoked automatically for applicable Skills: ```python print("✓ Running command optimizer. ...[truncated 2413 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
subskills/exec-agent/env_checker.py:43
Finding

Automatic Installation of Target-Controlled Unpinned Python Dependencies

Content
View full analysis
=')[0].split('<=')[0].split('~=')[0].strip() if package: self.required_python_packages.add(package) ``` The resulting package name is installed using several increasingly invasive strategies: ```python # Try multiple installation strategies strategies = [ # Strategy 1: Try --user flag (for externally-managed environments) ([sys.executable, '-m', 'pip', 'install', '--user', package], '--user'), # Strategy 2: Try --break-system-packages (for PEP 668 environments) ([sys.executable, '-m', 'pip', 'install', '--break-system-packages', package], '--break-system-packages'), # Strategy 3: Try without flags (for virtual environments) ([sys.executable, '-m', 'pip', 'install', package], 'default'), ] for cmd, strategy_name in strategies: try: result = subprocess.run( cmd, capture_output=True, text=True, timeout=300 # 5 minute timeout ) ``` Automatic installation is enabled by default: ```yaml execution: timeout_per_task: 300 max_retries: 2 parallel_execution: false auto_install_deps: true ``` ### Technical Analysis A target Skill controls its own `requirements.txt`. Skills-Coach reads package identifiers from that untrusted ...[truncated 2140 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (147)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared access to a specific local skill path is a scope and confidentiality issue: users may not expect repository scanning or parsing outside the immediate requested file. In a meta-skill, even read-only traversal can expose secrets, proprietary code, or unrelated files if path controls are weak.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
- `target-skill-path` (required): Path to the directory containing the Skill to analyze and optimize. Must contain a valid `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
- `target-skill-path` (required): Path to the directory containing the Skill to analyze and optimize. Must contain a valid `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
- `target-skill-path` (required): Path to the directory containing the Skill to analyze and optimize. Must contain a valid `SKILL.md`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 414)May include surrounding context.

md
- `target-skill-path` (required): Path to the directory containing the Skill to analyze and optimize. Must contain a valid `SKILL.md`.

Static analysis

No suspicious patterns detected.