Back to skill

Security audit

effect-ts

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Effect-TS coding guide with disclosed, purpose-relevant examples for HTTP, AI providers, subprocesses, uploads, and persistence.

Installers should treat this as a developer reference skill. Use it when you want Effect-TS guidance, and review generated code before running it, especially examples involving subprocesses, external AI/HTTP providers, database mutations, uploads, or durable/background execution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says to use the skill when 'writing, debugging, or reviewing Effect code' and whenever code imports from 'effect' or any '@effect/*' package. This is a wide trigger scope without negative examples or clearer constraints, which could cause the skill to activate for many ordinary coding conversations or repositories that merely contain those imports.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes this skill as guidance for writing, debugging, or reviewing Effect code across areas like errors, concurrency, services, streams, and schema. This file is specifically a concurrency reference, but it also documents process-spawning APIs that execute external commands, which is a materially different operational capability than concurrency primitives alone.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The section documents effect/unstable/process and shows invoking node, git, and head through a process spawner. For a skill presented as an Effect-TS coding guide, especially within a concurrency reference, teaching shell-command execution is an extra capability with security implications that is not clearly justified by the stated purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/http.md (reported line 20)May include surrounding context.

md
// GET request
  const response = yield* client.execute(
    HttpClientRequest.get("https://api.example.com/users")
  )

  // POST with JSON body

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/http.md (reported line 25)May include surrounding context.

md
// GET request
  const response = yield* client.execute(
    HttpClientRequest.get("https://api.example.com/users")
  )

  // POST with JSON body

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/http.md (reported line 32)May include surrounding context.

md
// GET request
  const response = yield* client.execute(
    HttpClientRequest.get("https://api.example.com/users")
  )

  // POST with JSON body

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The multipart upload guidance explicitly states that uploaded files are persisted to disk and exposed via a filesystem path, but it does not warn about the security and operational implications of writing untrusted user content to local storage. In a developer guide, this omission can lead adopters to deploy unsafe defaults, causing disk exhaustion, unsafe retention of sensitive files, or downstream processing of attacker-controlled files without validation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/migration-v4.md (reported line 206)May include surrounding context.

md
## Other API Removals & Renames

| v3                                       | v4                                                                                |
|------------------------------------------|-----------------------------------------------------------------------------------|
| `Layer.scoped(Tag, eff)`                 | `Layer.effect(Tag, eff)` — strips `Scope` from requirements automatically         |
| `Effect.async((resume) => ...)`          | `Effect.callback((resume, signal) => ...)` — `signal: AbortSignal` is positional  |

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · references/retry-scheduling.md (reported line 47)May include surrounding context.

md
| `Schedule.exponential("100 millis", 1.5)` | Custom growth factor             |
| `Schedule.fibonacci("100 millis")` | Fibonacci backoff                          |
| `Schedule.fixed("5 seconds")`  | Fixed interval (accounts for elapsed time)     |
| `Schedule.forever`             | Repeat indefinitely                            |
| `Schedule.once` (v3 only)      | Run once more — v4: use `Schedule.recurs(0)`   |
| `Schedule.jittered`            | Add randomness (combine with other schedules)  |
| `Schedule.take(n)`             | Bound any schedule to n iterations (v4 idiom)  |

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 27)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 31)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 54)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 147)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This markdown file includes example code that sends prompts to external AI providers and later documents tracing of model-call metadata, but the skill description does not warn that user-supplied content may be transmitted to third-party services or captured in observability spans. For markdown files, SQP-2 applies when behaviors affecting privacy are described without disclosure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/effect-ai.md:50