Back to skill

Security audit

update-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed repository-maintenance automation, but it gives an agent broad mutation and publication authority and can query cross-project conversation data without a project boundary.

Install only if you are comfortable letting the agent edit, validate, commit, push, and potentially publish skill repository changes after approval prompts. Use it on trusted skill names only, review diffs before GATE 2, and avoid or disable Pond cross-project research unless you explicitly want unrelated project conversation history searched.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:20
Finding

Unsanitized Skill Name Can Reach a Shell Command

Content
View full analysis
` refers to the resolved skill name. ``` ```bash git -C "${CLAUDE_PROJECT_DIR}" worktree add "${CLAUDE_PROJECT_DIR}/../skills-" -b chore/update- ``` ```markdown Set `` = `${CLAUDE_PROJECT_DIR}/../skills-`. If that path or branch already exists, add the same numeric suffix (`-2`, `-3`, ...) to both the worktree path and the branch name until both are free, and carry that suffix into ``. ``` ### Technical Analysis The skill accepts `$ARGUMENTS` as a skill name and only requires the corresponding `SKILL.md` file to exist. It does not define a strict character allowlist for the resolved value. The resolved `` is subsequently interpolated into a shell command. Although the worktree path is quoted, the branch value in `chore/update-` is not explicitly quoted. If an agent substitutes an attacker-controlled skill directory name containing shell metacharacters, the shell can interpret those characters as command syntax rather than as part of a branch name. Checking that a path exists does not sanitize its name. On file systems that permit shell metacharacters in directory names, an attacker with the ability to add or rename a skill directory could create a name designed to alter the resulting command. ### Attack Path 1. An attacker who can modify the skills repository creates a skill directory whose name includes shell metacharacters. 2. The attacker places a `SKILL.md` file inside that directory, satisfying the d ...[truncated 1201 chars]
Remediation
View remediation
" worktree_path="${CLAUDE_PROJECT_DIR}/../skills-${skill_name}" branch_name="chore/update-${skill_name}" git -C "${CLAUDE_PROJECT_DIR}" worktree add \ "${worktree_path}" \ -b "${branch_name}" ``` 4. Prefer structured process execution in which the executable and argument array are passed separately, rather than constructing a shell command string. 5. Resolve and verify the target path remains under `${CLAUDE_PROJECT_DIR}/skills/` after canonicalization. 6. Repeat validation after adding numeric suffixes, and use `--` where supported to prevent values beginning with a hyphen from being interpreted as options. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:67
Finding

Unscoped Cross-Project Conversation Mining Violates Least-Privilege Access

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Self-Modification

High
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill is explicitly designed to read, modify, validate, commit, and push changes to skills in a repository, including SKILL.md, CHANGELOG.md, and generated files. Even with approval gates, this is a self-/repo-modifying automation pattern that can propagate unsafe edits, introduce malicious content from researched sources, or publish changes if a user approves prompts without careful review.

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
upstream: "keep-a-changelog@2.0.0"
---

# Update Skill

Run a thorough on-demand refresh of one skill in a skills repository. Two hard human-approval gates ensure no edits or commits happen without explicit confirmation.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- **(a) Drift check** - compare the docs against the skill's current `SKILL.md` and `references/`, flagging API changes, deprecated or removed symbols, and patt

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
- **(a) Drift check** - compare the docs against the skill's current `SKILL.md` and `references/`, flagging API changes, deprecated or removed symbols, and patt

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 152)May include surrounding context.

md
- **(a) Drift check** - compare the docs against the skill's current `SKILL.md` and `references/`, flagging API changes, deprecated or removed symbols, and patt

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 153)May include surrounding context.

md
- **(a) Drift check** - compare the docs against the skill's current `SKILL.md` and `references/`, flagging API changes, deprecated or removed symbols, and patt

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 171)May include surrounding context.

md
- **(a) Drift check** - compare the docs against the skill's current `SKILL.md` and `references/`, flagging API changes, deprecated or removed symbols, and patt

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 27)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 31)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 54)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.txt (reported line 147)May include surrounding context.

text
permissions granted by this License.

"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation source, and
configuration files.

"Object" form shall mean any form resulting from mechanical transformation or

Static analysis

No suspicious patterns detected.