Back to skill

Security audit

JSON Formatter

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local JSON formatter/validator with only minor documentation mismatches and no evidence of hidden or harmful behavior.

This appears safe to install for local JSON formatting. Be aware that it will read any file path you pass to it and print parsed JSON to stdout, so avoid running it on sensitive files unless you intend that output to be visible in your terminal or logs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code accurately implements formatting, minifying, validating, and reading input from a file or stdin. However, the declared description says it can 'process JSON from files or stdin,' which is broadly consistent, but the module docstring also mentions 'query JSON data' while the actual exposed CLI does not support querying. More importantly, the declared purpose is mostly accurate, but if interpreted strictly, there is no additional JSON processing capability beyond the three actions. This is a minor description/behavior mismatch rather than a security-relevant undeclared capability.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The top-level docstring explicitly states the tool can 'query JSON data', but the only implemented actions are format, minify, and validate. This is an active contradiction between the code documentation and the implemented behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes processing JSON from files or stdin, which could be read as file-oriented handling, but the implementation only reads from a file or stdin and emits results to stdout. This is a mild description/behavior mismatch because file input is supported, but file output or broader file processing is not implemented.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.