Back to skill

Security audit

weekly-dev-tips

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small markdown-only developer tips collection; its elevated shell examples are visible teaching examples, not hidden or automatic behavior.

Install only if you want a lightweight developer tips reference. Treat the shell snippets as examples to review before running, especially commands using sudo or commands that delete Git branches.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Chaining Abuse

High
Category
Tool Misuse
Content
## 5. `tee` when you need root + pipe
```bash
echo "hello" | sudo tee /etc/motd
```

## 6. Use `fzf` for fuzzy everything
Confidence
75% confidence
Finding
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Content
## 2. `!!` repeats the last command
Prefix with `sudo` when you forgot permissions:
```bash
sudo !!
```

## 3. `cd -` goes back to the previous directory
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Content
## 2. `!!` repeats the last command
Prefix with `sudo` when you forgot permissions:
```bash
sudo !!
```

## 3. `cd -` goes back to the previous directory
Confidence
70% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Static analysis

No suspicious patterns detected.