Back to skill

Security audit

Agent Bom Vulnerability Intel

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a vulnerability/SBOM scanner, but it asks for broad execution and write authority and includes instructions that drift into general code modification work.

Review this skill carefully before installing. It may be useful for dependency vulnerability checks, but only use it with a constrained workspace and require explicit approval before it runs commands or modifies files. Do not treat it as read-only security analysis unless your host environment enforces that limitation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:20
Finding

Excessive Tool Permissions Violate Least-Privilege Boundaries

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–25; supporting operational instructions at lines 62–66
Vulnerability Type: Excessive command-execution and file-modification capabilities
Risk Level: Medium

Vulnerable Code

yaml
tools:
  - read
  - exec
  - write
  - glob
  - grep

Technical Analysis

The Skill is presented as a package, SBOM, and dependency-vulnerability analysis capability. Such analysis generally requires controlled file reading, dependency enumeration, and access to vulnerability intelligence. However, the Skill requests unrestricted exec and write tools in addition to read-only discovery tools.

The operational instructions at lines 62–66 also expand the Skill's behavior beyond vulnerability analysis by authorizing development operations such as writing, refactoring, and testing according to user instructions. The document does not define:

  • An allowlist of permitted commands or executables.
  • Validation or escaping rules for command arguments.
  • Workspace-only restrictions for file access.
  • A list of files that may be modified.
  • User confirmation before commands or writes occur.
  • Enforced sandbox boundaries.
  • Separation between trusted instructions and untrusted repository content.

This violates the principle of least privilege. Although the document claims that commands execute in a secure sandbox, no implementation or enforceable sandbox policy is included in the audited project.

Attack Path

  1. An agent loads the Skill and grants the declared read, exec, and write capabilities.
  2. A user supplies a crafted scanning request, package identifier, SBOM, repository, or project content.
  3. The agent interprets the broad development-operation instructions as authorization to execute commands or modify files while conducting the scan.
  4. Because no command allowlist, path restriction, or confirmation boundary is defined, the agent ...[truncated 1214 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the write capability unless saving a report is an essential feature. If persistence is required, restrict writes to a dedicated output directory and prevent overwriting existing project files by default.
  2. Avoid general-purpose exec. Prefer a narrowly scoped vulnerability-scanner API or a dedicated tool exposing only required operations.
  3. If command execution is unavoidable, define an explicit allowlist of executable names, fixed subcommands, and accepted argument formats.
  4. Pass user-controlled package names and paths as separately validated arguments rather than interpolating them into shell command strings.
  5. Reject shell metacharacters and enforce package-manager-specific package-name and version syntax.
  6. Canonicalize paths and verify that all reads and writes remain within the approved workspace or report directory.
  7. Require explicit user confirmation before any command with side effects or any modification to project files.
  8. Treat package metadata, SBOM content, source files, and repository instructions as untrusted data rather than executable agent instructions.
  9. Replace the broad development-operation instruction with a narrowly defined, read-only vulnerability-analysis workflow.
  10. Document and technically enforce sandbox restrictions, including filesystem, network, process, timeout, and resource limits.
  11. Add tests demonstrating that crafted package names, paths, SBOM fields, and repository text cannot trigger arbitrary commands or writes.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation guidance uses very broad trigger language covering general AI model calls, chat, agent orchestration, and LLM applications, without clearly limiting when this skill should be selected. In an agentic environment, ambiguous routing can cause the skill to activate in unrelated contexts, unnecessarily exposing read/exec/write capabilities and increasing the chance of unsafe or irrelevant actions.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill is presented as a vulnerability-intelligence tool, but its usage instructions describe broad code-reading, editing, refactoring, testing, and validation actions. This mismatch can cause an agent to perform materially different operations than a user expects, including modifying files or executing workflows beyond passive security analysis, increasing the risk of unintended system changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill advertises executing development operations and uses powerful tools including exec and write, but does not give a clear, prominent warning that these actions can alter files or affect the host environment. In the context of a purported security-analysis skill, this is especially risky because users may expect read-only analysis while the agent may instead make changes or run commands with side effects.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example output schema shows generic code-quality scoring fields such as style, compliance scores, and improvement points rather than concrete vulnerability-intelligence results. This can mislead downstream agents or users into trusting irrelevant output, suppress real security findings, or integrating the skill incorrectly into automated decision pipelines.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.