Back to skill

Security audit

Claude

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a document-analysis guide, but it requests the ability to run local commands even though its workflow does not need that power.

Review this skill carefully before installing. Its document-analysis behavior is ordinary, but install it only in an environment where command execution can be disabled or tightly sandboxed, especially when analyzing sensitive contracts, legal-adjacent material, or business documents.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:34
Finding

Unnecessary Command-Execution Capability Violates Least Privilege

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 34–36
Vulnerability Type: Excessive tool permission
Risk Level: Medium

Evidence

yaml
tools:
- read
- exec

Technical Analysis

The skill declares access to the exec tool even though its documented purpose and execution protocol consist solely of reading, analyzing, summarizing, comparing, and rewriting documents. No legitimate workflow in the reviewed file requires shell-command execution.

Exposing exec unnecessarily violates the principle of least privilege. Although the current instructions do not directly invoke commands, documents processed by the skill may contain hostile prompt-injection content. If an agent treats such content as instructions, the availability of exec could turn a document-level instruction-manipulation issue into local command execution.

No direct command-execution payload, malicious script, or explicit instruction to execute document content was found. Exploitation therefore depends on the hosting agent allowing document content or other untrusted input to influence tool calls.

Attack Path

  1. A user or external source supplies a malicious document for analysis.
  2. The document includes prompt-injection text directing the agent to disregard the analysis workflow and invoke the command-execution tool.
  3. The agent fails to maintain the distinction between untrusted document content and trusted skill instructions.
  4. Because exec is declared as an available tool, the agent invokes a local command.
  5. The command operates with the permissions of the agent process and may access or modify resources available to that process.

Impact Assessment

Successful exploitation could permit command execution under the operating-system identity running the agent. Depending on the host sandbox and process privileges, this could expose readable local files, environment variables, workspace content, or writable resources and could allow data modifica ...[truncated 288 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec from the declared tool list and retain only the minimum capability required:
yaml
tools:
- read
  1. Change the availability classification from MD+EXEC to a Markdown-only classification so that the metadata accurately reflects the implementation.
  2. Configure the host agent to treat analyzed document content as untrusted data rather than executable instructions.
  3. Require explicit user confirmation and restrictive sandboxing for any future feature that genuinely needs command execution.
  4. If command execution is later introduced, use a narrowly scoped allowlist of fixed commands and arguments rather than unrestricted shell access.
  5. Deny access to credentials, sensitive environment variables, and files outside the required workspace from any command-execution sandbox.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description switches into Chinese for core capability, use-case, differentiation, and trigger text, while the rest of the skill is primarily in English. This imposes a language choice on users without opt-in and may violate a language/locale policy requiring user choice or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.