Back to skill

Security audit

Buffer Calculator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local lab buffer calculator, but its core recipe calculations are badly wrong and its declared file/tool permissions are broader than its documentation admits.

Review before installing or using in a lab. Do not rely on its recipe outputs without independent verification, and prefer a corrected version with fixed unit conversions, explicit reagent forms, input validation, and narrower tool permissions.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:53
Finding

Incorrect Unit Conversion Produces Solid Quantities 1,000 Times Too Large

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:25
Finding

Ambiguous Reagent Forms and Percentage Units Can Generate Incorrect Chemical Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:43
Finding

Unvalidated Numeric Inputs Permit Negative, Non-Finite, and Unrealistic Recipes

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
SKILL.md:4
Finding

Skill Declares Filesystem and Command Capabilities Beyond Its Functional Requirements

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill claims 'No file access' and presents a low-risk profile, but the manifest explicitly allows Write/Edit/Bash and the documentation describes creation of output files. This mismatch can mislead users or downstream policy systems into granting too much trust, increasing the chance that file-modifying behavior is used without appropriate scrutiny or restrictions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The natural-language labels "上游" and "下游" introduce a locale-specific element in the skill description, but the document does not indicate that multilingual output is optional or user-selected. This can conflict with a language/locale policy requiring user opt-in before forcing a specific language.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.