Back to skill

Security audit

FlashForge AI Flashcard Generator

Security checks for vulnerabilities and agentic risk

Overview

This flashcard skill is coherent and locally stores study decks as expected, with no evidence of network exfiltration, privilege escalation, or hidden behavior.

Before installing, users should understand that flashcard fronts, backs, tags, and review history can be saved locally in a JSON file. Avoid pasting highly sensitive notes unless the local storage location is acceptable for your environment.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The documented purpose is a simple flashcard generator, but the finding indicates undeclared filesystem read/write behavior and a mismatch between advertised automatic generation and actual behavior. Undeclared local persistence increases risk because users may expose notes or study material to storage they did not consent to, and behavior mismatches undermine trust and can hide broader unsafe functionality.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · README.md (reported line 44)May include surrounding context.

md
**USE AT YOUR OWN RISK.**

- The author(s) are NOT liable for any damages, losses, or consequences arising from 
  the use or misuse of this software — including but not limited to financial loss, 
  data loss, security breaches, business interruption, or any indirect/consequential damages.
- This software does NOT constitute financial, legal, trading, or professional advice.
- Users are solely responsible for evaluating whether this software is suitable for

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
**USE AT YOUR OWN RISK.**

- The author(s) are NOT liable for any damages, losses, or consequences arising from 
  the use or misuse of this software — including but not limited to financial loss, 
  data loss, security breaches, business interruption, or any indirect/consequential damages.
- This software does NOT constitute financial, legal, trading, or professional advice.
- Users are solely responsible for evaluating whether this software is suitable for

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The DATA DISCLAIMER states as a factual behavior claim that the software 'processes and stores data locally' and 'does not transmit data externally unless explicitly configured by the user.' In this file, however, there is no supporting implementation at all—only product/marketing documentation—so the documentation makes concrete operational assurances not substantiated by code here, which is an intent/documentation divergence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The _save method persists the full deck to a local JSON file, which affects user data by storing potentially sensitive study content on disk. There is no confirmation prompt, log message, or inline disclosure near the write operation to make this persistence behavior visible to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.