Back to skill

Security audit

3-Tier Auto-Backup Daily Snapshots, Drive Mirror & Emergency Recovery

Security checks for vulnerabilities and agentic risk

Overview

This backup skill is mostly disclosed and local, but it needs Review because its restore instructions include a destructive mirror command without a clear warning.

Install only if you are comfortable reviewing and adapting the backup commands yourself. Before using the mirror restore command, restore into a new empty directory or run a dry run first; do not point `/MIR` at a live workspace unless you understand it can delete files. The emergency chat sends typed prompts to a local Ollama server on your machine, so avoid sensitive content unless you trust that local service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file implements a live chat client to a local Ollama inference server, which is materially different from the declared backup/recovery purpose. This kind of hidden capability expands the skill's behavior beyond user expectations and can expose sensitive prompts or data to an undeclared local service, making the mismatch itself a significant security and trust concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The restore command uses robocopy ... /MIR, which mirrors the source to the destination by overwriting changed files and deleting files that do not exist in the backup. In a backup/restore skill, users are especially likely to copy-paste commands during a stressful recovery scenario, so omitting an explicit warning materially increases the risk of accidental data loss.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The restore instructions use robocopy ... /MIR, which mirrors the source to the destination and can delete files in the destination that are not present in the backup. Presenting this as a restore command without an explicit warning or safer alternative creates a real risk of accidental destructive data loss during recovery, especially for non-expert users following the documentation verbatim.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code introduces interactive inference features unrelated to backup, mirroring, or emergency export, creating unnecessary attack surface and undisclosed functionality. In a security review, unjustified capabilities are risky because they may process sensitive user input and interact with local services without a clear operational need.

Content

No source excerpt is available for this finding.

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · emergency-chat.html (reported line 30)May include surrounding context.

html
async function checkOllama() {
  try {
    const r = await fetch('http://127.0.0.1:11434/api/tags');
    const d = await r.json();
    const names = d.models.map(m => m.name.split(':')[0] + ':' + (m.name.split(':')[1]||'latest'));
    for (const m of MODELS) { if (names.some(n => n.includes(m.split(':')[0]))) { model = m; break; } }

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · emergency-chat.html (reported line 52)May include surrounding context.

html
async function checkOllama() {
  try {
    const r = await fetch('http://127.0.0.1:11434/api/tags');
    const d = await r.json();
    const names = d.models.map(m => m.name.split(':')[0] + ':' + (m.name.split(':')[1]||'latest'));
    for (const m of MODELS) { if (names.some(n => n.includes(m.split(':')[0]))) { model = m; break; } }

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · emergency-chat.html (reported line 52)May include surrounding context.

html
chat.scrollTop = chat.scrollHeight;
  
  try {
    const r = await fetch('http://127.0.0.1:11434/api/generate', {
      method: 'POST',
      headers: {'Content-Type': 'application/json'},
      body: JSON.stringify({ model, prompt: msg, stream: false })

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · README.md (reported line 79)May include surrounding context.

md
**USE AT YOUR OWN RISK.**

- The author(s) are NOT liable for any damages, losses, or consequences arising from 
  the use or misuse of this software — including but not limited to financial loss, 
  data loss, security breaches, business interruption, or any indirect/consequential damages.
- This software does NOT constitute financial, legal, trading, or professional advice.
- Users are solely responsible for evaluating whether this software is suitable for

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
**USE AT YOUR OWN RISK.**

- The author(s) are NOT liable for any damages, losses, or consequences arising from 
  the use or misuse of this software — including but not limited to financial loss, 
  data loss, security breaches, business interruption, or any indirect/consequential damages.
- This software does NOT constitute financial, legal, trading, or professional advice.
- Users are solely responsible for evaluating whether this software is suitable for

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

User-entered messages are transmitted to the local Ollama API without clear user-facing disclosure that their text is being sent to another service. Even though the destination is localhost, the behavior can still surprise users and expose sensitive recovery-related content to a separate process they did not knowingly engage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.