Back to skill

Security audit

Home Inspection

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its home-inspection purpose, but it tells the agent to run an analytics script that is not included for review.

Install only if you are comfortable with a Taiwan-focused Traditional Chinese inspection workflow. Do not let the agent run `skills/analytics.py` unless you can verify that script from the installed environment, and direct report output to a specific safe `.md` path to avoid overwriting important files.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Warning
Location
SKILL.md:104
Finding

Execution of an Unpackaged and Unverified Analytics Script

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gen-report.py:51
Finding

Unescaped Markdown Generation and Unrestricted Output File Overwrite

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill instructs the agent to read references and generate reports via a script, implying file read/write behavior, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization gap where an agent or runtime may permit broader filesystem access than intended, increasing the chance of unintended file access or overwrite during skill execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template is entirely written in Traditional Chinese and presents a fixed-language report format, including headings, field labels, and conclusions. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the regional constraint is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file's usage example, sample data, report labels, and generated conclusions are written entirely in Traditional Chinese, and the generated report text is also fixed to that language. This imposes a specific language/locale on users without any opt-in or documented justification that the skill is intended only for a Chinese-speaking or Taiwan-specific context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The description specifies Taiwan residential properties and the document content heavily mixes or defaults to Traditional Chinese terminology and instructions. Under the stated policy, a skill that effectively forces a specific language/locale should either offer user choice or clearly document a justified locale constraint; this file does not explicitly present that opt-in or justification as a locale restriction policy.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill asks users to run an external analytics script unrelated to the core home-inspection function, which introduces unnecessary code execution. Even if benign, this expands the attack surface by encouraging execution of auxiliary code that may collect telemetry or perform actions the user does not expect as part of an inspection workflow.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown checklist forces a specific language/locale for all users, and the file does not provide any opt-in, alternative language, or justification for the locale restriction. Under the stated policy, natural-language content that mandates a single language without user choice is a language/locale policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This markdown file presents all guidance in a single language/locale, which can be a natural-language policy issue if skills are expected not to force a specific language without user opt-in. There is no indication that the user can choose another language or that the Taiwan-specific language/locale scope is explicitly justified as a constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.