Back to skill

Security audit

jev-pipeline

Security checks for vulnerabilities and agentic risk

Overview

This skill is a short Jev workflow guide with disclosed optional CLI install commands, but users should review the remote GitHub install before running it.

Install only if you are comfortable running unpinned code from the referenced GitHub repositories. Prefer pinning a commit, reviewing the package and tool-sync behavior, and running it in a project-local or isolated environment before using it on sensitive repositories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

YARA rule 'agent_skill_remote_bootstrap_execution': Remote script or code download followed by execution/bootstrap installation [agent_skills]

High
Category
YARA Match
Confidence
97% confidence
Finding

The skill instructs users to install code directly from a GitHub repository via pip install git+https://... and then run a module that performs additional repository cloning (tools-sync). This is a real supply-chain risk because it executes unpinned remote code outside a trusted package registry and can change over time; in an agent-skill context, users may copy these commands verbatim, increasing the chance of compromise.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

ed Jev responses.

Jev pipeline

One workflow for Jev question design: find → fit → draft → lint → spread → threshold → cascade. Find decision-shaped LLM calls in a repo, judge whether Jev fits them, draft typed questions from field-tested patterns, lint them, then calibrate on real responses and plan which answers act, pass, or escalate.

If the CLI is installed

bash
pip install git+https://github.com/vicfei/jev-pipeline-skill   # stdlib only
python -m jev_pipeline tools-sync   # once: clones the upstream tool repos (MIT, by reference)
CommandAnswersNeeds
run REPOfind+fit+draft+lint in one passnothing (offline)
find REPOwhich LLM calls output decisions, not text?nothing
fitgo / go-with-guards / no-go per candidateeditable *.answers.json
draftfirst question template per candidatenothing
lintdoes the draft break known rules?nothing
spread RESPONSES.jsonldoes the

Static analysis

No suspicious patterns detected.