Back to skill

Security audit

complaint-cannon

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local complaint-letter and case-tracking tool with disclosed local storage and no evidence of hidden network activity, persistence, or automatic posting.

Install only if you want a local tool for drafting consumer complaint escalations. Before sending letters, regulator filings, CEO emails, or public reviews, verify the legal/regulatory claims, remove account numbers and private personal data, and make sure the timeline is accurate and supportable.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares no explicit tool scope or permissions, yet its documented behavior implies local file read/write (complaints.json, evidence references) and potential network-enabled actions such as regulator routing or sending escalation content. Without an allowlist, an agent runtime may grant broader capabilities than necessary, increasing the risk of unintended file access or outbound communication if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The generated escalation and final-notice letters explicitly threaten to 'publish the documented record' and the plan output recommends 'public review + exec email TOGETHER' without any explicit user confirmation, privacy warning, or redaction guidance. Because the stored timeline and contacts may contain personal data, account details, or defamatory/unverified statements, the tool can nudge users into disclosing sensitive information or posting risky content they did not mean to make public.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.