Back to skill

Security audit

concept-cartographer

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local learning-map tool; its only notable risk is that optional output commands can write or overwrite files you name.

Install only if you want a local Python learning-path CLI. When using --output, write to a new or intended file path because existing files may be overwritten. Avoid passing private or untrusted custom graph files unless you are comfortable with the tool reading that JSON content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation instructs users to run commands that write output files (for example with --output my_plan.json and --output diagram.md), but the manifest declares no explicit tool scope such as permissions or allowed-tools. That mismatch means the skill appears capable of file writes without a declared boundary, which weakens least-privilege controls and can lead to unauthorized or unexpected file creation/overwrite if an agent executes the workflow automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code writes JSON output to a user-specified path, but the file contains no warning comment, docstring note, or user-facing disclosure that existing files may be created or overwritten. Because this is a code file, file writes are in scope for missing-warning review when there is no visible disclosure beyond the CLI option itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The visualize command writes rendered output to a user-provided file path, but there is no explicit disclosure in comments, help text, or printed warning that the command modifies the filesystem. Under the code-file criteria, file writes should have some visible user disclosure unless already clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.