Back to skill

Security audit

furnace-panic-doctor

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent furnace-troubleshooting guidance, but it includes a consumer electrical bypass step and default local logging that deserve review before installation.

Review carefully before installing or using. Treat it as decision support only: avoid the thermostat jumper step unless a qualified person confirms it is a low-voltage conventional thermostat circuit and uses proper precautions, and be aware that the helper script may create ~/.furnace_log.json unless run with --no-log.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill advertises no explicit tool or permission scope, yet static analysis detected file-write capability in the associated code. That mismatch is a real security issue because users and orchestrators cannot accurately assess what the skill may modify, and hidden write behavior can alter local files, logs, configs, or other artifacts beyond the user’s expectation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to jump R↔W at the thermostat base with a paperclip describes an improvised electrical bypass without an explicit warning to shut off power, avoid shorting other terminals, or limit the action to low-voltage thermostat circuits only. In a consumer-facing HVAC troubleshooting skill, that omission can lead users to contact the wrong terminals, cause equipment damage, blow a fuse/transformer, or create a shock/arc risk if the user misidentifies the system or wiring.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The table presents DIY actions for combustion-heating equipment without a prominent general safety warning at the start covering shutoff of power/gas, carbon monoxide risk, and boundaries on homeowner repair. Although some rows do escalate to emergency or professional help, a user skimming the document could attempt troubleshooting on a furnace in unsafe conditions, especially around ignition, gas, venting, or electrical faults.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.