Back to skill

Security audit

heirloom-provenance

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local heirloom-record tool that stores family provenance and wish-list data in a plainly disclosed local JSON file.

Install only if you are comfortable keeping family stories, names, estimated values, and inheritance preferences in a plaintext local `heirlooms.json` file. Store that file somewhere private and backed up, and avoid placing it in shared folders or public repositories.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes commands that read from and write to local files (heirlooms.json, storybook export, tag/report output) but does not declare an explicit tool scope such as permissions or allowed-tools. That creates a permission-model gap: an agent or runtime may infer broader file access than users expect, increasing the risk of unauthorized reads/writes in the working directory or adjacent paths if the implementation is extended or misused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

In cmd_interview, the code appends who, date, and object association to the database and saves it immediately. Although the module docstring mentions a local JSON store, there is no inline prompt or explicit warning at the point of collection that personal/family-history data will be retained on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

cmd_wish writes a person's name, desired object, ranking, and date into heirlooms.json. These preference records may be sensitive in estate contexts, but the code provides no disclosure beyond indicating the wishes are 'sealed' until reveal, which does not warn that the data is stored locally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.