Back to skill

Security audit

internet-outage-warlord

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent internet-outage diagnostic tool, but its monitor mode can execute any supplied shell command when the connection goes down, so it needs careful review before installation.

Install only if you are comfortable with a network diagnostic script that writes a local outage log and contacts public test endpoints. Avoid using --notify with arbitrary shell text; prefer running diagnose/report manually or replacing notification with a fixed, trusted notifier command you fully control.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (12)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The monitor feature includes a generic command-execution hook that is not necessary for diagnosing outages or building ISP evidence. Because it turns a connectivity monitor into a shell execution primitive triggered by network state changes, it creates a meaningful abuse path in environments where an agent may pass or transform parameters automatically.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

This is a tool-parameter abuse issue because a normal-looking runtime parameter directly controls a shell execution sink. If an attacker can influence the notify string, they can escalate a benign outage-monitoring tool into arbitrary command execution, persistence, or data exfiltration on outage events.

Content

Scanner excerpt · scripts/outage_warlord.py (reported line 230)May include surrounding context.

python
print(f"{ts}  {cur}  ({v})")
            if notify and cur == "DOWN":
                try:
                    subprocess.run(notify, shell=True, timeout=15)
                except Exception:
                    pass
            state = cur

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

md
# VERDICT: ISP  (gateway ok, 100% loss to 1.1.1.1/8.8.8.8, DNS dead)
#   actions: 1. check ISP status via mobile data  2. report once, get ticket
#            3. start monitor — this outage is now evidence  4. SLA credit accruing
python3 scripts/outage_warlord.py monitor --interval 120 --notify "curl -s -d 'NET DOWN' ntfy.sh/home >/dev/null"
# ...next day...
python3 scripts/outage_warlord.py report --sla-credit --contract "100Mbps, SLA 99.5%"
# OUTAGE WINDOWS (2): 16:02->16:49 [ISP]  18:02->18:50 [ISP]

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/isp-evidence-playbook.md (reported line 56)May include surrounding context.

md
# VERDICT: ISP  (gateway ok, 100% loss to 1.1.1.1/8.8.8.8, DNS dead)
#   actions: 1. check ISP status via mobile data  2. report once, get ticket
#            3. start monitor — this outage is now evidence  4. SLA credit accruing
python3 scripts/outage_warlord.py monitor --interval 120 --notify "curl -s -d 'NET DOWN' ntfy.sh/home >/dev/null"
# ...next day...
python3 scripts/outage_warlord.py report --sla-credit --contract "100Mbps, SLA 99.5%"
# OUTAGE WINDOWS (2): 16:02->16:49 [ISP]  18:02->18:50 [ISP]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes capabilities that read and write local logs, invoke shell-based probes, and perform network diagnostics, but it does not declare any explicit tool scope or permission boundaries. In an agent environment, that ambiguity can allow the skill to be executed with broader-than-necessary privileges, increasing the chance of unintended file access, arbitrary command execution, or uncontrolled network activity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The listed triggers include very common phrases such as 'The internet is down', 'Wi‑Fi is down', and 'websites won't load', which are broad natural-language requests likely to occur in ordinary conversation. The file provides examples of when to use the skill, but it does not define explicit invocation boundaries or negative examples to prevent unintended activation.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/outage_warlord.py (reported line 42)May include surrounding context.

python
system = platform.system()
    try:
        if system == "Linux":
            out = subprocess.run(["ip", "route", "show", "default"], capture_output=True, text=True, timeout=5).stdout
            m = re.search(r"via (\d+\.\d+\.\d+\.\d+)", out)
            return m.group(1) if m else None
        if system == "Darwin":

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/outage_warlord.py (reported line 46)May include surrounding context.

python
m = re.search(r"via (\d+\.\d+\.\d+\.\d+)", out)
            return m.group(1) if m else None
        if system == "Darwin":
            out = subprocess.run(["route", "-n", "get", "default"], capture_output=True, text=True, timeout=5).stdout
            m = re.search(r"gateway: (\d+\.\d+\.\d+\.\d+)", out)
            return m.group(1) if m else None
        out = subprocess.run(["powershell", "-c", "(Find-NetRoute -RemoteIPAddress 1.1.1.1).NextHop[0]"],

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/outage_warlord.py (reported line 49)May include surrounding context.

python
out = subprocess.run(["route", "-n", "get", "default"], capture_output=True, text=True, timeout=5).stdout
            m = re.search(r"gateway: (\d+\.\d+\.\d+\.\d+)", out)
            return m.group(1) if m else None
        out = subprocess.run(["powershell", "-c", "(Find-NetRoute -RemoteIPAddress 1.1.1.1).NextHop[0]"],
                             capture_output=True, text=True, timeout=10).stdout.strip()
        return out or None
    except Exception:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/outage_warlord.py (reported line 64)May include surrounding context.

python
tval = str(timeout * 1000) if system == "Windows" else str(timeout)
    try:
        cmd = ["ping", flag, str(count), tflag, tval, host]
        out = subprocess.run(cmd, capture_output=True, text=True, timeout=timeout * count + 5).stdout
        ok = ("ttl=" in out.lower()) or ("time=" in out.lower()) or (", 0% loss" in out.lower()) or ("(0% loss)" in out.lower())
        times = [float(x) for x in re.findall(r"time[=<]([\d.]+) ms", out)]
        loss_m = re.search(r"(\d+)% (?:packet )?loss", out)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
99% confidence
Finding

This code executes the user-supplied --notify value with shell=True whenever the monitor detects a DOWN event, allowing arbitrary shell command execution. In an agent or automation context, a crafted parameter can run any command with the privileges of the process, exceeding the skill's diagnostic scope.

Content

Scanner excerpt · scripts/outage_warlord.py (reported line 230)May include surrounding context.

python
print(f"{ts}  {cur}  ({v})")
            if notify and cur == "DOWN":
                try:
                    subprocess.run(notify, shell=True, timeout=15)
                except Exception:
                    pass
            state = cur

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The CLI exposes --notify as an ordinary string parameter without clearly warning that it will be executed as a shell command. This increases the chance of unsafe use, accidental injection, or misuse by higher-level tooling that treats it as harmless configuration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.