Back to skill

Security audit

knitting-pattern-solver

Security checks for vulnerabilities and agentic risk

Overview

This is a local knitting helper with some overstated feature breadth, but its behavior is disclosed, purpose-aligned, and does not show hidden access or unsafe actions.

Review the examples and expect a lightweight local CLI helper rather than a complete knitting project manager. It should be safe to install from the inspected artifact, but users should verify calculations for complex patterns because some documented notation support is limited.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code substantially matches the knitting-pattern domain and core behaviors around abbreviation decoding, repeat expansion, stitch-count tracking, and row verification. However, one explicitly declared capability is absent: there is no logic for gauge input, yarn estimation, yardage calculations, or project planning based on gauge. The implementation is a CLI parser/verifier for stitch operations and rows, not a yarn-requirement calculator. Also, while it can format row explanations and expand repeats in limited ways, it does not fully implement broad row-by-row generation from condensed patterns beyond parsed explanations. There are no suspicious undeclared external accesses or permissions; the mismatch is functional overstatement in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code is clearly knitting-related and does implement one declared sub-capability: calculating yarn requirements from gauge. However, the declared description presents a broader skill centered on parsing, decoding, and expanding knitting patterns, including abbreviation translation, stitch tracking, and row-by-row instruction generation. None of those behaviors are present in the supplied code. Instead, the actual code only accepts numeric gauge/project inputs, estimates yardage with a buffer, derives dimensions, and recommends skein counts by yarn weight. This is a materially narrower and different primary behavior than the declared pattern-understanding assistant, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.