Back to skill

Security audit

sleep-shift-survivor

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local shift-work sleep planner whose file writes are disclosed and limited to a local JSON log.

Before installing, understand that it stores shift schedules, sleep times, quality ratings, and notes in `shift_sleep.json` in whatever directory you run it from. Avoid entering sensitive health details you do not want stored locally, and treat the screening output as informational rather than medical advice.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/shift_sleep.py (reported line 106)May include surrounding context.

python
# ---------- plan ----------

def day_plan(kind: str, sched: dict, is_first_night: bool, prev_kind: str) -> list:
    """Return instruction lines for one roster day of block kind."""
    shifts = sched["shifts"]
    lines = []
    a0, a1 = sched["anchor"]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documentation indicates local file read/write behavior via shift_sleep.json in the current working directory and logging/report commands, but it does not declare any explicit tool scope or permissions. This creates a permission transparency gap: an agent or reviewer may assume the skill is purely advisory while it can persist or access local data, increasing the risk of unintended file access or writes in a broader execution context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.