Back to skill

Security audit

tire-pressure-coach

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local tire-pressure helper with no exfiltration behavior, but it overstates safety-critical capabilities and contains pressure math that could give unsafe advice.

Review this before installing if you might rely on it for real tire settings. It appears local and non-exfiltrating, but its safety advice is not complete and the altitude correction is unsafe as written; use the vehicle placard/manual or a tire professional for load, towing, high-speed, TPMS faults, altitude, and edge cases.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill promises safety-relevant capabilities such as load/speed corrections and TPMS decoding, but the analysis indicates those features are missing or only partially implemented while additional persistent logging behavior exists. In a vehicle-maintenance context, that mismatch can mislead users into trusting incomplete pressure guidance or generic TPMS advice, creating a real safety risk from underinflation, overload use, or delayed response to tire faults.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes and relies on persistent local storage (tire_coach.json) and logging behavior, but it declares no explicit tool or permission scope. That creates an unnecessary trust gap: an agent may grant broader file read/write capability than users expect, and the undeclared persistence can expose historical vehicle/service data or enable unintended modification of nearby files if implementation is loose.

Content

No source excerpt is available for this finding.

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.