Back to skill

Security audit

tool-selector

Security checks for vulnerabilities and agentic risk

Overview

The skill is a local DIY planning helper, but it gives under-scoped advice for hazardous electrical, mounting, and improvised tool-substitution tasks.

Review carefully before installing. The skill does not appear to access private data or persist on your system, but its DIY advice should not be treated as authoritative for electrical, structural, load-bearing, plumbing, or safety-critical work. Use proper tools and PPE, follow local code and manufacturer instructions, and consult a qualified professional for high-risk tasks.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/project_planner.py:182
Finding

Malformed Tool Record Causes Deterministic Project Planner Failure

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/tool_substitution.py:65
Finding

Hazardous Improvised Wire-Stripping Methods Presented as Tool Substitutions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code is broadly aligned with DIY project planning: it outputs tools, materials, cost estimates, and step-by-step instructions, and it accepts a list of tools the user already has. However, key parts of the declared description are not actually implemented. The script does not find or suggest substitute tools, and its handling of available tools is limited to annotating listed tools with icons rather than explicitly identifying missing tools or filtering the plan based on tool availability. Tool recommendations are static entries in the project database, not dynamic recommendations tailored to the job. It is also restricted to a predefined set of projects rather than generically planning arbitrary DIY or home repair tasks. No hidden or unrelated sensitive capabilities are present, but the description overstates the implemented functionality enough to count as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a broad DIY planning assistant with project descriptions, materials, cost estimates, tool filtering, and missing-tool detection. The supplied code only implements one narrow sub-feature: recommending substitute tools for a single requested tool via a static lookup table. There is no project analysis, no materials or cost logic, no step-by-step generation, and no inventory-aware filtering. While tool substitution is mentioned in the description, the actual code is materially narrower than the declared primary purpose, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README provides step-by-step DIY guidance involving cutting, drilling, fastening, and wall-mounting without meaningful safety disclaimers, PPE guidance, or recommendations to verify structural/electrical conditions before work. Users may follow the instructions as authoritative and suffer injury, property damage, or unsafe installations, especially beginners explicitly targeted by the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file enumerates potentially hazardous DIY categories, including plumbing and electrical work, without any safety caveats, skill-boundary guidance, or recommendation to consult licensed professionals for high-risk tasks. In the context of a tool-selection skill intended to guide users through home repair projects, this omission could encourage inexperienced users to attempt dangerous work and increases the chance of injury, property damage, or code-compliance issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill provides electrical DIY instructions for ceiling fan installation, a task with real shock, fire, and code-compliance risks, but does not consistently require professional consultation or local code verification before proceeding. Although it includes some safety notes, users may still rely on the generated steps as sufficient guidance and perform hazardous work incorrectly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest promises richer planning behavior: recommending the right tool for each job, finding substitutions, and flagging missing tools based on available tools. In the implementation, plan_project only prints a combined tool list with simple owned/not-owned icons derived from substring matching, without any substitution logic or dedicated missing-tool analysis.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script provides actionable substitutions for potentially dangerous tools, including clearly unsafe or imprecise alternatives such as stripping wire with a utility knife, estimating torque by feel, or using teeth on wire insulation, without an upfront safety warning or context gating. In a DIY-planning skill, users may treat the output as trusted guidance and attempt hazardous substitutions on electrical, mechanical, or cutting tasks, increasing the risk of injury or property damage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The wall-mounting guidance covers a load-bearing installation where mistakes can cause a TV to fall, injuring users or damaging property, but the warnings are not as explicit or prominent as the risk warrants. In a planning skill, concise instructions may be mistaken for authoritative installation guidance even when structural conditions vary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.