Back to skill

Security audit

api-spec-to-mock-server

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a simple agent instruction for generating mock API servers, with some sloppy template documentation but no evidence of hidden, destructive, persistent, or exfiltrating behavior.

Installers should treat this as a low-risk but rough scaffold: verify generated mock-server files before running them, choose trusted dependencies if the agent uses Prism/Mockoon/Express/Flask, and do not rely on the README's API_KEY or read/write mode examples without clarification from the publisher.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says this skill should turn an API spec into a runnable mock server. However, the provided code does not parse OpenAPI or Swagger, generate routes, start a server, or produce any mock API behavior. Its primary function is entirely different: it runs compliance-style tests against a skill repository's markdown/frontmatter and file layout. This is a material description-behavior mismatch, not a minor implementation detail.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- Do not make up facts or claim actions were taken that were not
- Do not hardcode API keys — use `os.getenv("API_KEY")` instead
- Do not store sensitive user data beyond the current session
- Do not exceed token budget without warning the user first
- Do not activate for off-topic requests — return a brief decline message

### Do

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction 'Keep SKILL.md body in English' imposes a language requirement in natural-language guidance. Under the policy, forcing a specific language without opt-in or a clearly justified regional/compliance reason is a locale-policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This line explicitly mandates 'SKILL.md body must be in English; reference docs in English,' which is a natural-language policy constraint. The file does not provide opt-in, alternatives, or a justified reason for enforcing a single language.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The line 'When triggered: [trigger condition].' leaves the invocation condition undefined. For a markdown file, this creates an ambiguous trigger scope because users and calling systems cannot tell exactly when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README advertises a write mode using an input file but does not warn that running in write mode may create or modify files. In an agent or automation context, unclear write-side effects can lead users or higher-level systems to invoke the skill with insufficient safeguards, causing unintended file changes, overwrites, or workspace pollution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Line L13 states '触发条件:[trigger condition]。' without specifying actual trigger phrases or constraints. In a markdown skill description, this makes invocation conditions ambiguous and could lead to unintended activation because users and tooling are not told when the skill should or should not apply.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documented usage advertises a generic "read" mode and a "write" mode with JSON input, which contradicts the skill's stated purpose of turning an OpenAPI/Swagger spec into a runnable mock server. This is not merely incomplete documentation: it describes behavior centered on generic file read/write actions rather than mock-server generation from API specs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown shows a '--mode write' invocation at L39-L40, which implies file-writing behavior, but there is no accompanying warning about potential changes to user data or filesystem state. For markdown files, operations that can affect user data or system integrity should be disclosed clearly.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The configuration section says API_KEY is required, but the surrounding documentation describes a local transformation from API spec to runnable mock server and provides no explanation for any external service dependency. This creates an intent/documentation contradiction by implying a required authenticated service even though the skill is presented as a spec-to-mock-server generator.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
- Do not make up facts or claim actions were taken that were not
- Do not hardcode API keys — use `os.getenv("API_KEY")` instead
- Do not store sensitive user data beyond the current session
- Do not exceed token budget without warning the user first
- Do not activate for off-topic requests — return a brief decline message

### Do

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The test requires the presence of README_zh.md, which imposes a specific language/locale artifact as a mandatory project condition. This is a natural-language policy concern because it enforces a locale-specific requirement without any visible opt-in or documented region-specific justification in this file.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file defines a correct test runner _main() earlier, then silently redefines _main() at the end to call _run_unit_tests(), which is undefined. Because the if __name__ == '__main__': sys.exit(_main()) block appears before the redefinition, normal script execution still uses the first _main(), but any importer or harness that resolves _main after module load will invoke the poisoned version and fail. In a testing skill, this kind of entrypoint shadowing undermines reliability and can be used to sabotage automation in a non-obvious way.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.