Back to skill

Security audit

log-to-incident-report

Security checks for vulnerabilities and agentic risk

Overview

This skill is a narrow log-analysis helper with some boilerplate documentation problems but no evidence of hidden execution, persistence, exfiltration, or destructive behavior.

Install only if you are comfortable pasting logs into the agent context. Redact tokens, API keys, personal data, internal hostnames, and customer identifiers first. Treat the README read/write and API_KEY sections as boilerplate until clarified by the publisher.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared purpose says the skill should process error logs and produce an incident report with root cause, impact, and remediation steps. The actual code does not parse logs, analyze incidents, infer causes, assess impact, or generate fixes. Instead, it implements a QA/compliance test harness for a skill repository. Its primary behavior is materially different from the declared description, and it exercises undeclared capabilities such as filesystem inspection and secret scanning. This is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
- Do not make up facts or claim actions were taken that were not
- Do not hardcode API keys — use `os.getenv("API_KEY")` instead
- Do not store sensitive user data beyond the current session
- Do not exceed token budget without warning the user first
- Do not activate for off-topic requests — return a brief decline message

### Do

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instruction to 'Keep SKILL.md body in English' imposes a language requirement in contributor guidance. Under the policy, forcing a specific language is a natural-language policy violation unless the file offers a choice or clearly documents a justified locale constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This line explicitly mandates that the SKILL.md body and reference docs 'must be in English.' That is a language-policy constraint stated in natural language, and no user choice or region/compliance justification is provided in the file.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README says "When triggered: [trigger condition]" without defining any actual invocation phrase or boundary. This leaves the activation scope unspecified, increasing the chance of unintended or inconsistent skill invocation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a focused analysis skill for turning error logs into a structured incident report with root cause, impact, and fix steps. The README instead documents generic "read" and especially "write" modes, which imply broader file-operation behavior unrelated to the stated purpose and conflict with the skill's narrowly described intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The usage example includes a --mode write operation with an input file, but the README does not explain whether this mode writes files, modifies user data, or has other system effects. For markdown descriptions, potentially data-affecting behavior should be disclosed so users understand the risk before running the skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L13 states the trigger as "[trigger condition]" rather than providing concrete invocation phrases or constraints. This makes it unclear when the skill should activate versus not activate, which matches the vague-trigger category for markdown files.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation describes a generic "read" mode and a "write" mode with JSON input, which suggests file-style data access behavior rather than converting provided error logs into a structured incident report. This is an intent-level contradiction because the surrounding documentation frames the skill as report generation from logs, but the usage instructions imply different operational semantics.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill invites users to paste raw error logs but does not warn that logs often contain secrets, tokens, internal hostnames, PII, or other sensitive operational data. That omission can lead users to disclose confidential information into the model context unnecessarily, creating avoidable data exposure risk.

Content

No source excerpt is available for this finding.

Context Window Stuffing

Medium
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
- Do not make up facts or claim actions were taken that were not
- Do not hardcode API keys — use `os.getenv("API_KEY")` instead
- Do not store sensitive user data beyond the current session
- Do not exceed token budget without warning the user first
- Do not activate for off-topic requests — return a brief decline message

### Do

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The test test_readme_zh_exists requires a README_zh.md file to exist, which imposes a specific language/locale requirement in the skill repository. There is no surrounding comment, docstring, or configuration indicating this is optional or justified by a region-specific policy, so it appears to enforce a locale expectation without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
62% confidence
Finding

The file links to a Chinese version, but this alone does not force a language or violate locale policy. However, if the skill defaults users into a specific language without opt-in, that would be a concern; this README does not clearly state the language selection behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The documentation explicitly promises "Preserves data integrity — no silent drops or fabrication," but the README contains template placeholders and inconsistent operating modes instead of concrete implemented behavior. This is an intent/documentation claim that is not supported by the documented skill behavior and could mislead users about what the skill actually guarantees.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document presents the skill instructions entirely in Chinese while not indicating that language selection is optional or that the skill is intended only for Chinese-speaking users. This can violate language/locale policy expectations when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The statement promises "no silent dropping or fabrication," which is a strong behavioral guarantee, yet nearby lines show placeholder/template content rather than concrete implementation-specific documentation. This creates an intent/documentation divergence because the file asserts a precise behavior guarantee without corresponding substantiation in the documented operation of the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.