Back to skill

Security audit

Sirchmunk

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local file-search skill, but it needs review because broad local paths and LLM-backed search are under-scoped and the wrapper has dependency and input-handling risks.

Install only if you trust the Sirchmunk backend and the LLM endpoint you configure. Pin the package version, run it in an isolated environment, restrict `SIRCHMUNK_SEARCH_PATHS` to approved project folders, avoid secret or credential directories, and treat search queries and matched content as potentially visible to the configured service/model.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned Third-Party Package Installation

Content
View full analysis
Remediation
View remediation
' ``` 2. Maintain a locked requirements file with package hashes and install with hash enforcement: ```bash python3 -m pip install --require-hashes -r requirements.txt ``` 3. Verify the package's official registry namespace and document the expected publisher and source repository. 4. Review the pinned package and its transitive dependencies before updating. 5. Install the package in an isolated virtual environment rather than the user's global Python environment. 6. Run the service as a non-privileged account and grant it access only to explicitly approved search directories. 7. Protect `~/.sirchmunk/.env` with restrictive file permissions and use a narrowly scoped LLM API key. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sirchmunk_search.sh:15
Finding

Unescaped User Input in JSON Request Body

Content
View full analysis
/dev/null || cat ``` ### Technical Analysis The script inserts the caller-controlled `QUERY` and `PATHS` values directly into a JSON document. Shell quoting prevents ordinary shell command substitution from being re-evaluated after parameter expansion, so this is not demonstrated shell command injection. However, the values are not JSON-escaped. An argument containing quotation marks, backslashes, control characters, or JSON syntax can terminate its intended string and change the structure of the request. For example, an attacker-controlled path can close the array or inject additional object members. The resulting behavior depends on how the Sirchmunk API handles malformed JSON, duplicate keys, and unexpected fields. Using a caller-selected path is related to the declared local-search functionality, but accepting it without structural encoding or an allowlist is broader than necessary. The issue is particularly relevant if another agent, application, or untrusted document can influence the arguments passed to this wrapper. ### Attack Path 1. An attacker influences the query or path argument supplied to `sirchmunk_search.sh`. 2. The attacker includes JSON delimiters such as quotes, commas, brackets, or braces in that argument. 3. The script interpolates the value directly into the request body without JSON encoding. 4. The request sent to `http://localhost:8584/api/v1/search` is malformed or has an atta ...[truncated 1100 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/sirchmunk_search.sh (reported line 22)May include surrounding context.

sh
PATHS_JSON="[\"$PATHS\"]"
fi

curl -s -X POST "http://localhost:8584/api/v1/search" \
  -H "Content-Type: application/json" \
  -d "{
    \"query\": \"$QUERY\",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell-based execution examples and operational behavior but does not declare any explicit tool scope or permission boundaries. That increases the risk that an agent may invoke shell-capable behavior without clear constraints, making misuse, overreach, or unsafe command execution more likely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description is broad enough that the skill could be selected for many generic file- or content-search requests without clear limitations on what paths or content are in scope. In an agent environment, overly broad routing can expose sensitive local files to search operations or cause the model to use this skill in situations the user did not intend.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
81% confidence
Finding

The skill sends user queries and configured local search paths to an HTTP service, which is an external transmission boundary even if the endpoint is localhost. Because the backend relies on an LLM configuration and searches local files, sensitive file contents or metadata may be transmitted to another service layer without any documented access controls, sanitization, or transport/authentication guarantees.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

Under the hood:

bash
curl -s -X POST "http://localhost:8584/api/v1/search" \
  -H "Content-Type: application/json" \
  -d '{
    "query": "<your query>",

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/sirchmunk_search.sh (reported line 22)May include surrounding context.

sh
PATHS_JSON="[\"$PATHS\"]"
fi

curl -s -X POST "http://localhost:8584/api/v1/search" \
  -H "Content-Type: application/json" \
  -d "{
    \"query\": \"$QUERY\",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This shell script sends the user's query and optional paths in an HTTP POST request to a local service, but the script provides no visible notice beyond a generic usage line that data will be transmitted over the network. For code files, network calls that transmit user or system data should have some disclosure such as a prompt, log message, or documented warning unless the warning is otherwise explicit.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.