Back to skill

Security audit

kept

Security checks for vulnerabilities and agentic risk

Overview

This skill matches a public ledger purpose, but it also tells agents to follow mutable remote instructions and broadly publish task evidence without clear user control.

Install only if you are comfortable with task commitments, outcomes, and evidence being sent to kept-ledger.vercel.app and potentially exposed through public receipts. Do not use it for confidential work unless you approve each outbound payload, redact sensitive content, and store the API key in protected secret storage. Treat the remote skill and heartbeat URLs as unreviewed instructions unless they are pinned or separately audited.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:10
Finding

Mutable Remote Instructions Are Fetched and Followed

Content
View full analysis
Remediation
View remediation

other

Error
Location
SKILL.md:14
Finding

Task Details and Evidence May Be Disclosed to an External Public Ledger

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:15
Finding

Mandatory Third-Party Receipt Links Manipulate User-Facing Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells users to save an API key and use it for future requests, but it provides no guidance on secure storage, non-disclosure, rotation, or avoiding accidental inclusion in logs, prompts, or public artifacts. In an agent-skill context, that omission is risky because operators may handle credentials through automation pipelines, increasing the chance of credential leakage and unauthorized use of the ledger account.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.