Back to skill

Security audit

agent-tracer

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent tracing purpose, but it encourages broad raw logging of agent tool calls to a network service without enough privacy, security, or deployment safeguards.

Install only if you are comfortable with agent activity being stored in the tracer. Keep it bound to localhost unless you have authentication, TLS, and firewall controls; do not log secrets, credentials, private files, customer data, or personal data without redaction and a retention/deletion plan.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:22
Finding

Unredacted Collection of Tool Arguments and Results

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:16
Finding

Plaintext Configurable Telemetry Destination and Network-Wide Service Binding

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

bash
# 1. 创建 trace,拿到 trace_id
TRACE_ID=$(curl -s -X POST $TRACER_BASE_URL/traces \
  -H 'Content-Type: application/json' \
  -d '{"agent":"market-bot","task":"收盘汇总","session_id":"sess-001"}' \
  | python3 -c "import sys,json;print(json.load(sys.stdin)['trace_id'])")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is explicitly designed to record every tool call, including agent tasks, session identifiers, arguments, results, model names, and token counts, and send them to a network service. The documentation provides no warning about sensitive-data handling, retention, minimization, access control, or consent, so users may inadvertently transmit confidential prompts, tool outputs, or personal data to the tracer backend.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

bash
# 1. 创建 trace,拿到 trace_id
TRACE_ID=$(curl -s -X POST $TRACER_BASE_URL/traces \
  -H 'Content-Type: application/json' \
  -d '{"agent":"market-bot","task":"收盘汇总","session_id":"sess-001"}' \
  | python3 -c "import sys,json;print(json.load(sys.stdin)['trace_id'])")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example workflow posts detailed execution data to the tracer service, including task names, session IDs, tool arguments, and tool results, but gives no user-facing warning that these fields may expose proprietary, regulated, or personal information. Because this is sample code users are likely to copy directly, it materially increases the chance of accidental data disclosure and long-term retention in the tracing system.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This example transmits raw tool-call arguments and results to the tracer service, which can easily include secrets, internal documents, personal data, or model outputs with sensitive content. In the context of an agent tracing skill, this is especially dangerous because comprehensive logging is encouraged by design, amplifying the blast radius of any backend compromise, misconfiguration, or over-retention.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

md
| python3 -c "import sys,json;print(json.load(sys.stdin)['trace_id'])")

# 2. 每次工具调用记一条 span(model/tokens 可选,带上才有成本分析)
curl -s -X POST $TRACER_BASE_URL/traces/$TRACE_ID/spans \
  -H 'Content-Type: application/json' \
  -d '{"tool_name":"web_search","arguments":{"query":"上证指数"},
       "result":"上证 3200.15 +0.85%","duration_ms":850,

Static analysis

No suspicious patterns detected.