Back to skill

Security audit

Action Guard

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent local action log, but its non-atomic check-then-record workflow can fail for concurrent irreversible actions it claims to prevent.

Review before installing if you intend to use this for money movement, public posting, production deploys, or any other irreversible action. It is reasonable as a simple personal reminder log, but it should not be trusted as an exactly-once concurrency control unless the author adds atomic reservations or locking, restrictive ledger permissions, and clear recovery behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/guard.js:47
Finding

Non-Atomic Check-and-Record Workflow Permits Duplicate Irreversible Actions

Content
View full analysis
a.type === type && a.target === target); if (direct) { console.error(`DUPLICATE: Already performed ${type} on ${target}`); console.error(` Date: ${direct.ts}`); if (direct.note) console.error(` Note: ${direct.note}`); process.exit(1); } // Parent match — already acted on this parent (catches reply-to-same-post) const parentMatch = actions.find(a => a.type === type && a.parent === target); if (parentMatch) { console.error(`DUPLICATE: Already performed ${type} on parent ${target}`); console.error(` Via: ${parentMatch.target}`); console.error(` Date: ${parentMatch.ts}`); if (parentMatch.note) console.error(` Note: ${parentMatch.note}`); process.exit(1); } console.log(`OK: No prior ${type} on ${target}`); process.exit(0); } // Record an action function record(type, target) { const note = getOpt('note') || ''; const parent = getOpt('parent') || undefined; const action = { type, target, ...(parent && { parent }), ...(note && { note }), ts: new Date().toISOString(), }; appendAction(action); console.log(`RECORDED: ${type} ${target}${parent ? ' (parent: ' + parent + ')' : ''}`); } ``` The documented calling pattern separates checking, performing the external operation, and recording: ```text BEFORE each action: node guard.js check If exit 1 → SKIP (already done) DO the action AFTER success: node guard.js record --note "what you did" --parent ``` ### Technical Analysis Deduplication is implemente ...[truncated 1806 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/guard.js:20
Finding

Action Ledger Append Can Follow an Attacker-Prepared Symbolic Link

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

md
node scripts/guard.js check <action-type> <target-id>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
node scripts/guard.js check <action-type> <target-id>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
node scripts/guard.js check <action-type> <target-id>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
node scripts/guard.js check <action-type> <target-id>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
node scripts/guard.js check <action-type> <target-id>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
node scripts/guard.js check <action-type> <target-id>

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
node scripts/guard.js check <action-type> <target-id>

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code appends action metadata to a local JSONL file, which is a file-write operation affecting user/system data. Although the CLI help documents the data directory option, it does not clearly warn that targets, notes, and parent identifiers will be persisted on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.