Back to skill

Security audit

senior-security

Security checks for vulnerabilities and agentic risk

Overview

This security skill appears to be a placeholder that advertises audits, threat modeling, and penetration testing but reports success without doing real checks.

Review this skill carefully before installing. It does not show evidence of credential theft, persistence, or destructive behavior, but it should not be trusted for real security audits, penetration tests, threat models, or compliance decisions until its documentation is corrected and its tools perform real checks with clear coverage and limitations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/security_auditor.py:43
Finding

Security Auditor Unconditionally Reports Success Without Performing Analysis

Content
View full analysis

Vulnerability Details

File Location: scripts/security_auditor.py:43-51
Vulnerability Type: False security assurance caused by an unimplemented analysis routine
Risk Level: High

Vulnerable Code

python
def analyze(self):
    """Perform the main analysis or operation"""
    if self.verbose:
        print("📊 Analyzing...")

    # Main logic here
    self.results["status"] = "success"
    self.results["target"] = str(self.target_path)
    self.results["findings"] = []

Technical Analysis

The analyze() method does not open, enumerate, parse, or inspect any content under the supplied target path. It unconditionally sets the assessment status to success and initializes an empty findings list.

The only preceding validation checks whether the target path exists. Consequently, any existing path—including a project containing known vulnerabilities—is reported as successfully audited with zero findings. This conflicts with the deep-analysis and comprehensive-auditing capabilities advertised in SKILL.md.

This is a fail-open security design: an unavailable or unimplemented security control presents its result as a successful assessment rather than explicitly reporting that analysis was not performed.

Attack Path

  1. An attacker introduces vulnerable or malicious code into a project.
  2. An operator invokes python scripts/security_auditor.py <target-path>.
  3. The script verifies only that the path exists.
  4. The analyze() method performs no inspection and records status as success.
  5. The generated report displays zero findings.
  6. The operator may approve or deploy the vulnerable project based on the false result.

Impact Assessment

Exploitation does not directly grant operating-system privileges or execute attacker-controlled code. The impact is instead on the integrity and reliability of the security-review process. Vulnerabilities, malicious code, exposed ...[truncated 223 chars]

Remediation
View remediation

Remediation Suggestions

  • Implement actual recursive target discovery and security analysis appropriate to each supported language and configuration format.
  • Until analysis is implemented, terminate with a nonzero exit status and return an explicit not_implemented or analysis_not_performed status.
  • Never equate successful program execution with a successful security assessment.
  • Track whether at least one supported file was inspected and report unsupported or unreadable files.
  • Distinguish clean, vulnerable, incomplete, failed, and unsupported outcomes.
  • Add automated tests containing known vulnerable fixtures and require the auditor to detect them.
  • Add negative tests confirming that empty, unreadable, unsupported, and partially analyzed targets cannot produce an unconditional clean result.
  • Update SKILL.md so documented capabilities accurately reflect implemented behavior.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/pentest_automator.py:43
Finding

Pentest Automator Unconditionally Reports Success Without Performing Penetration Testing

Content
View full analysis

Vulnerability Details

File Location: scripts/pentest_automator.py:43-51
Vulnerability Type: False security assurance caused by an unimplemented testing routine
Risk Level: High

Vulnerable Code

python
def analyze(self):
    """Perform the main analysis or operation"""
    if self.verbose:
        print("📊 Analyzing...")

    # Main logic here
    self.results["status"] = "success"
    self.results["target"] = str(self.target_path)
    self.results["findings"] = []

Technical Analysis

The advertised penetration-testing tool does not perform reconnaissance, target inspection, vulnerability checks, or any other testing. Its analysis routine merely records the supplied path, assigns a successful status, and returns an empty findings list.

Because target existence is the only prerequisite for success, the output cannot distinguish a secure target from a vulnerable one. Presenting an unexecuted penetration test as successful creates a fail-open assessment process and materially conflicts with the advanced automation and production-grade output advertised in SKILL.md.

Attack Path

  1. A vulnerable or malicious project is submitted for penetration testing.
  2. An operator runs python scripts/pentest_automator.py <target-path>.
  3. The script confirms that the path exists but performs no security tests.
  4. The analysis routine sets status to success and produces zero findings.
  5. The operator relies on the generated report as evidence that testing completed.
  6. The untested vulnerabilities remain present and may subsequently be exploited.

Impact Assessment

This issue does not itself provide code execution or elevated system privileges. It compromises the integrity of penetration-testing results and can allow exploitable weaknesses to pass review. The affected scope includes all targets assessed with the script and downstream release, acceptance, or compliance pro ...[truncated 29 chars]

Remediation
View remediation

Remediation Suggestions

  • Implement the documented testing functionality with explicit target scoping and authorization controls.
  • Report not_implemented and exit unsuccessfully until real tests are available.
  • Define separate statuses for completed, incomplete, failed, unsupported, and clean assessments.
  • Record which tests ran, their coverage, errors, skipped checks, and supporting evidence.
  • Do not report zero findings unless applicable checks actually completed.
  • Add regression fixtures containing known weaknesses and verify that they generate expected findings.
  • Require explicit authorization before implementing any active network or exploitation behavior.
  • Correct the capability claims in SKILL.md to match the current implementation.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/threat_modeler.py:43
Finding

Threat Modeler Unconditionally Reports Success Without Constructing a Threat Model

Content
View full analysis

Vulnerability Details

File Location: scripts/threat_modeler.py:43-51
Vulnerability Type: False security assurance caused by an unimplemented threat-modeling routine
Risk Level: High

Vulnerable Code

python
def analyze(self):
    """Perform the main analysis or operation"""
    if self.verbose:
        print("📊 Analyzing...")

    # Main logic here
    self.results["status"] = "success"
    self.results["target"] = str(self.target_path)
    self.results["findings"] = []

Technical Analysis

The threat-modeling routine does not inspect architecture, components, trust boundaries, data flows, assets, entry points, or threat scenarios. It always marks the operation successful and returns no findings for any existing target path.

This behavior makes the output independent of the target's actual architecture and risk profile. It creates false assurance because users can reasonably interpret the success message and empty findings list as evidence that a threat model was completed, despite no modeling or analysis having occurred.

Attack Path

  1. A system containing unmodeled trust boundaries or attack surfaces is submitted for assessment.
  2. An operator runs python scripts/threat_modeler.py <target-path>.
  3. The script validates only that the supplied path exists.
  4. No files, architecture descriptions, or data flows are analyzed.
  5. The routine records a successful result with no findings.
  6. Security design decisions proceed without identifying the omitted threats.

Impact Assessment

No direct operating-system privilege or unauthorized access is obtained through this defect. The impact concerns security-governance integrity: design threats, trust-boundary violations, spoofing risks, data exposure paths, and privilege-escalation opportunities may remain unidentified. The scope covers every architecture or project for which this output is treated as a completed threat ...[truncated 7 chars]

Remediation
View remediation

Remediation Suggestions

  • Implement architecture and data-flow ingestion, asset identification, trust-boundary mapping, entry-point discovery, and a documented threat-classification methodology.
  • Require sufficient input to construct a threat model and reject targets lacking usable architecture information.
  • Return an explicit incomplete or unsupported result when modeling cannot be performed.
  • Include generated threats, assumptions, affected assets, mitigations, residual risk, and coverage limitations in reports.
  • Add test projects with predefined threat scenarios and assert that expected threats are identified.
  • Prevent a successful status unless all required modeling stages complete.
  • Revise SKILL.md to avoid advertising functionality that has not been implemented.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is another manifestation of the same description-behavior mismatch: the file presents comprehensive security functions, while the observed behavior appears placeholder-level and includes undisclosed file output. In a security context, overstated capabilities can directly undermine decision-making and create a false sense of safety.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is another manifestation of the same description-behavior mismatch: the file presents comprehensive security functions, while the observed behavior appears placeholder-level and includes undisclosed file output. In a security context, overstated capabilities can directly undermine decision-making and create a false sense of safety.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is another manifestation of the same description-behavior mismatch: the file presents comprehensive security functions, while the observed behavior appears placeholder-level and includes undisclosed file output. In a security context, overstated capabilities can directly undermine decision-making and create a false sense of safety.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

pip install -r requirements.txt

Configure environment

cp .env.example .env

text

### 2. Run Quality Checks

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill advertises scripts that can analyze projects and potentially write outputs or apply fixes, but it declares no explicit tool scope or permissions. That creates a trust and safety gap: users and orchestrators cannot tell in advance that file-modifying behavior may occur, increasing the risk of unintended writes or overbroad execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Overly broad activation language can cause the skill to be invoked for many generic security-related requests beyond its proven competence. In a security domain, over-triggering increases the chance that users receive irrelevant, incomplete, or falsely authoritative guidance, which can lead to unsafe actions or misplaced trust.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The markdown mentions automated fixes but does not warn that user files may be modified. Undisclosed modification behavior is dangerous because users may run the tool expecting analysis only, leading to accidental changes, corruption, or unreviewed edits in sensitive codebases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Penetration-testing automation can be disruptive, legally sensitive, or trigger unintended network and system effects, yet the documentation provides no caution or scope restrictions. In the context of a broadly described security skill, this omission materially increases the risk of misuse against unauthorized targets or accidental impact on production systems.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file presents itself as a pentest/security automation tool, but the implementation only validates a local path, sets a hardcoded success result, and prints a report with no actual security testing. In a security skill, this is dangerous because users may rely on a false sense of assessment coverage and conclude a target was analyzed when no meaningful checks occurred.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The runtime behavior does not match the manifest's claimed comprehensive security engineering and penetration-testing capabilities; the analyze method only populates a success status and empty findings list. In this context, capability misrepresentation is more dangerous because the skill is explicitly security-focused, so operators may trust it for audits or pentests and miss real vulnerabilities.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially misrepresents the skill's advertised purpose: it claims comprehensive security auditing capability but only validates that a path exists, returns a hardcoded success result, and prints an empty report. In a security context, this can create dangerous false assurance, causing users or downstream agents to believe a target was audited when no meaningful analysis occurred.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The skill manifest and markdown describe concrete operational capabilities such as threat modeling, security auditing, and pentest automation, yet this file contains only descriptive documentation and command examples. That creates a mild description-behavior mismatch within the analyzed artifact because the claimed functionality is not actually present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

The heading and usage imply a security auditing function, while the accompanying prose emphasizes optimization, performance metrics, and automated fixes rather than security assessment. This is an intent-documentation divergence because the local documentation describes a different kind of tool than the security-oriented name suggests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The analyze() method's documentation and control flow imply that a substantive audit is being performed, but the method only sets placeholder fields and an empty findings list. This is risky because consumers may interpret an empty findings result as a clean security assessment rather than absence of implemented checks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.