Back to skill

Security audit

Knowledge Placement Planner

Security checks for vulnerabilities and agentic risk

Overview

This skill runs a local standard-library Python path planner and does not show active file-writing, network, credential, or persistence behavior.

Install only if an archive-style CSV path is the intended destination format for your workflow. The skill appears low-risk operationally, but users should verify that downstream systems will not treat the returned archives/*.csv path as a knowledge-base article location without additional review.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

A skill described as a pure planner may actually execute a generic operation and materialize effects to a user-specified output directory, despite no declared permissions. This is dangerous because hidden write-capable behavior can be abused for unauthorized file creation or workspace manipulation when callers expect a harmless path-computation function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

A skill described as a pure planner may actually execute a generic operation and materialize effects to a user-specified output directory, despite no declared permissions. This is dangerous because hidden write-capable behavior can be abused for unauthorized file creation or workspace manipulation when callers expect a harmless path-computation function.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A skill described as a pure planner may actually execute a generic operation and materialize effects to a user-specified output directory, despite no declared permissions. This is dangerous because hidden write-capable behavior can be abused for unauthorized file creation or workspace manipulation when callers expect a harmless path-computation function.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The output schema only permits paths matching archives/...\.csv, which conflicts with the skill’s stated purpose of planning a knowledge-base placement path and with the accepted document kinds such as project summaries and implementation notes. This mismatch can cause downstream systems to misroute content into archive CSV locations, leading to improper storage, type confusion, or accidental exposure/overwrite if other components trust this path as a safe knowledge-base destination.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.