Back to skill

Security audit

Skill Taxonomy Router Pro

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent skill router, but it defaults to persistent local routing logs and includes helpers that can download skills and delete a hard-coded inbox folder.

Install only if you are comfortable with a router that keeps local history of skill choices and task metadata, and review or disable the intake, logging, and cleanup scripts before using it in a workspace with sensitive prompts or untrusted skills.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/log_routing_decision.py:39
Finding

Default Persistence of Potentially Sensitive Routing Metadata

Content
View full analysis

Vulnerability Details

File Location: scripts/log_routing_decision.py:39-64
Vulnerability Type: Plaintext storage of potentially sensitive task content
Risk Level: Medium

Vulnerable Code

python
def append_log(entry):
    with LOG.open('a', encoding='utf-8') as f:
        f.write(json.dumps(entry, ensure_ascii=False) + '\n')


def main():
    ap = argparse.ArgumentParser(description='Log skill-router routing decisions and mark skill usage')
    ap.add_argument('--intent', required=True)
    ap.add_argument('--domain', default='')
    ap.add_argument('--subdomain', default='')
    ap.add_argument('--risk', default='')
    ap.add_argument('--skills', nargs='+', required=True)
    ap.add_argument('--candidates', nargs='*', default=[])
    ap.add_argument('--reason', default='')
    args = ap.parse_args()

    ts = datetime.now(timezone.utc).isoformat()
    mark_usage(args.skills)
    append_log({
        'timestamp': ts,
        'intent': args.intent,
        'domain': args.domain,
        'subdomain': args.subdomain,
        'risk': args.risk,
        'skills': args.skills,
        'candidates': args.candidates,
        'reason': args.reason,
    })
    print('logged routing decision for:', ', '.join(args.skills))

The behavior is enabled by default in SKILL.md:166:

markdown
11. After a skill is actually chosen and used, treat routing-decision logging as the default post-action: record the chosen skill(s) with `python3 scripts/log_routing_decision.py ...` unless there is a concrete reason not to.

Technical Analysis

The routing logger accepts unrestricted free-form --intent and --reason values and writes them verbatim to the append-only references/routing-decisions.jsonl file. User task descriptions and routing rationales can contain personal information, confidential business data, infrastructure identifiers, financial details, or credent ...[truncated 2174 chars]

Remediation
View remediation

Remediation Suggestions

  1. Record only coarse structured metadata by default, such as domain, subdomain, risk level, and selected Skill identifier.
  2. Make free-form intent and reason storage explicitly opt-in rather than the default.
  3. Add secret and personal-data redaction before serialization, including API keys, tokens, passwords, email addresses, account identifiers, and private filesystem paths.
  4. Avoid passing sensitive text through command-line arguments. Accept structured input through standard input or another protected local channel.
  5. Create the log with owner-only permissions, such as mode 0600, and verify the parent directory is not broadly writable or readable.
  6. Add configurable retention and rotation, including maximum age and maximum file size.
  7. Provide a command to purge routing history safely.
  8. Document that raw user prompts, credentials, personal data, and confidential business information must never be logged.
  9. Ensure generated telemetry files are excluded from source-control commits and unintended synchronization where appropriate.
  10. Consider storing only a non-reversible category or short user-approved summary when detailed auditing is required.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Undeclared persistence of usage telemetry and routing logs is a real concern, especially in a skill framed as decision support rather than data collection. Persistent local logs can reveal task history, chosen skills, and workflow patterns, which may expose sensitive operational context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared persistence of usage telemetry and routing logs is a real concern, especially in a skill framed as decision support rather than data collection. Persistent local logs can reveal task history, chosen skills, and workflow patterns, which may expose sensitive operational context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Undeclared persistence of usage telemetry and routing logs is a real concern, especially in a skill framed as decision support rather than data collection. Persistent local logs can reveal task history, chosen skills, and workflow patterns, which may expose sensitive operational context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Undeclared persistence of usage telemetry and routing logs is a real concern, especially in a skill framed as decision support rather than data collection. Persistent local logs can reveal task history, chosen skills, and workflow patterns, which may expose sensitive operational context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

Undeclared persistence of usage telemetry and routing logs is a real concern, especially in a skill framed as decision support rather than data collection. Persistent local logs can reveal task history, chosen skills, and workflow patterns, which may expose sensitive operational context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared persistence of usage telemetry and routing logs is a real concern, especially in a skill framed as decision support rather than data collection. Persistent local logs can reveal task history, chosen skills, and workflow patterns, which may expose sensitive operational context.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Undeclared persistence of usage telemetry and routing logs is a real concern, especially in a skill framed as decision support rather than data collection. Persistent local logs can reveal task history, chosen skills, and workflow patterns, which may expose sensitive operational context.

Content

No source excerpt is available for this finding.

Self-Modification

High
Category
Rogue Agent
Confidence
89% confidence
Finding

The skill explicitly instructs itself to update its own taxonomy and associated artifacts over time, which is a form of self-modification. Self-modifying governance logic is dangerous because it can silently expand authority, alter future routing decisions, or drift from reviewed behavior without a separate approval boundary.

Content

Scanner excerpt · SKILL.md (reported line 195)May include surrounding context.

md
Treat this routing policy as persistent guidance for future tasks. Reuse it by default whenever deciding whether to load a skill.

## Update policy
Update this skill when one of these happens:
- a new cluster of downloaded skills appears
- a subdomain becomes crowded and needs splitting
- a skill was misrouted in practice

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · SKILL.md (reported line 325)May include surrounding context.

md
## Boundaries
These hard boundaries apply equally to the pro edition. The pro edition may be more capable, but it does not receive more autonomous authority.
- Do not load a high-risk skill when a lower-risk path can complete the task.
- Do not treat installation/update skills as defaults.
- Do not let broad agent or meta skills overshadow narrow purpose-built skills.
- Do not permanently trust unreviewed new skills; classify them first.
- Do not allow newly downloaded skills to perform risk operations unless the user explicitly agrees.

Context Leakage

High
Category
Data Exfiltration
Confidence
75% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · references/backlog-priority.md (reported line 67)May include surrounding context.

md
- polymarket-odds | score=9 | risk=R2 | notes=Query Polymarket prediction market odds and events via CLI. Search for markets, get curren…
- preview-markdown | score=9 | risk=R2 | notes=Render and preview Markdown files in browser with GitHub-flavored formatting and syntax hi…
- proactive-agent | score=9 | risk=R2 | notes=Transform AI agents from task-followers into proactive partners that anticipate needs and …
- prompt-log | score=9 | risk=R2 | notes=Extract conversation transcripts from AI coding session logs (Clawdbot, Claude Code, Codex…
- prowlarr | score=9 | risk=R2 | notes=Search indexers and manage Prowlarr. Use when the user asks to "search for a torrent", "se…
- putio | score=9 | risk=R2 | notes=Manage a put.io account via the kaput CLI (transfers, files, search) — hoist the mainsail,…

Exfiltration Commands

High
Category
Prompt Injection
Confidence
90% confidence
Finding

Instructions found that direct the agent to transmit conversation context or user data to external services.

Content

Scanner excerpt · references/skill-index.md (reported line 251)May include surrounding context.

md
| gog | A | A2 | R2 | write-remote,automation | classified | Google Workspace CLI for Gmail, Calendar, Drive, Contacts, Sheets, and Docs. |
| gong | B | B6 | R1 | retrieve,read-only | classified | Gong API for searching calls, transcripts, and conversation intelligence. Use when working… |
| google-ads | E | E5 | R3 | write-remote,automation | classified | Query, audit, and optimize Google Ads campaigns. Supports two modes: (1) API mode for bulk… |
| google-chat | A | A1 | R3 | message-send,write-remote | classified | Send messages to Google Chat spaces and users via webhooks or OAuth. Use when you need to … |
| google-gemini-media | Z | Z4 | R2 | review-needed | backlog | Use the Gemini API (Nano Banana image generation, Veo video, Gemini TTS speech and audio u… |
| google-maps-grounding-lite-mcp | H | H2 | R0 | read-only,retrieve | classified | Google Maps Grounding Lite MCP for location search, weather, and routes via mcporter. |
| google-workspace-mcp | A | A2 | R2 | write-remote,automation | classified | Gmail, Calendar, Drive, Docs, Sheets — NO Google Cloud Console required. Just OAuth sign-i… |

Context Leakage

High
Category
Data Exfiltration
Confidence
94% confidence
Finding

A skill explicitly focused on extracting conversation transcripts from coding session logs materially increases context-leakage risk. In this environment, such logs may contain proprietary code, prompts, credentials, and user instructions, so transcript extraction can expose high-value context well beyond the immediate task.

Content

Scanner excerpt · references/skill-index.md (reported line 466)May include surrounding context.

md
| pro | Z | Z4 | R2 | review-needed | backlog | Guide for creating effective skills. This skill should be used when users want to create a… |
| proactive-agent | Z | Z4 | R2 | review-needed | backlog | Transform AI agents from task-followers into proactive partners that anticipate needs and … |
| project-management-guru-adhd | Z | Z4 | R2 | review-needed | backlog | Expert project manager for ADHD engineers managing multiple concurrent projects. Specializ… |
| prompt-log | Z | Z4 | R2 | review-needed | backlog | Extract conversation transcripts from AI coding session logs (Clawdbot, Claude Code, Codex… |
| protonmail | A | A2 | R1 | read-only,retrieve | classified | Read, search, and scan ProtonMail via IMAP bridge (Proton Bridge or hydroxide). Includes d… |
| prowlarr | Z | Z4 | R2 | review-needed | backlog | Search indexers and manage Prowlarr. Use when the user asks to "search for a torrent", "se… |
| proxmox-full | D | D5 | R3 | write-remote,automation | classified | Complete Proxmox VE management - create/clone/start/stop VMs and LXC containers, manage sn… |

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill instructs use of local files and shell-driven scripts but declares no explicit tool scope or permissions boundary. That creates an authorization ambiguity where a loader or reviewer may underestimate that the skill can read, write, and invoke local automation, increasing the chance of unintended file changes or script execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The entry for git-notes-memory explicitly says the agent 'should use this SILENTLY and AUTOMAT...user opt-in,' which normalizes hidden autonomous behavior. In a routing/classification skill, this is dangerous because it can cause automatic loading or use of a memory system without transparency, consent, or task-scoped necessity, increasing the risk of covert data retention and privacy violations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The entry at this line describes a trigger that applies to very broad user requests, which can cause the router to load or prioritize a capability without sufficiently specific user intent. In a skill-routing context, overbroad activation increases the chance of invoking higher-risk skills unnecessarily and can expand data/tool exposure beyond minimum-necessary use.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
88% confidence
Finding

Although phrased as a developer convenience, 'run arbitrary commands when files change' is effectively an unconstrained execution primitive. If connected to untrusted repositories, generated files, or attacker-controlled content, it can trigger unintended command execution and broaden the system's attack surface.

Content

Scanner excerpt · references/skill-index.md (reported line 196)May include surrounding context.

md
| email-best-practices | Z | Z4 | R2 | review-needed | backlog | Use when building email features, emails going to spam, high bounce rates, setting up SPF/… |
| email-prompt-injection-defense | Z | Z4 | R2 | review-needed | backlog | Detect and block prompt injection attacks in emails. Use when reading, processing, or summ… |
| endurance-coach | Z | Z4 | R2 | review-needed | backlog | Create personalized triathlon, marathon, and ultra-endurance training plans. Use when athl… |
| entr | Z | Z4 | R2 | review-needed | backlog | Run arbitrary commands when files change. Useful for watching files and triggering builds … |
| event-planner | H | H4 | R1 | retrieve,automation | classified | Plan events (night out, weekend, date night, team outing, meals, trips) by searching venue… |
| exa | B | B1 | R0 | search,retrieve | classified | Neural web search and code context via Exa AI API. Requires EXA_API_KEY. Use for finding d… |
| exa-plus | B | B1 | R0 | search,retrieve | classified | Neural web search via Exa AI. Search people, companies, news, research, code. Supports dee… |

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This line instructs silent or automatic use without clear trigger boundaries, which is unsafe because it enables hidden activation outside informed user intent. In a router/index file, that can lead to stealthy collection, storage, or processing of conversation data through auxiliary skills.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The description implies silent, automatic retention of user prompts across sessions, which creates a real privacy and security risk by normalizing default collection of sensitive conversational data. If routed automatically, the system may archive secrets, credentials, or regulated content without clear notice or consent.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatic conversation backup to Obsidian is a true data-collection risk because it creates ongoing local storage of chat content by default. Chat transcripts often contain sensitive operational details, personal data, or tokens, and routine backup expands the blast radius if the notes store is accessed or synced.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A trigger phrase that overlaps with common everyday speech can accidentally activate the skill during unrelated conversations. Because this file drives routing, accidental matches can load sensitive or powerful skills and increase the chance of unintended actions or data access.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Preserving and archiving conversation continuity across compaction cycles suggests broad capture of user inputs over time. Even if intended for continuity, it increases exposure of sensitive data and creates a durable record that could later be searched, shared, or exfiltrated.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/skill-index.md (reported line 524)May include surrounding context.

md
| sfsymbol-generator | Z | Z4 | R2 | review-needed | backlog | Generate an Xcode SF Symbol asset catalog .symbolset from an SVG. Use when you need to add… |
| shared-memory | F | F5 | R2 | knowledge-base,write-remote | classified | Share memories and state with other users. Use when user wants to share knowledge, create … |
| shopping-expert | H | H4 | R1 | retrieve,write-remote | classified | Find and compare products online (Google Shopping) and locally (stores near you). Auto-sel… |
| shortcuts-skill | F | F5 | R1 | automation,write-local | classified | Generate macOS/iOS Shortcuts by creating plist files. Use when asked to create shortcuts, … |
| silverbullet-skill | A | A6 | R1 | knowledge-base,write-remote | classified | MCP server for SilverBullet note-taking app - read, write, search, and manage markdown pag… |
| simple-backup | D | D6 | R2 | write-local,automation | classified | Backup agent brain (workspace) and body (state) to local folder and optionally sync to clo… |
| skanetrafiken | Z | Z4 | R2 | review-needed | backlog | Skåne public transport trip planner (Skånetrafiken). Plans bus/train journeys with real-ti… |

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script permanently deletes a hard-coded directory with shutil.rmtree once invoked with --yes, and it performs no additional validation, safety checks, or containment beyond that flag. In the context of a taxonomy/routing skill, destructive filesystem cleanup is outside the stated purpose, which makes the capability risky because it could remove downloaded skills or user data if run at the wrong time or in the wrong environment.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code maintains persistent intake state and manages an inbox directory for external skills, which exceeds a narrow taxonomy-routing role and creates durable side effects on the host. In context, this makes the skill more dangerous because a routing/classification component should minimize authority; persistent staging of skills can facilitate stealthy intake pipelines and normalize handling of untrusted content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script downloads and installs external skills from an external source as part of an intake workflow, which materially expands trust boundaries beyond simple routing/classification. In this skill context, automatic acquisition of untrusted skills is dangerous because downloaded skills may later be loaded or executed elsewhere, creating a supply-chain entry point inconsistent with the stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.