Back to skill

Security audit

Ai Search Rank Tracker

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it presents simulated AI-engine results as real tracking and has path-handling bugs that can read or write outside intended folders.

Before installing, treat this as a review item: do not rely on its reports as actual ChatGPT, Claude, Gemini, or Perplexity rankings unless the implementation is changed to query those services directly or clearly labels results as simulations. Avoid confidential prompts or brand strategy, restrict promptPack values to bundled pack names, review generated report paths, and open CSV exports cautiously.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/prompt-db.js:6
Finding

Prompt Pack Path Traversal Enables Unauthorized JSON File Read and External Disclosure

Content
View full analysis
({ prompt })) }; } const packs = Array.isArray(promptPack) ? promptPack : [promptPack]; const records = packs.flatMap((pack) => readPack(pack)); ``` ### Technical Analysis `config.promptPack` and `config.promptPacks` are used as path components without validating them against the list of supported packs. `path.join()` normalizes traversal sequences but does not guarantee that the resulting path remains beneath `prompt-db/`. A value containing `../` can therefore resolve to a readable JSON file outside `prompt-db/`. If the selected file contains a compatible array of prompt records, its data is processed as prompts. The application then sends those prompt values to the configured OpenAI-compatible, Anthropic, or OpenRouter-compatible endpoint. This creates both a local file access violation and a potential external disclosure channel. The file must be valid JSON and structurally compatible with the expected prompt-pack format, which limits—but does not eliminate—the exploitability. ### Attack Path 1. An attacker supplies or modifies a tracker configuration file. 2. The attacker sets `promptPack` or an element of `promptPacks` to a traversal path such as `../../some-directory/sensitive-data`. 3. `readPack()` appends `.json ...[truncated 748 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/index.js:70
Finding

Unsanitized Prompt Pack Name Enables Report Path Traversal Outside the Output Directory

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/utils.js:20
Finding

CSV Formula Injection Through User-Controlled and Model-Controlled Report Fields

Content
View full analysis
{ const str = String(value ?? ''); if (/[",\n]/.test(str)) return `"${str.replace(/"/g, '""')}"`; return str; }) .join(','); } ``` User-controlled and model-controlled values are passed directly to that encoder: ```js const rows = output.results.map((item) => toCsvRow([ item.engine, item.prompt, item.brand, item.mentioned, item.rank ?? '', item.mentionType, item.sentiment, (item.competitors || []).join('|'), item.excerpt || '', item.score ?? '', item.promptMeta?.category || '', item.promptMeta?.subcategory || '', item.promptMeta?.intent || '', item.promptMeta?.journeyStage || '', item.promptMeta?.difficulty || '', item.promptMeta?.commercialValue || '', item.error || '', item.startedAt || '', item.finishedAt || '' ])); ``` ### Technical Analysis CSV quoting protects delimiters and embedded quotation marks, but it does not prevent spreadsheet applications from interpreting a cell as a formula. Fields such as `prompt`, `brand`, prompt metadata, model-generated `excerpt`, and provider-generated `error` can begin with formula-triggering characters such as: - `=` - `+` - `-` - `@` - Tab - Carriage return When a generated CSV file is opened in formula-capable spreadsheet software, such cells may be evaluated instead of treated as text. Quoting the cell does not reliably prevent this behavior. The attack requires a victim to open the generated report in vulnerable or permissively configured spreadsheet software. ### Attack Path 1. An attacker controls a tracker configuration, prompt-pack record, or content likely to be reproduced in a model response. 2. The attacker places a spreadsheet ...[truncated 825 chars]
Remediation
View remediation
{ const str = sanitizeSpreadsheetCell(value); return `"${str.replace(/"/g, '""')}"`; }) .join(','); } ``` Also add tests covering formula prefixes, leading whitespace followed by a formula character, embedded newlines, quotation marks, and model-generated excerpts. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The documented behavior does not match the described purpose: the skill appears to require external API usage and may simulate target engines rather than actually query them, while omitting core promised functions like ranking, sentiment, competitor detection, and reporting in the analyzed content. This mismatch is dangerous because it can mislead users into trusting inaccurate output and can conceal undeclared data flows to third-party LLM providers.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
node src/index.js prompts/starter.json

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 7)May include surrounding context.

sh
SCRIPT_DIR="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"
ROOT_DIR="$(cd "$SCRIPT_DIR/.." && pwd)"
ENV_EXAMPLE="$ROOT_DIR/.env.example"
ENV_FILE="$ROOT_DIR/.env"
STARTER_JSON="$ROOT_DIR/prompts/starter.json"

printf "\n==> AI Search Rank Tracker installer\n"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 32)May include surrounding context.

sh
npm install

if [ ! -f "$ENV_FILE" ]; then
  echo "\n==> Creating .env from .env.example"
  cp "$ENV_EXAMPLE" "$ENV_FILE"
else
  echo "\n==> Keeping existing .env (not overwriting)"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 35)May include surrounding context.

sh
npm install

if [ ! -f "$ENV_FILE" ]; then
  echo "\n==> Creating .env from .env.example"
  cp "$ENV_EXAMPLE" "$ENV_FILE"
else
  echo "\n==> Keeping existing .env (not overwriting)"

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation does not query ChatGPT, Claude, Gemini, or Perplexity directly; it asks a configurable backend to imitate them. That creates a material integrity and deception risk because users may rely on the output as actual cross-engine visibility data when it is only synthetic simulation, leading to false business decisions and misrepresentation of monitoring results.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README tells users how to run the tracker and what reports it generates, but it does not disclose that prompts, brand names, competitor names, and related query data may be transmitted to external AI providers. In a tool specifically designed to benchmark multiple third-party AI engines, this omission can cause users to unknowingly send commercially sensitive marketing, competitive intelligence, or customer-related data off-system.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises executable setup and runtime steps and explicitly relies on environment-based credentials, but it declares no tool scope or permissions boundary. That creates an authorization and review gap: a host may allow the skill to access secrets or execute code without the user being clearly informed of those capabilities.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest description lists broad phrases like "brand mention checks," "competitor detection in AI answers," and "a simple visibility report" as usage cues without clearly constraining how the skill should be triggered. In a manifest file, this kind of expansive natural-language description can create ambiguous activation conditions and unintended invocation overlap with ordinary analytics or research requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The report discloses operational security details by explicitly stating that the ANTHROPIC_API_KEY is missing. While it does not reveal the secret itself, it exposes internal credential state and provider configuration to anyone who can view the report, which can aid reconnaissance and confirm which integrations are enabled or misconfigured.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The prompt entries are generic discovery queries such as 'best ai agent platform' that can match ordinary user requests far outside a narrowly scoped rank-tracking workflow. In an agent-skill setting, broad triggers can cause unintended activation, inappropriate routing, or opportunistic collection/processing of user queries that were not meant for this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file contains many broad, high-volume prompts spanning generic categories like assistants, agents, automation, and browser tools, with brand and competitor targeting attached. This substantially increases the chance that common discovery queries will activate the skill outside its stated purpose, enabling overreach in query interception and biased competitive monitoring behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt database materially exceeds the stated purpose of an AI search visibility tracker by including large volumes of unrelated commercial discovery prompts across SaaS, developer tools, local AI, and OpenClaw ecosystem comparisons. In an agent skill, this scope expansion can covertly repurpose the tool for broad brand/competitor intelligence gathering or SEO market targeting, causing users to send queries and evaluate brands outside the consented or expected task boundary.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The code uses generic provider credentials and configurable base URLs/models to impersonate multiple third-party engines unrelated to the stated purpose of measuring actual AI search visibility. This broadens the trust boundary and can facilitate misleading output generation or routing sensitive prompts to unintended endpoints if configuration is altered.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/engines.js (reported line 26)May include surrounding context.

js
async function runWithOpenAICompatible(engine, prompt) {
  const apiKey = process.env.OPENAI_API_KEY;
  const baseURL = process.env.OPENAI_BASE_URL || 'https://api.openai.com/v1';
  const model = process.env.OPENAI_MODEL || 'gpt-5.4';
  if (!apiKey) throw new Error('Missing OPENAI_API_KEY');

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

User-supplied prompts are transmitted to an external model provider, but this file provides no notice, consent, or data handling guardrails. If prompts contain confidential business queries, customer data, or proprietary terms, they may be disclosed to a third party without the user's informed understanding.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This path sends prompt content to Anthropic without any disclosure or consent mechanism visible in the code. In the context of a brand-monitoring skill, prompts may contain sensitive market strategy, customer names, or internal competitor research that should not silently leave the system.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The OpenRouter path transmits prompts to a configurable external endpoint and model, which increases the risk of data being sent to an unexpected or less trusted destination. Because both baseURL and model are environment-controlled, misconfiguration can silently redirect sensitive prompts outside the intended provider boundary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This CSV contains natural-language error content that hard-codes the credential label "Missing ANTHROPIC_API_KEY". Under the policy provided, locale or language constraints should not be forced without opt-in or documented justification, and no such opt-in or justification appears in this file.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 11)May include surrounding context.

json
"run:starter": "node src/index.js prompts/starter.json"
  },
  "dependencies": {
    "@anthropic-ai/sdk": "^0.54.0",
    "dotenv": "^16.4.5",
    "openai": "^5.12.2"
  }

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 12)May include surrounding context.

json
},
  "dependencies": {
    "@anthropic-ai/sdk": "^0.54.0",
    "dotenv": "^16.4.5",
    "openai": "^5.12.2"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"dependencies": {
    "@anthropic-ai/sdk": "^0.54.0",
    "dotenv": "^16.4.5",
    "openai": "^5.12.2"
  }
}

Static analysis

No suspicious patterns detected.