Back to skill

Security audit

Auto Monitor - System Monitoring

Security checks for vulnerabilities and agentic risk

Overview

This skill is a system monitor, but it also tells the agent to act proactively and automatically fix issues without clear limits or user approval.

Install only if you intend to let an agent monitor server health, and run it with least privilege. Treat automatic fixes as requiring explicit approval unless you separately define a narrow allowlist of safe actions, targets, logging, and rollback steps.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:43
Finding

Unbounded Automatic Remediation Without User Authorization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 43
Vulnerability Type: T09: Insecure Skill Coding Practices
Risk Level: Medium

Complete instruction snippet translated into English:

text
- Immediately handle anything that can be automatically repaired.

Technical Analysis

The instruction directs the agent to perform automatic remediation but does not define an allowlist of permitted operations, privilege boundaries, approval requirements, validation checks, or rollback procedures. This expands the skill from passive monitoring into potentially destructive system modification.

The package contains no executable implementation, so no specific malicious command or privilege-escalation mechanism is present. Exploitation depends on the tools and operating-system permissions granted to the agent at runtime. If privileged system-management tools are available, an incorrect diagnosis or manipulated monitoring result could cause the agent to execute unsafe corrective actions.

Attack Path

  1. The skill is loaded with access to system-monitoring and system-management tools.
  2. A genuine, transient, misclassified, or attacker-induced condition is identified as an anomaly.
  3. The broad remediation instruction causes the agent to select a state-changing action without requesting user approval.
  4. The agent performs that action using its existing runtime privileges.
  5. The action disrupts services, processes, files, or configuration if the diagnosis or remediation choice is incorrect.

Impact Assessment

The maximum impact is limited to the permissions and tools already available to the agent; the skill itself does not obtain additional privileges. With restricted permissions, impact may be negligible or confined to user-owned resources. With administrative permissions, possible consequences include stopping services or processes, changing configuration, modifying or deleting files, and causin ...[truncated 146 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make monitoring and reporting the default behavior; do not perform state-changing remediation automatically.
  2. Require explicit user confirmation before stopping processes, changing configuration, deleting files, restarting services, or performing other consequential actions.
  3. Define a narrow allowlist of low-risk automated actions, including exact commands, permitted arguments, target resources, and execution conditions.
  4. Run the skill with least privilege and separate read-only monitoring permissions from remediation permissions.
  5. Add precondition validation, dry-run previews, timeouts, post-action health checks, and rollback procedures.
  6. Record anomaly evidence, selected remediation, authorization, commands executed, and results in an audit log.
  7. Treat externally influenced monitoring data as untrusted and require corroboration before initiating remediation.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill content is entirely written in Chinese and describes its behavior without indicating that language choice is optional. Under the stated policy, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill explicitly authorizes autonomous remediation with '可以自动修复的立刻处理' without any safety guardrails, approval requirements, rollback guidance, or scope limits. In an agent skill, this can lead to unintended system changes, service disruption, destructive actions, or abuse if the monitoring logic misclassifies conditions or is manipulated by hostile inputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest description '主动监控系统状态' is broad and does not define clear activation boundaries, scope, or user consent requirements. In an auto-monitoring skill, this ambiguity can cause the agent to over-activate, inspect unintended systems or contexts, and report data without an explicit triggering policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The only natural-language description in the manifest is written in Chinese, which may impose a language expectation without indicating user opt-in or a documented region-specific constraint. Under the language/locale policy, skills should either offer language choice or clearly justify a locale-specific limitation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.