Back to skill

Security audit

Tool Registry

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed tool registry, but its bundled execution API can run file writes and shell commands without enforcing the permission controls it documents.

Review before installing. This skill is not showing evidence of hidden exfiltration or persistence, but it exposes powerful local capabilities: arbitrary file reads, arbitrary file writes, and shell command execution. It should only be used in a tightly controlled environment or after adding enforced authorization, workspace path restrictions, explicit confirmations, and command limits.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/tool-registry.mjs:286
Finding

Missing Runtime Authorization Allows Unrestricted File Access and Command Execution

Content
View full analysis
{ const fs = await import('fs'); const path = await import('path'); const filePath = typeof input === 'string' ? input : input.path; if (!filePath) throw new Error('path required'); const content = fs.readFileSync(filePath, 'utf-8'); return { path: filePath, content, size: content.length }; } ``` They also include unrestricted file writes: ```javascript execute: async (ctx, input) => { const fs = await import('fs'); const path = await import('path'); const { file: filePath, content } = typeof input === 'string' ? JSON.parse(input) : input; if (!filePath || content === undefined) throw new Error('file and content required'); fs.writeFileSync(filePath, content, 'utf-8'); return { path: filePath, bytes: content.length }; } ``` Finally, the registry exposes arbitrary operating-system command execution: ```javascript execute: async (ctx, input) => { const { spawn } = await import('child_process'); const comman ...[truncated 3671 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
99% confidence
Finding

The bundled bash tool executes arbitrary user-supplied shell commands via /bin/sh -c or cmd /C, which is effectively unrestricted command execution. In the context of a tool registry/discovery system, this capability is unjustified and extremely dangerous because it can lead to full host compromise, data theft, persistence, or destructive actions.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
const { ToolRegistry } = require('./scripts/tool-registry.mjs');

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This registry skill claims to provide tool registration and discovery, but it also embeds operational tools that read files, write files, and execute shell commands. That expands the attack surface far beyond metadata lookup, and any caller that can reach registry execution can trigger powerful side effects inconsistent with the advertised purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill includes direct file read and write operations even though its stated purpose is registry/discovery. These primitives enable arbitrary local file access and modification, which can expose secrets, alter code/configuration, or overwrite important files if this registry is invoked by an agent or untrusted caller.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The bash tool runs arbitrary commands with no confirmation, no allowlist, and no safety interlock. In an agent setting, this makes prompt-induced or accidental command execution far more likely and can directly result in data loss, exfiltration, or full system modification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger phrases are broad and include common conversational queries about tools, searching, and routing, which can cause the skill to activate in benign contexts where the user is not explicitly requesting this registry behavior. Because this skill influences tool discovery and routing, unintended invocation can expose tool metadata or affect downstream agent behavior more than a typical informational skill would.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The write_file tool overwrites arbitrary paths immediately with writeFileSync and does not present any confirmation, warning, backup, or path restriction. In agentic contexts, this increases the likelihood of accidental or induced destructive writes, configuration tampering, and loss of integrity.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The help text describes exec <name> <input> as 'for testing', which suggests a limited or harmless action. In reality, the execution mechanism can invoke real file writes and shell commands through registered tools, so the documentation understates the operational impact.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/tool-registry.mjs:404