Back to skill

Security audit

rotifer-guide

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Rotifer CLI guide skill whose filesystem, command, and network use fit its developer-tool purpose.

Install this only if you intend to use Rotifer. Before running scaffold or publish workflows, note that the Web Studio path can send your prompt and generated source to rotifer.ai, and publishing makes the Gene public; use the local CLI path for private work.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: rotifer-guide
description: >-
  Entry point for Rotifer Protocol — onboarding to Rotifer Genes, scaffolding a Gene from a
  description, diagnosing a Gene's F(g) or compile failure, searching the Rotifer Gene registry,
  and upgrading a Gene's fidelity from Wrapped to Native.
  Invoke explicitly when starting with Rotifer, or when unsure which Rotifer capability to use.
  Do NOT use for general onboarding, tutorials, troubleshooting, or search — every capability
  here operates on Rotifer Genes and the Rotifer CLI, and nothing else.
---

# Rotifer Guide — User Entry Point

> This Skill handles intent

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is described as a broad entry point that covers onboarding, scaffolding, diagnostics, registry search, and upgrades, but it does not define narrow activation boundaries inside the skill artifact. In combination with powerful permissions such as process execution, filesystem write, and outbound network access, this ambiguity can cause the agent to invoke the skill in situations broader than intended, increasing the chance of unsafe or unexpected actions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.