Back to skill

Security audit

Switchyard Runtime Diagnostics

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and read-only at the MCP level, but its setup asks users to run unpinned code from an external repository.

Install only if you are comfortable running the external Switchyard repository locally. Prefer checking out a known commit or signed release, reviewing package scripts and dependencies, using a frozen lockfile or ignoring lifecycle scripts where possible, and running the setup in a least-privilege sandbox without sensitive credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Note
Location
references/INSTALL.md:7
Finding

Execution of an Unpinned Remote Repository and Dependency Chain

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/OPENCLAW_MCP_CONFIG.json:11

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
references/OPENHANDS_MCP_CONFIG.json:10