Back to skill

Security audit

Awesome Cheatsheets

Security checks for vulnerabilities and agentic risk

Overview

The skill is advertised as a programming cheatsheet, but one included script is a generic local data and history logger that is not clearly disclosed.

Review this before installing. It does not appear to exfiltrate data or install a backdoor, but it does keep local data and command history that are not well aligned with a cheatsheet skill. Install only if you are comfortable with that local persistence and the mismatch between the advertised purpose and the included script behavior.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp1

High
Category
MCP Tool Poisoning
Confidence
85% confidence
Finding

Zero-width Unicode characters are invisible to humans but detectable by AI. When followed by visible text, they indicate hidden content injection.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The finding indicates additional behaviors such as local data storage, command history logging, and CRUD-like operations that are unrelated to a cheatsheet skill's declared purpose. Hidden or undocumented functionality in a benign-looking skill raises supply-chain and trust concerns because operators may grant permissions expecting static reference content, not stateful data handling.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The finding indicates additional behaviors such as local data storage, command history logging, and CRUD-like operations that are unrelated to a cheatsheet skill's declared purpose. Hidden or undocumented functionality in a benign-looking skill raises supply-chain and trust concerns because operators may grant permissions expecting static reference content, not stateful data handling.

Content

No source excerpt is available for this finding.

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt ยท SKILL.md (reported line 4)May include surrounding context.

md
---
version: "2.0.0"
name: Awesome Cheatsheets
description: "๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿ‘จโ€๐Ÿ’ป Awesome cheatsheets for popular programming languages, frameworks and development tools. They awesome cheatsheets, javascript, backend, bash."
author: BytesAgain
homepage: https://bytesagain.com
source: https://github.com/bytesagain/ai-skills
---

# Awesome Cheatsheets

๐Ÿ‘ฉโ€๐Ÿ’ป๐Ÿ‘จโ€๐Ÿ’ป Awesome cheatsheets for popular programming languages, frameworks and development tools. They include everything you should know in one single file. ## Commands

- `help` - Help
- `run` - Run
- `info` - Info
- `status` - Status

## Features

- Core functionality from L

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implemented behavior does not match the declared skill purpose: instead of serving cheatsheet content, the script acts as a generic local data collection and logging utility. This kind of capability mismatch is dangerous because it can mislead users and reviewers about what data is being stored and why, increasing the risk of covert collection of user inputs under an unrelated package identity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Command triggers like help, run, info, and status are overly generic and can collide with common user language or other tools. In an agent environment, broad triggers increase the risk of accidental invocation, ambiguous routing, or abuse through prompt phrasing that unintentionally activates the skill.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The usage text says 'Run any command,' which implies unconstrained command execution through a generic command interface. Even without executable code shown here, presenting unrestricted command dispatch in a skill is risky because it encourages broad capability exposure and makes abuse easier if the backing implementation accepts arbitrary actions or arguments.

Content

Scanner excerpt ยท SKILL.md (reported line 25)May include surrounding context.

md
## Usage

Run any command: `awesome-cheatsheets <command> [args]`
---
๐Ÿ’ฌ Feedback & Feature Requests: https://bytesagain.com/feedback
Powered by BytesAgain | bytesagain.com

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The internal help text explicitly describes the tool as a 'Multi-purpose utility tool,' which contradicts the declared cheatsheet-focused metadata. This inconsistency is a security concern because deceptive or misleading documentation can hide unexpected capabilities and reduce the likelihood that users notice persistent logging or data storage behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script persistently records user activity and arbitrary user-supplied content to files in the user's data directory, even though that behavior is not justified by the stated cheatsheet use case. In this context, the mismatch makes the logging more dangerous because users may provide search terms or entries assuming a harmless reference tool, while the script silently retains that data for later exposure or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The _log function writes user-supplied command arguments to a persistent history file without warning, which can capture sensitive strings such as search queries, notes, paths, or accidental secrets passed on the command line. In the context of a cheatsheet skill, this is especially suspicious because such telemetry is unrelated to the advertised purpose and is not disclosed to the user.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.