Back to skill

Security audit

FDE Delivery Loop

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent and disclosed, but its demo scaffold can turn untrusted project text into executable local JavaScript.

Review before installing. The skill's delivery workflow is purpose-aligned, but do not use attacker-controlled customer text directly as the POC name, scenario, or project ID until the scaffold generator escapes values separately for JavaScript, HTML, and JSON. Prefer trusted or sanitized metadata, inspect generated server.js/index.html before running them, and keep generated POC work in a disposable directory without secrets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
fde-agent-skill-designer/scripts/scaffold-poc.js:42
Finding

Unescaped Scaffold Metadata Enables Generated JavaScript Injection and Stored Cross-Site Scripting

Content
View full analysis
{{POC_NAME}}

FDE MINIMUM POC · v0.1.0

{{POC_NAME}}

{{SCENARIO}}

``` ### Technical Analysis The scaffold generat ...[truncated 3576 chars]
Remediation
View remediation
`, `"`, and `'` before inserting names or scenarios into HTML text or attribute contexts. Prefer setting dynamic text through `textContent` rather than generating markup. 5. **Remove metadata from executable code where possible.** The server startup message can read a validated manifest at runtime instead of embedding `POC_NAME` directly into `server.js`. 6. **Validate command-line metadata.** Apply reasonable length limits, reject control characters, and reject unexpected line breaks. Validation should supplement, not replace, output encoding. 7. **Use distinct placeholders for distinct contexts.** A single token must not be reused in JavaScript, HTML, and JSON unless every destination receives format-specific encoding. 8. **Add adversarial regression tests.** Test names, scenarios, and project identifiers containing: - Backticks and template interpolation syntax. - Single and double quotation marks. - Backslashes and newlines. - HTML tags and closing script sequences. - JSON structural characters. - Unicode control and directionality characters. 9. **Validate generated artifacts before reporting success.** Parse generated JSON, syntax-check generated JavaScript, and inspect generated HTML to ensure metadata remains inert text. 10. **Docum ...[truncated 181 chars]
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
Findings (24)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The declared description presents a comprehensive delivery skill with routing and eight specialist modules that produce multiple delivery artifacts. The supplied code chunk does not implement that functionality; instead, it only provides a browser UI layer that captures input, calls a preexisting window.PocLogic.run(...), and renders returned fields such as status, evidence, and actions. There is no evidence in this chunk of orchestration across modules, artifact generation such as PRDs or architectures, or broader end-to-end delivery behavior. This is a materially narrower and different purpose than the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description promises a comprehensive end-to-end delivery system composed of multiple runnable modules that produce substantive customer-delivery artifacts. The supplied code instead implements a small guardrail wrapper: it checks for empty input, a couple of prompt-injection regex patterns, and missing-field markers, then either blocks execution or emits a generic stub summary. It performs no routing, no specialist-module execution, no artifact generation, and no meaningful POC or delivery analysis. This is a material purpose/behavior mismatch, not merely an implementation detail gap.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad delivery/solution-design skill with multiple modules producing business and engineering artifacts. The actual code chunk does not implement routing across delivery modules, artifact generation, customer-need analysis, PRD creation, deployment architecture design, or evidence/adoption workflows. Instead, it only starts a simple static file server for a minimal POC asset directory. That is a materially different primary purpose and adds an undeclared capability (hosting files over HTTP), so this code chunk does not accurately represent the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a comprehensive delivery orchestration skill with multiple specialist modules for customer-facing solution delivery outputs. The supplied code does something materially different: it is a filesystem-based validation script for a skill package. It reads SKILL.md and agents/openai.yaml, validates required fields, naming rules, local links, and emits blockers/warnings. This is not a supporting implementation detail of the described delivery workflow; it is a separate packaging/quality-check utility with a different primary purpose and resource access pattern.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a broad multi-module delivery workflow skill for enterprise POC execution and artifact generation. The supplied code chunk instead implements a narrow utility: summarizing evaluation records into a Markdown report with pass rates, averages, category breakdowns, and hard-failure indexing. This is materially different in primary purpose and capabilities. While eval summarization could be a small supporting component of a larger POC workflow, the declared description does not accurately represent this code chunk's actual behavior.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

md
2. In the source repository, each child entry point is `SKILL.md`. In the one-click release, children become `MODULE.md` so the archive has exactly one`SKILL.md

Memory Manipulation

High
Category
Memory Poisoning
Confidence
85% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · fde-prd-writer/references/method-selection.md (reported line 26)May include surrounding context.

md
### Mermaid: Reduce misunderstandings of complex processes

Prioritize drawing state changes, responsibility boundaries, conditional branches and asynchronous callbacks. Diagrams do not replace rules, permissions, or acceptance criteria; each item must still map to `FR-`and`AC-`.

### JTBD / 5W1H: Avoid treating solutions as requirements

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document declares lang="zh-CN", which sets a specific language/locale for the skill interface. In this file there is no visible indication that the locale is optional, user-selectable, or justified as a region-specific tool, so it appears to enforce a language preference without opt-in.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The template leaves the 'Trigger conditions' field empty, which can lead authors to ship skills without clearly defining when the skill should activate. In an agent skill context, ambiguous activation scope increases the chance of the skill running on unintended inputs or contexts, causing unauthorized actions, data exposure, or unsafe automation behavior.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · fde-agent-skill-designer/references/platform-adapters.md (reported line 56)May include surrounding context.

md
- Claude's custom Skills also use the directory containing `SKILL.md`;
-`name` Use only lowercase letters, numbers and hyphens to avoid platform reserved words;
-`description` Also write down what to do and when to use it;
- Keep references and scripts loaded on demand, don't cram everything into `SKILL.md`.

### Claude Code

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

Line L112 imposes a language/locale handling rule by stating that the Chinese and English versions must use the same skill ID and field version. This is a natural-language locale policy constraint, but the document does not offer user choice, opt-in, or a documented justification for enforcing this cross-locale policy.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger is described only as a general need to process a bill explanation ticket, without concrete activation gates such as required ticket attributes, queue/source restrictions, or explicit user initiation. In an agent skill, ambiguous activation can cause the workflow to run on the wrong tickets or in broader contexts than intended, increasing the chance of unauthorized data access, policy misuse, or accidental progression toward prohibited actions.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · fde-engagement-charter/references/charter-worked-example.md (reported line 5)May include surrounding context.

md
## Background

Problem discovery and confirmation: retrieving data and drafting billing-ticket responses take too long, and the reference to old policies results in rework. Customers are not allowed to automatically send or close tickets.

## POC decision problem

YARA rule 'network_reconnaissance': Network reconnaissance and scanning patterns [hacktools]

Medium
Category
YARA Match
Confidence
65% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · fde-playbook-productizer/references/product-strategy.md (reported line 44)May include surrounding context.

md
ive products, demand changes, technological disruption, regulatory risks, economic downturn |

**Strategic Application**:

- **Attack (Build)**: Advantage + Opportunity
- **Defend**: Disadvantage + Threat
- **Pivot**: Explore opportunities to change the competitive landscape

---

## 3. Porter’s Five Forces Model

| Five Forces | Assessment Questions |
|------|---------|
| **Competitors** | How fierce is the competition? What is the size and strength of the opponent? |
| **Supplier Bargaining Power** | How much say do suppliers have? |
| **Buyer's Bargaining Power** | How much power do customers have to lower prices? |
| **Threat of Substitutes** | What alternative solutions exist? |
| **Threat of New Entrants** | Is it easy for new competitors to enter? |

---

## 4. PESTLE analysis

| Dimensions | Assessment content |
|------|---------|
| **Political** | Government policies, tax regulations, political stability |
| **Economic** | Economic growth, interest rates, inflation, consumer

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The handbook says skill assets should include triggers, workflows, tools, guardrails, assessments, and platform adaptation, but it does not define trigger specificity, authorization boundaries, or conditions to prevent accidental or over-broad invocation. In a delivery skill that may be reused across customers and scenarios, vague trigger guidance can lead to unintended activation, scope creep, or execution in the wrong context, increasing the chance of unsafe behavior or data exposure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · fde-playbook-productizer/references/productization-quality-rubric.md (reported line 20)May include surrounding context.

md
## Reuse test score

Can the new FDE, without asking the original author:

1. Determine whether it is applicable or not;
2. Collect minimum input;

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The default prompt uses the activation phrase "$fde-problem-discovery" together with a very general action description, "analyze these customer materials," without clarifying trigger constraints or exclusion conditions. In a manifest file, this can be considered overly broad because it does not specify when this skill should be invoked versus other customer-research or analysis skills.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · LICENSE.md (reported line 7)May include surrounding context.

md
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Line L15 instructs routing output to use specific English labels such as "Design and Verification/Stage 4 Deployment Architecture." This is a natural-language locale constraint, and the file does not indicate that users may choose another language or that English-only output is required for a documented regional or compliance reason.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Line L42 uses the phrase "Contract Keeping Draft," which appears to be a non-standard or locale-translated term in an otherwise English document. Because the file does not offer the user a language/terminology choice or justify a locale-specific convention, this may violate the language/locale policy requiring opt-in or documented justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This markdown guidance content presents all instructions and framework labels in a single language with no indication that users may choose another language or locale. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The console output uses non-English/full-width formatting and phrasing such as '|' separators and 'Reminder'/'Conclusion' message styles without offering a locale or output-format choice. This creates a natural-language/locale constraint in the skill's user-facing behavior with no documented opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs a filesystem write via writeFileSync, which changes user data on disk. Although the write is requested through the --output argument, there is no confirmation prompt, overwrite notice, or inline documentation warning the user that an existing file may be replaced.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.install_untrusted_source

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
fde-agent-skill-designer/assets/minimal-poc/poc-manifest.json:21