Back to skill

Security audit

Skill Port

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent audit-and-port helper, but its bundled auditor can read outside the chosen source through symlinks and some validation guidance could execute mutable third-party code.

Install only if you are comfortable using it as a review tool on trusted or sandboxed source directories. For untrusted repositories, avoid running the bundled auditor until symlinks are rejected and file-size limits are enforced, pass --target-agent explicitly, and do not run the npx validation command unless the package source and version are pinned and reviewed.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
references/target-codex.md:75
Finding

Unpinned npx Package May Download and Execute Untrusted Code

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Note
Location
scripts/audit_skill.py:160
Finding

Target-Agent Inference Reads Every Environment Variable Value

Content
View full analysis
tuple[str, bool]: if explicit: return explicit, False env_pairs = {key.upper(): value.lower() for key, value in os.environ.items()} joined = " ".join(f"{key}={value}" for key, value in env_pairs.items()) if "CODEX" in env_pairs or "codex" in joined: return "codex", True if "CLAUDECODE" in joined or "claude_code" in joined or "claude-code" in joined: return "claude", True if "CURSOR" in env_pairs or "cursor" in joined: return "cursor", True if "GEMINI" in env_pairs or "gemini" in joined: return "gemini", True return "codex", True ``` ### Technical Analysis The target-agent inference routine enumerates all process environment variables, lowercases every value, and concatenates all names and values into one large string. Environment variables frequently contain API tokens, cloud credentials, database passwords, CI/CD secrets, and private endpoints. The declared purpose only requires detecting a small number of runtime markers. Reading and duplicating every environment value therefore exceeds the minimum data access necessary for target-agent inference. No code was found that transmits or deliberately writes the concatenated environment data. Consequently, this is not direct credential exfiltration. The security concern is unnecessary secret handling: sensitive values are copied into additional Python objects and remain in process memory until garbage collection, increasing their exposure to debuggers, memory inspection, crash diagnostics, or future logging changes. ### Attack Path 1. The auditor is launched in an environment containing credentials or other sensitive values. 2. No explicit target agent is supplied. 3. `infer_target_ ...[truncated 988 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/audit_skill.py:579
Finding

Auditor Follows File Symlinks Outside the Selected Source Directory

Content
View full analysis
tuple[str, bool]: data = path.read_bytes()[:MAX_TEXT_BYTES] binary = is_binary(data) if binary: return "", True return data.decode("utf-8", errors="replace"), False ``` ### Technical Analysis The inventory loop does not reject symbolic links and does not verify that each resolved file remains below the selected audit root. A malicious source repository can include a file symlink whose target is an arbitrary user-readable file outside the repository. `path.stat()` and `path.read_bytes()` follow file symlinks by default. The scanner therefore samples the target and then reads the entire target again to calculate its SHA-256 digest. Information derived from the external target can enter the generated report through: - File size. - SHA-256 digest. - Binary status. - Security-pattern matches and matching text fragments. The one-megabyte sampling limit does not apply to dige ...[truncated 1924 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
Findings (23)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
- Prefer `scripts/audit_skill.py` for deterministic local inspection.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
- Prefer `scripts/audit_skill.py` for deterministic local inspection.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
- Prefer `scripts/audit_skill.py` for deterministic local inspection.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
- Prefer `scripts/audit_skill.py` for deterministic local inspection.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
- Prefer `scripts/audit_skill.py` for deterministic local inspection.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
- Prefer `scripts/audit_skill.py` for deterministic local inspection.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
- Portable: agent-neutral `SKILL.md`, references, examples, assets, templates.

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · references/source-claude.md (reported line 17)May include surrounding context.

md
| `.claude/agents/*.md` or `agents/*.md` | Convert procedural parts into skills. Keep role/runtime/subagent behavior as target-specific notes unless supported. |
| `.claude/settings*.json` hooks | Treat as unsupported lifecycle behavior unless the target has an equivalent hook mechanism. |
| `.claude-plugin/`, `plugin.json`, `manifest.json` | Inventory metadata. Convert plugin behavior into skills plus dependency notes. |
| `.mcp.json` or MCP server configs | Treat as dependency-bound. Capture server names, URLs, auth requirements, and credentials needed. |
| Managed Agent `agent.yaml` and callable agents | Treat as orchestration behavior. Port reusable instructions only; report subagent handoff requirements. |
| Cowork dispatch/project behavior | Treat as Claude/Cowork-specific unless the target environment provides a matching workflow. |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/source-codex.md (reported line 16)May include surrounding context.

md
| `.codex-plugin/plugin.json` | Convert into a target plugin/extension manifest only when target package fields are known; otherwise document as plugin implementation notes. |
| `.agents/plugins/marketplace.json` | Treat as distribution metadata. Do not assume another agent can consume it directly. |
| `.codex/agents/*.toml` or `~/.codex/agents/*.toml` | Convert required fields and instructions into target subagent format when supported; otherwise mark partial. |
| `.codex/config.toml`, `~/.codex/config.toml`, `[mcp_servers.*]` | Treat MCP/tool setup as dependency-bound. Convert simple configs only with target-specific review. |
| `.codex/hooks.json`, `hooks/hooks.json`, inline hooks in `config.toml` | Treat as risky lifecycle behavior. Convert only with known event/matcher/input/output mapping. |

## Codex-Specific Signals

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · references/source-gemini.md (reported line 17)May include surrounding context.

md
| `agents/*.md` | Gemini subagents. Convert known fields to target subagent/custom-agent format; otherwise mark partial. |
| `hooks/hooks.json` | Gemini lifecycle hooks. Treat as risky lifecycle behavior requiring event/schema mapping. |
| `policies/*.toml` | Gemini policy rules/safety checkers. Treat as target-specific safety configuration, not as a skill. |
| `.gemini/settings.json`, `~/.gemini/settings.json`, `mcpServers` | MCP/tool setup. Treat credentials, trust, include/exclude tools, and scopes as dependency-bound. |

## Gemini-Specific Signals

MCP Config Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · references/target-claude.md (reported line 58)May include surrounding context.

md
- Convert Codex `AGENTS.md` and Gemini `GEMINI.md` into `CLAUDE.md` guidance or a bridge note.
- Convert Codex custom-agent TOML into Claude subagent Markdown only for known fields.
- Convert Gemini extension agents into Claude agent Markdown only for known fields.
- Keep MCP/provider setup as dependency notes unless the user explicitly asks to stage `.mcp.json`.
- Do not emit Claude dynamic context injection (`!` shell syntax) unless the source already used it and the command has been security reviewed.
- Do not enable hooks automatically.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/audit_skill.py (reported line 96)May include surrounding context.

python
re.compile(rf"\.{lit('s', 's', 'h')}/"),
        re.compile(rf"\.{lit('a', 'w', 's')}/"),
        re.compile(rf"\.{lit('c', 'o', 'n', 'f', 'i', 'g')}/"),
        re.compile(r"\bkeychain\b", re.IGNORECASE),
        re.compile(r"\bprintenv\b"),
        re.compile(r"\benv\s*>\b"),
    ],

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/audit_skill.py (reported line 162)May include surrounding context.

python
if explicit:
        return explicit, False

    env_pairs = {key.upper(): value.lower() for key, value in os.environ.items()}
    joined = " ".join(f"{key}={value}" for key, value in env_pairs.items())
    if "CODEX" in env_pairs or "codex" in joined:
        return "codex", True

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to inspect repositories, read references, potentially stage ported files, and document clone/fetch commands for remote sources, which implies meaningful file, shell, and possibly network use. Because it declares no explicit tool scope or allowed-tools boundary, a runtime may grant broader capabilities than intended, increasing the risk of unintended file modification, remote access, or command execution during analysis of untrusted skill/plugin content.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Enabling implicit invocation without trigger constraints allows this skill to be auto-selected in broader contexts than intended, which is risky because the skill can audit and stage ports of untrusted agent skills and plugins. In this context, unintended activation could cause the system to process adversarial repositories or generate follow-on actions based on unsafe inputs, increasing the chance of unsafe automation or trust boundary bypass.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/ecosystem-porting.md (reported line 32)May include surrounding context.

md
## Scope Heuristics

Choose a recommended scope without asking when the source structure is clear:

- **Single skill**: one `SKILL.md` and no plugin/command/agent/MCP structure.
- **Focused bundle**: multiple skills, commands, or integrations and no explicit request for all content.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/target-claude.md (reported line 39)May include surrounding context.

md
- Single skill: `skills/claude/<skill-name>/`
- Multi-skill/plugin source: `ports/<source-name>/claude/`
- Do not write directly to `~/.claude/skills/` or `.claude/skills/` unless the user explicitly asks for installation.

## Target-Specific Package Surfaces

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/target-codex.md (reported line 37)May include surrounding context.

md
- Single skill: `skills/codex/<skill-name>/`
- Multi-skill/plugin source: `ports/<source-name>/codex/`
- Do not write directly to `~/.codex/skills/` unless the user explicitly asks for installation.

## Claude-to-Codex Rules

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The reference instructs running npx skills add . --list without pinning a package version or verifying provenance. npx can resolve and execute remote package code at runtime, so an unexpected package update, typo-squatted dependency, or registry compromise could lead to arbitrary code execution during validation.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · references/target-gemini.md (reported line 17)May include surrounding context.

assets/ # optional templates or static assets

text

Gemini discovers skills from `.gemini/skills/`, `~/.gemini/skills/`, and the `.agents/skills/` alias. Keep `SKILL.md` frontmatter valid with `name` and `description`.

## Project Instructions

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/target-gemini.md (reported line 29)May include surrounding context.

md
- Single skill: `skills/gemini/<skill-name>/`
- Multi-skill/plugin source: `ports/<source-name>/gemini/`
- Do not write directly to `~/.gemini/skills/`, `.gemini/skills/`, or `.agents/skills/` unless the user explicitly asks for installation.

## Target-Specific Package Surfaces

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
76% confidence
Finding

The module-level security boundary says the script 'writes only when --output is explicitly provided'. However, the code supports a 'port' mode and constructs a porting map plus output_path values for staged translated artifacts, which contradicts the documented write boundary as written. Even if this file itself only emits a report, the documentation presents a stricter no-write guarantee than the behavior implied by the porting workflow it advertises.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The manifest describes a tool for auditing and porting skill repositories, but this file enumerates all environment variables and searches them to infer the target runtime. Reading the ambient environment is broader than necessary for repository auditing and may expose unrelated host context, while the target agent could be supplied explicitly or inferred from repository contents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.