Back to skill

Security audit

元安全 yotta-agent-hardening

Security checks for vulnerabilities and agentic risk

Overview

This is a defensive agent-hardening scanner with disclosed local install, audit, and guardrail writes; the sensitive-looking strings are mostly detection rules and examples.

Install only from a source and version you trust, prefer an explicit --agent or --dir target over global installation, and scan narrowly scoped directories because the scanner will read text files under the target. Expect local audit logs and optional guardrail/report files to be written.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (79)

YARA rule 'exploit_framework': Exploit framework components and payloads [hacktools]

High
Category
YARA Match
Content
- **Authorization**: directory and configuration inspection assumes the user owns or is authorized for them; sensitive data (keys / credentials) is reported by location and risk level only — contents are never echoed.
- **Legal redlines**: this skill is for defense / hardening / education on your own environments only; it produces no executable injection strings, no evasion, no phishing and no social-engineering steps; users are responsible for applicable law (e.g. China Cybersecurity Law, Criminal Law Articles 285/286).

## Installation

Pick any of the four methods below; the order is the recommended priority. Skill files always come from **npm** (GitHub can be slow without a proxy; npm supports mirrors).

### Method 1: npm one-liner (recommended)

```text
# Optional China mirror: npm config set registry https://registry.npmmirror.com
npx -y @yottameta/yotta-agent-hardening --agent <agent-name>      # install to the agent's default user-level skills dir
npx -y @yottameta/yotta-age
Confidence
80% confidence
Finding
YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
This finding reinforces that the skill promises static, read-only safety analysis but appears to perform file writes and multi-directory skill operations instead of the advertised scans and reports. Such deception by capability mismatch can bypass user caution and creates a supply-chain style risk in agent ecosystems where 'security' branding earns extra trust.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding
This finding reinforces that the skill promises static, read-only safety analysis but appears to perform file writes and multi-directory skill operations instead of the advertised scans and reports. Such deception by capability mismatch can bypass user caution and creates a supply-chain style risk in agent ecosystems where 'security' branding earns extra trust.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Credential Access

High
Category
Privilege Escalation
Content
### 域 3:数据隔离

审视**数据怎么进、怎么出**:脚本读取路径(home / .ssh / .aws / .env / cookie / token 文件)、
输出面(写日志 / 上传 / 网络请求 / 消息)、配置文件里的凭据字面量。检测敏感读取、跨上下文外传链、
输出脱敏缺口、硬编码凭据。
Confidence
60% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
python3 scripts/yotta_agent_hardening.py scan ./agent-runtime
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- references/report-template.md — 加固扫描报告模板(JSON / Markdown / 留痕)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Ae1

High
Category
analysis-evasion
Content
- references/tutorial.md — 中文教程(新手全流程)
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected

Tool Parameter Abuse

High
Category
Tool Misuse
Content
install_to() {
  mkdir -p "$1/$SKILL_NAME"
  cp -r "$SOURCE_DIR/." "$1/$SKILL_NAME/"
  rm -rf "$1/$SKILL_NAME/.git"
  echo "installed -> $1/$SKILL_NAME"
}
Confidence
95% confidence
Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Credential Access

High
Category
Privilege Escalation
Content
r"(?i)osascript[^\n;]{0,120}(?:password|passphrase)",
         "macOS 弹窗套取密码", 90),
    Rule("CRE-002", "CredentialTheft", "critical",
         r"(?i)security\s+find-generic-password|keychain",
         "访问 macOS keychain 凭据", 85),
    Rule("CRE-003", "CredentialTheft", "high",
         r"(?i)(?:id_rsa|id_ed25519|id_dsa)\.?(?:pub)?\b",
Confidence
70% confidence
Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Static analysis

No suspicious patterns detected.