Back to skill

Security audit

diagnose-hardware-root-causes-rd

Security checks for vulnerabilities and agentic risk

Overview

This skill provides a disclosed hardware root-cause workflow and a local PNG exporter, with no evidence of hidden access, persistence, or data exfiltration.

Reasonable to install for engineering RCA work. Treat its conclusions as diagnostic support, not certification; have safety-critical or regulated findings reviewed by qualified engineers. When using the PNG exporter, run it on trusted or reasonably sized JSON inputs, avoid maximum DPI for large trees, and review outputs before sharing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ceae_tree_export.py:51
Finding

Unbounded JSON content and rendering dimensions enable resource exhaustion

Content
View full analysis
dict[str, Any]: if not path.is_file(): raise TreeValidationError(f"Input file does not exist: {path}") try: value = json.loads(path.read_text(encoding="utf-8-sig")) except (OSError, json.JSONDecodeError) as exc: raise TreeValidationError(f"Cannot read valid JSON from {path}: {exc}") from exc if not isinstance(value, dict): raise TreeValidationError("Top-level JSON value must be an object") return value ``` ```python def optional_text(value: Any, field: str, identifier: str) -> str: if value is None: return "" if isinstance(value, list): value = "; ".join(str(item) for item in value) if not isinstance(value, str): raise TreeValidationError(f"Node {identifier!r} {field!r} must be text or an array") return " ".join(value.replace("\x00", " ").split()) ``` ```python def wrap_label(node: FlatNode) -> str: label = "\n".join( textwrap.wrap(node.label, width=WRAP_WIDTH, break_long_words=False, break_on_hyphens=False) ) if node.evidence: label += f"\nEvidence: {node.evidence}" return label ``` ```python figure_width = min(MAX_FIGURE_INCHES, max(12.0, x_span + 4.0)) figure_height = min(MAX_FIGURE_INCHES, max(8.0, y_span + 5.0)) ``` ```python def validate_output(path: Path, force: bool, dpi: int) -> None: if path.suffix.lower() != ".png": raise TreeValidationError("Output path must use the .png suffix") if path.exists() and not force: raise TreeValidationError(f"Refusing to replace existing output without --force: {path}") if not 72 <= dpi <= 600: raise TreeValidationError(" ...[truncated 3648 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.