Back to skill

Security audit

Security Guard

Security checks for vulnerabilities and agentic risk

Overview

This skill is a security guard, but several advertised protections can silently fail or be bypassed, so users should review it before relying on it.

Install only if you are prepared to review or fix the security-control gaps first. Do not rely on this package as an enforcement boundary for high-risk operations, custom role policies, blocked content patterns, or output redaction without additional safeguards. Also confirm where audit logs are stored, what metadata they contain, and how long they are retained.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/security-guard.js:64
Finding

High-Risk Operations Are Marked Allowed Before Confirmation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
src/permission-manager.js:10
Finding

Configured Authorization Roles and Strict Mode Are Ignored

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/content-safety.js:28
Finding

Configured Blocked Patterns Produce Warnings but Do Not Block Input

Content
View full analysis
w.severity === 'high').length === 0; ``` ### Technical Analysis The name `blockedPatterns` and the documented security behavior imply that a match should deny the input. Instead, those values are merged into `sensitiveWords`, where every match is assigned medium severity. Medium warnings do not affect the final `safe` decision, and the matching loop does not set `result.blocked`. Therefore, content containing only configured terms such as `password`, `secret`, or `token` returns `safe: true`. `SecurityGuard.check()` rejects content only when `safe` is false, so the configured block list is not enforced. This is not a pattern-matching bypass; it is a direct policy implementation error in which a successful match still permits the content. ### Attack Path 1. An administrator configures a value in `contentSafety.blockedPatterns`. 2. An attacker submits content containing that value but no separately recognized h ...[truncated 805 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/security-guard.js:123
Finding

Output Safety and Redaction Are Not Applied by the Security Guard

Content
View full analysis
{ const confirmResult = await this.confirm(userId, action, resource, confirmed); if (confirmResult.allowed) { return await fn(); } else { throw new Error('Operation rejected'); } } }); return; } return await fn(); } ``` An output scanner exists but is disconnected from both execution paths: ```javascript checkOutput(text) { const result = { safe: true, warnings: [], sanitized: text }; // Check whether execution results contain sensitive information const sensitivePatterns = [ { pattern: /password[:\s]+(\S+)/i, type: 'password' }, { pattern: /token[:\s]+([a-zA-Z0-9]{ ...[truncated 2333 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (16)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code records potentially sensitive metadata such as userId, IP address, userAgent, actions, resources, and arbitrary details, then persists them to disk. Although the file has internal comments describing audit logging, it lacks any confirmation prompt or user-facing disclosure warning that user/system activity will be collected and stored.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This JavaScript file uses Chinese-only natural-language descriptions in the header comments and key inline comments, such as "内容安全审查" and later operational annotations. For a general-purpose skill file, this imposes a specific language/locale without offering user choice or documenting that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code defines both requireConfirmation() and isHighRiskAction(), but there is no enforcement path in checkPermission() or elsewhere that requires confirmation before allowing high-risk actions. This creates a security-control gap where dangerous operations may proceed based solely on role permissions, despite the interface implying an additional approval step.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · src/permission-manager.js (reported line 20)May include surrounding context.

js
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · test/security-test.js (reported line 17)May include surrounding context.

js
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The package description is entirely in Chinese, which can imply a fixed language expectation for the skill without offering any language or locale choice. The policy specifically calls for flagging language or locale constraints when they are imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The cleanup routine automatically deletes older log files once the retention limit is exceeded. While log rotation is expected for an audit logger, the code does not include a visible warning, confirmation, or documented notice that persisted audit history may be removed automatically.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains user- and maintainer-facing natural language such as the header and method documentation in Chinese, while other descriptive strings are in English. Under the policy rule, forcing a specific language without opt-in can be a locale/language policy issue when no justification or language choice is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code file contains natural-language comments and descriptions entirely in Chinese, such as the module header and method documentation, without any indication that the skill is region-specific or that another language is available. Under the policy rule, forcing a specific language without user opt-in can be a locale-policy violation when no justification or alternative is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

This JavaScript file contains natural-language strings and comments entirely in Chinese, including the file header and inline section labels, without any indication that the skill is region-specific or that users may choose another language. Under the language/locale policy rule, forcing a specific language without opt-in can be a policy violation when no justification is provided.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

md
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 123)May include surrounding context.

md
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · src/permission-manager.js (reported line 20)May include surrounding context.

js
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · test/security-test.js (reported line 17)May include surrounding context.

js
permissions: {
    defaultRole: 'user',
    roles: {
      admin: { permissions: ['*'] },
      user: { permissions: ['file:read', 'file:write:home'] },
      guest: { permissions: ['file:read:home'] }
    }

Static analysis

No suspicious patterns detected.