Back to skill

Security audit

Skill Package Doctor

Security checks for vulnerabilities and agentic risk

Overview

The skill is not malicious, but its audit and proof-card claims are stronger than the bundled checker actually supports.

Install only if you treat this as a lightweight packaging checklist, not a real security audit. Review scripts and sensitive instructions manually before relying on its publish-ready score or sharing its proof card.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skill_doctor.py:90
Finding

Security Audit Bypass Through Incomplete Script and Instruction Analysis

Content
View full analysis
"): continue if not clean or re.search(r"\b(do not|never|avoid|refuse)\b", clean, re.I): continue if any(re.search(pattern, clean, re.I) for pattern in patterns): out.append(clean) return out[:5] ``` ### Technical Analysis The auditor detects whether a package contains files under `scripts/`, but it does not read or analyze those files. It only checks whether the `SKILL.md` body contains wording that mentions scripts, Python, Node, or a bundled script. Consequently, a malicious script can satisfy this check merely by being mentioned in otherwise benign documentation. The unsafe-instruction scanner also excludes several security-relevant Markdown contexts: - Fenced code blocks are skipped entirely. - Indented code blocks are skipped. - Block quotations are skipped. - Lines containin ...[truncated 2678 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The phrase "Use this skill when the user wants to review, debug, score, publish, or improve an agent skill package" lists very broad verbs without clear boundaries or exclusions. In a markdown skill description, this can create ambiguous invocation conditions because it is unclear when this skill should activate versus other generic review or debugging skills.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The write() helper creates directories and writes output files, which can modify the filesystem. In this code path there is no confirmation prompt, user-facing log, or nearby comment/docstring disclosing that files will be created or overwritten when output arguments are provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.