Back to skill

Security audit

Swmm Experiment Audit

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its SWMM audit purpose, but it automatically writes outside the run directory in direct-script mode and can execute adjacent repository helper code during auditing.

Install only if you are comfortable with an audit helper that writes Markdown/JSON records and, when the direct script is used, copies notes into a local Obsidian vault by default. Prefer `aiswmm audit` without `--obsidian`, or pass `--no-obsidian` to the direct script, unless you explicitly want vault updates. Run it only in a trusted Agentic SWMM repository because the audit script can execute adjacent helper modules when certain water-quality or uncertainty artifacts are present.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description is for a post-run auditing/consolidation skill that should collect artifacts from SWMM runs and produce auditable provenance, comparison records, and Obsidian notes tied to specific executions. The provided code instead only bootstraps a local Obsidian vault structure with static folders, configuration, and template notes. While this supports the broader auditing ecosystem, it is not the described core behavior. There is no logic to inspect runs, read inputs/commands/artifacts, compute metrics or diffs, or emit run-level provenance/comparison outputs. Therefore the code's actual purpose is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes operations that read from run directories, write audit outputs, update an Obsidian index, and invoke CLI/script commands, but it declares no explicit tool scope or permission boundaries. In an agent setting, that ambiguity can lead to broader-than-necessary file and shell access, increasing the chance of unintended writes, data exposure, or command execution outside the intended audit workflow.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script is configured to write audit notes by default into a fixed Obsidian vault path under the user's home directory, outside the run artifact directory. In a security-sensitive agent setting, writing to user knowledge stores by default can leak run metadata, overwrite existing notes, and create unexpected side effects beyond the requested workspace.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A default home-directory Obsidian destination means the script silently persists data to a user-facing personal vault without confirmation. In this skill's context, audit artifacts may include commands, paths, repo state, and run metadata, so silent export increases privacy and integrity risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/audit_run.py (reported line 122)May include surrounding context.

python
def run_git(repo_root: Path, *args: str) -> str | None:
    proc = subprocess.run(["git", *args], cwd=repo_root, capture_output=True, text=True)
    if proc.returncode != 0:
        return None
    return proc.stdout.strip()

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/audit_run.py (reported line 130)May include surrounding context.

python
def get_swmm_version(repo_root: Path) -> str | None:
    try:
        proc = subprocess.run(["swmm5", "--version"], cwd=repo_root, capture_output=True, text=True)
    except FileNotFoundError:
        return None
    if proc.returncode != 0:

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The audit script dynamically loads and executes Python code from another repository path via importlib, which means running the audit can execute arbitrary code present in that helper script. In an agent-skill context, this violates the expected boundary of artifact consolidation and creates a code-execution primitive if the repository contents are modified or untrusted.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code conditionally imports and executes an external source_decomposition.py module during audit, causing the audit action to trigger additional workflow logic beyond note generation. That expands the trust boundary and allows arbitrary Python execution from repository-controlled content whenever certain artifacts are present.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script performs multiple writes—provenance JSON, comparison JSON, markdown note, model diagnostics, optional Obsidian copy, and index update—in one execution path without a dry-run or explicit disclosure at the execution point. In an agent workflow, broad write side effects can surprise users and make it easier for a compromised or misused skill to alter records beyond the expected output set.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/audit_run.py:499