Back to skill

Security audit

BrainHarness Docs

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a documentation organizer, but it tells agents to move or delete broad categories of project files without requiring explicit approval.

Install only if you are comfortable with an agent reorganizing files in your project. Before using it, instruct the agent to do a dry run, list every proposed move or deletion, archive by default, and never delete files unless you approve specific paths.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:40
Finding

Unconfirmed Deletion of User-Owned Project Files

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 40–53; related instruction at line 245
Vulnerability Type: Destructive file operation without mandatory confirmation
Risk Level: Medium

Vulnerable Instruction:

markdown
Before touching docs, clean non-documentation clutter from the project root.
Root-level noise (screenshots, recordings, debug logs, AI chat exports) is often
the biggest source of visual chaos — and it has nothing to do with documentation structure.

Run `ls | wc -l` and capture the count. Then identify and relocate:

| What to look for | Where it goes |
|-----------------|---------------|
| Screenshots, recordings (`.png`, `.mov`, `.mp4`) | `archive/media/` or `screenshots/` if curated |
| Debug/build logs (`*.log`, `firebase-debug.log`) | `archive/` or delete |
| AI chat exports, temp markdown dumps | `archive/` or delete |
| One-off config experiments | `archive/` or delete |

Do this first — it dramatically reduces root-level item count and makes the real
structure visible before you start reorganizing docs.

A related instruction at line 245 states:

markdown
| Chat logs in `docs/` | Not documentation | Move to `archive/` or delete |

Technical Analysis

The Skill is intended to reorganize project documentation, but its mandatory preliminary workflow instructs the Agent to clean the project root and permits deletion of broadly defined file classes. Terms such as “temp markdown dumps” and “one-off config experiments” are subjective and can include valuable drafts, configuration work, diagnostic evidence, or operational records.

The instructions do not require a dry run, an exact candidate-file inventory, per-file approval, backups, or use of a recoverable deletion mechanism. A textual recommendation to either archive or delete does not technically enforce the safer choice. Consequently, an Agent following the Skill may select deletion without obtainin ...[truncated 1659 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make archival, rather than deletion, the mandatory default for every candidate file.
  2. Require the Agent to present an exact list of files and proposed destinations before making changes.
  3. Require explicit user confirmation before deleting any file, with deletion approval scoped to individually identified paths.
  4. Use a recoverable trash mechanism or create a backup instead of performing permanent deletion.
  5. Exclude configuration files, logs, and diagnostic records from automatic deletion unless the user explicitly requests their removal.
  6. Add a dry-run phase that reports classifications, proposed moves, and proposed deletions without modifying the workspace.
  7. Replace subjective categories with narrow matching rules and require manual review where classification is uncertain.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
workspace/                          # NOT a git repo
├── CLAUDE.md                       # Repo map + cross-repo conventions + doc index
├── docker-compose.yml              # Cross-repo orchestration (lives at root)
├── .env / .env.example             # Shared secrets (lives at root)
│
├── repo-a/                         # Independent git repo
├── repo-b/                         # Independent git repo

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to execute npx skills add zning1994/brainharness-docs without pinning the skills package to a specific version. Because npx resolves and runs the latest matching package at execution time, a compromised or malicious future release could execute arbitrary code on the user's machine during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description includes generic phrases such as "where to put docs," "doc best practices," and "docs are messy," which are broad enough to match ordinary conversation rather than a clearly scoped invocation. The file also lacks negative examples or exclusion conditions that would clarify when the skill should not trigger.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.