Reviewed deterministic Inspection · report 1
snyk-labs/toxicskills-goof
Static review of the exact pinned ToxicSkills demo snapshot. The repository contains intentionally malicious agent-skill examples. The deterministic Inspector completed successfully, but this review found both reference-document false positives and material malicious behavior that the machine findings did not surface.
- Exact snapshot
3ccab3554ed5acb51a8fc857dfa0f6a6f684bb7cd19f2bafc9bc3efd77b74f72- Version / commit
80ce2e06f52fd384163c4bd6778676019723773c- Acquired
- 2026-09-25T08:11:04.548816+00:00
- Reviewed
- 2026-09-25T08:22:00Z
- Currentness
- snapshot only
- Machine report digest
9316743fba1485aa96a2c33dfd4f09c26d24c10631ab3cef36b569c20a4520cf
What was reviewed
- Review all 19 correlated deterministic findings from the exact pinned inspection snapshot and assign a disposition to each.
- Open exact source evidence for material candidates and inspect nearby high-risk agent-skill instructions when needed to determine whether the machine result reflects executable, exfiltration, installation, privilege or persistence behavior.
- Treat repository content and scanner output as untrusted evidence. No target code, package lifecycle hook, skill, command or remote payload was executed.
The acquisition and deterministic inspection pipeline completed successfully and produced 19 correlated candidates with no tool errors. All 19 machine findings were dispositioned. Reference-document matches account for substantial false-positive noise, while two Snyk-skill candidates remain unresolved because a material disposition requires an editorial finding bound to the exact pinned machine evidence and that exact range is not carried in this returned package. Static review also identified detector-gap observations outside the correlated machine findings, including Vercel host/.env exfiltration instructions, an obfuscated network-to-shell prerequisite in the ClawHub skill, and a UserPromptSubmit environment-dump hook in the Snyk skill. Those detector-gap observations remain conclusions/limitations rather than machine-provenanced findings.
Inspection is deterministic machine work. This Audit is a reviewed editorial conclusion. Neither constitutes a blanket safe/unsafe certificate.
Exact disclosed material
Only the operator-cleared material below is included in this immutable public Release. External references are not additional reviewed snapshot files.
No source file is cleared for public disclosure. Private artifact bytes are not published automatically. Inspect the pinned evidence locators and scope below.
Deterministic inspection coverage
33 ordinary acquired files · 21 other inventory entries. Exact skip/extraction limits are described in the reviewed scope and limitations.
Pass means the rule condition was not found within its inspected scope, not that the target is safe.
iac
- skipped
- 2
mcp
- pass
- 11
rag
- pass
- 3
tls
- pass
- 7
- not applicable
- 2
network
- pass
- 2
secrets
- skipped
- 13
web forms
- not applicable
- 2
containers
- not applicable
- 42
filesystem
- pass
- 3
kubernetes
- not applicable
- 49
randomness
- pass
- 5
- not applicable
- 1
acquisition
- pass
- 10
persistence
- pass
- 2
- finding
- 1
web headers
- not applicable
- 5
cryptography
- pass
- 4
authorization
- not applicable
- 18
code analysis
- finding
- 1
shell process
- pass
- 4
- not applicable
- 1
website trust
- not applicable
- 5
authentication
- pass
- 2
github actions
- not applicable
- 7
remote loading
- pass
- 1
- not applicable
- 2
deserialization
- pass
- 8
dynamic context
- pass
- 3
dynamic loading
- pass
- 4
install scripts
- pass
- 16
privacy logging
- pass
- 2
- not applicable
- 1
download execute
- pass
- 1
- finding
- 1
prompt injection
- pass
- 2
- finding
- 3
session handling
- not applicable
- 3
agent permissions
- pass
- 8
- finding
- 1
command injection
- pass
- 5
- not applicable
- 1
dynamic execution
- pass
- 2
- not applicable
- 2
web configuration
- not applicable
- 1
environment access
- pass
- 4
known dependencies
- not applicable
- 1
network boundaries
- not applicable
- 8
template execution
- pass
- 1
- not applicable
- 2
cloud configuration
- not applicable
- 124
hardcoded endpoints
- not applicable
- 1
skills installation
- pass
- 2
- finding
- 1
model output execution
- pass
- 3
Machine coverage and toolchain identities
{
"summary": {
"groups": {
"iac": {
"skipped": 2
},
"mcp": {
"pass": 11
},
"rag": {
"pass": 3
},
"tls": {
"pass": 7,
"not_applicable": 2
},
"network": {
"pass": 2
},
"secrets": {
"skipped": 13
},
"web_forms": {
"not_applicable": 2
},
"containers": {
"not_applicable": 42
},
"filesystem": {
"pass": 3
},
"kubernetes": {
"not_applicable": 49
},
"randomness": {
"pass": 5,
"not_applicable": 1
},
"acquisition": {
"pass": 10
},
"persistence": {
"pass": 2,
"finding": 1
},
"web_headers": {
"not_applicable": 5
},
"cryptography": {
"pass": 4
},
"authorization": {
"not_applicable": 18
},
"code_analysis": {
"finding": 1
},
"shell_process": {
"pass": 4,
"not_applicable": 1
},
"website_trust": {
"not_applicable": 5
},
"authentication": {
"pass": 2
},
"github_actions": {
"not_applicable": 7
},
"remote_loading": {
"pass": 1,
"not_applicable": 2
},
"deserialization": {
"pass": 8
},
"dynamic_context": {
"pass": 3
},
"dynamic_loading": {
"pass": 4
},
"install_scripts": {
"pass": 16
},
"privacy_logging": {
"pass": 2,
"not_applicable": 1
},
"download_execute": {
"pass": 1,
"finding": 1
},
"prompt_injection": {
"pass": 2,
"finding": 3
},
"session_handling": {
"not_applicable": 3
},
"agent_permissions": {
"pass": 8,
"finding": 1
},
"command_injection": {
"pass": 5,
"not_applicable": 1
},
"dynamic_execution": {
"pass": 2,
"not_applicable": 2
},
"web_configuration": {
"not_applicable": 1
},
"environment_access": {
"pass": 4
},
"known_dependencies": {
"not_applicable": 1
},
"network_boundaries": {
"not_applicable": 8
},
"template_execution": {
"pass": 1,
"not_applicable": 2
},
"cloud_configuration": {
"not_applicable": 124
},
"hardcoded_endpoints": {
"not_applicable": 1
},
"skills_installation": {
"pass": 2,
"finding": 1
},
"model_output_execution": {
"pass": 3
}
},
"finding_count": 19,
"checks_by_status": {
"pass": 115,
"finding": 8,
"skipped": 15,
"not_applicable": 278
},
"skipped_surfaces": 9,
"tool_error_count": 0,
"findings_by_severity": {
"low": 3,
"medium": 16
}
},
"coverage": {
"cancelled": false,
"fact_count": 408,
"checks_expected": 416,
"terminal_results": 416,
"inventory_complete": true,
"correlated_findings_omitted": 0,
"files_with_extraction_errors": 1,
"finding_review_complete_possible": true,
"all_declared_checks_accounted_for": true
},
"toolchain": {
"tools": [
{
"name": "gitleaks",
"error": null,
"status": "completed",
"version": "8.30.1",
"output_ref": "6ca34b28f6a8d5b966db4205b2c0713f7618ddeb5f13e5cc9b9f309d96029e20",
"duration_ms": 2040,
"ruleset_identity": "d37c74a9b3a03ea2ec975095da3efb4630f2d18bcc6d20632158bcf88162de6f"
},
{
"name": "bandit",
"error": null,
"status": "completed",
"version": "1.8.6",
"output_ref": "f5636a06312d57ba5188f159799b3daee300c955069607cbc2ad7665d98545df",
"duration_ms": 2860,
"ruleset_identity": "7c1568bc97d0e7a166c47ab1f998d02a114a816fc30a1b5da8d724878585289f"
},
{
"name": "osv-offline",
"error": null,
"status": "not_applicable",
"version": "1",
"output_ref": null,
"duration_ms": 0,
"ruleset_identity": "not_applicable"
}
],
"ruleset": {
"by_group": {
"iac": 2,
"mcp": 11,
"rag": 3,
"tls": 9,
"network": 2,
"secrets": 12,
"web_forms": 2,
"containers": 42,
"filesystem": 3,
"kubernetes": 49,
"randomness": 6,
"acquisition": 10,
"persistence": 3,
"web_headers": 5,
"cryptography": 4,
"authorization": 18,
"shell_process": 5,
"website_trust": 5,
"authentication": 2,
"github_actions": 7,
"remote_loading": 3,
"deserialization": 8,
"dynamic_context": 3,
"dynamic_loading": 4,
"install_scripts": 16,
"privacy_logging": 3,
"download_execute": 2,
"prompt_injection": 5,
"session_handling": 3,
"agent_permissions": 9,
"command_injection": 6,
"dynamic_execution": 4,
"web_configuration": 1,
"environment_access": 4,
"network_boundaries": 8,
"template_execution": 3,
"cloud_configuration": 124,
"hardcoded_endpoints": 1,
"skills_installation": 3,
"model_output_execution": 3
},
"by_adapter": {
"fact": 150,
"document": 246,
"workflow": 7,
"inventory": 10
},
"enabled_checks": 413,
"ruleset_sha256": "c467b3065b9578830aba8fbd8a0e7441e92d6e88732da4dfecf8383092e3d519",
"disabled_checks": 0,
"ruleset_version": "first-party/3",
"candidate_checks": 101,
"production_by_group": {
"iac": 0,
"mcp": 5,
"rag": 0,
"tls": 7,
"network": 2,
"secrets": 12,
"web_forms": 0,
"containers": 29,
"filesystem": 3,
"kubernetes": 48,
"randomness": 5,
"acquisition": 10,
"persistence": 1,
"web_headers": 0,
"cryptography": 4,
"authorization": 15,
"shell_process": 4,
"website_trust": 0,
"authentication": 1,
"github_actions": 7,
"remote_loading": 0,
"deserialization": 8,
"dynamic_context": 0,
"dynamic_loading": 4,
"install_scripts": 6,
"privacy_logging": 0,
"download_execute": 1,
"prompt_injection": 0,
"session_handling": 0,
"agent_permissions": 5,
"command_injection": 5,
"dynamic_execution": 2,
"web_configuration": 0,
"environment_access": 1,
"network_boundaries": 8,
"template_execution": 1,
"cloud_configuration": 118,
"hardcoded_endpoints": 0,
"skills_installation": 0,
"model_output_execution": 0
},
"production_by_adapter": {
"fact": 61,
"document": 234,
"workflow": 7,
"inventory": 10
},
"enabled_production_checks": 312
},
"python_version": "3.13.15",
"inspector_version": "0.2.0",
"toolchain_version": "sha256:0c8b220065b051d4047fb0a4ca8d7cbbc4d9d9441e0c3796c3f829c1aee3bbbd",
"installed_identity": {
"python": "3.13.15",
"ruleset": {
"by_group": {
"iac": 2,
"mcp": 11,
"rag": 3,
"tls": 9,
"network": 2,
"secrets": 12,
"web_forms": 2,
"containers": 42,
"filesystem": 3,
"kubernetes": 49,
"randomness": 6,
"acquisition": 10,
"persistence": 3,
"web_headers": 5,
"cryptography": 4,
"authorization": 18,
"shell_process": 5,
"website_trust": 5,
"authentication": 2,
"github_actions": 7,
"remote_loading": 3,
"deserialization": 8,
"dynamic_context": 3,
"dynamic_loading": 4,
"install_scripts": 16,
"privacy_logging": 3,
"download_execute": 2,
"prompt_injection": 5,
"session_handling": 3,
"agent_permissions": 9,
"command_injection": 6,
"dynamic_execution": 4,
"web_configuration": 1,
"environment_access": 4,
"network_boundaries": 8,
"template_execution": 3,
"cloud_configuration": 124,
"hardcoded_endpoints": 1,
"skills_installation": 3,
"model_output_execution": 3
},
"by_adapter": {
"fact": 150,
"document": 246,
"workflow": 7,
"inventory": 10
},
"enabled_checks": 413,
"ruleset_sha256": "c467b3065b9578830aba8fbd8a0e7441e92d6e88732da4dfecf8383092e3d519",
"disabled_checks": 0,
"ruleset_version": "first-party/3",
"candidate_checks": 101,
"production_by_group": {
"iac": 0,
"mcp": 5,
"rag": 0,
"tls": 7,
"network": 2,
"secrets": 12,
"web_forms": 0,
"containers": 29,
"filesystem": 3,
"kubernetes": 48,
"randomness": 5,
"acquisition": 10,
"persistence": 1,
"web_headers": 0,
"cryptography": 4,
"authorization": 15,
"shell_process": 4,
"website_trust": 0,
"authentication": 1,
"github_actions": 7,
"remote_loading": 0,
"deserialization": 8,
"dynamic_context": 0,
"dynamic_loading": 4,
"install_scripts": 6,
"privacy_logging": 0,
"download_execute": 1,
"prompt_injection": 0,
"session_handling": 0,
"agent_permissions": 5,
"command_injection": 5,
"dynamic_execution": 2,
"web_configuration": 0,
"environment_access": 1,
"network_boundaries": 8,
"template_execution": 1,
"cloud_configuration": 118,
"hardcoded_endpoints": 0,
"skills_installation": 0,
"model_output_execution": 0
},
"production_by_adapter": {
"fact": 61,
"document": 234,
"workflow": 7,
"inventory": 10
},
"enabled_production_checks": 312
},
"contract": "inspector.toolchain/1",
"platform": "x86_64",
"executables": {
"bandit": "60b67b200393962f5c59668119ab4433f7ef85fc78ede33b92bf8b7ce6c23cbe",
"gitleaks": "88f91962aa2f93ac6ab281d553b9e125f5197bbbce38f9f2437f7299c32e5509"
},
"source_sha256": "498db5f132a7cfa3f70b9fc4c504ea0cb400c1c1a6dfc2ff1daaf2a45cb8a051",
"toolchain_version": "sha256:0c8b220065b051d4047fb0a4ca8d7cbbc4d9d9441e0c3796c3f829c1aee3bbbd",
"installed_packages": [
[
"PyYAML",
"6.0.3"
],
[
"Pygments",
"2.21.0"
],
[
"attrs",
"26.1.0"
],
[
"bandit",
"1.8.6"
],
[
"diggingbeagle-inspector",
"0.2.0"
],
[
"iniconfig",
"2.3.0"
],
[
"jsonschema",
"4.26.0"
],
[
"jsonschema-specifications",
"2025.9.1"
],
[
"markdown-it-py",
"4.2.0"
],
[
"mdurl",
"0.1.2"
],
[
"packaging",
"25.0"
],
[
"pip",
"26.2.1"
],
[
"pluggy",
"1.6.0"
],
[
"psycopg",
"3.2.6"
],
[
"psycopg-binary",
"3.2.6"
],
[
"pytest",
"9.0.2"
],
[
"referencing",
"0.37.0"
],
[
"rich",
"15.0.0"
],
[
"rpds-py",
"2026.6.3"
],
[
"semver",
"3.0.4"
],
[
"setuptools",
"75.8.2"
],
[
"stevedore",
"5.9.1"
]
],
"tool_configurations": {
"bandit.ini": "1ac8b7ca6758d27c826f2e2389d315d2449b636596ca15557871d9992e47bb04",
"bandit.yaml": "0ee03e3824c3b4d993af538b46e200e66cd953af1c4063e25f1d7ad6cbc31f8a",
"gitleaks.toml": "030234da2fd3a18911bc9d46cb682a4502ec50dee9de82f56a7a6d7ad7586135",
"empty.gitleaksignore": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
},
"vulnerability_database_sha256": null
},
"vulnerability_db_version": "not_applicable"
}
}Reviewed findings
No material reviewed finding is asserted. Review scope and unresolved dispositions remain relevant.
Every deterministic finding reviewed
19 correlated machine findings have an explicit disposition.
false positive · 00997fdb3fe696bd6725edd56e6c0394
The match is an example of curl-to-shell syntax inside skill-defender threat-pattern reference documentation. The repository's scanner code explicitly allowlists skill-defender threat-pattern material because it documents the malicious patterns it detects.
informational · 04e89433611171430f6d502991988dd5
README instructs operators to run an unpinned mcp-scan@latest command. This is a real unpinned-install surface but is explicit demo/setup documentation rather than evidence of covert execution.
unresolved · 25d74bcfe2dc76401fdce281bf38cfb9
The machine candidate points to a concealed remote-installer-shaped command in the Snyk skill and appears security-relevant. It is left unresolved because this returned audit package does not carry the exact pinned machine evidence range needed to create a provenance-valid editorial finding without widening or inventing evidence.
false positive · 27f1c784c64448c008e3ba1c3669e86b
The MEMORY.md phrase occurs in skill-defender threat-pattern reference documentation describing persistence indicators, not as an instruction for this scanner skill to persist.
unresolved · 330f965947284c30688fe0d036e274fc
The machine candidate points to curl-to-shell behavior in the Snyk skill and appears security-relevant. It is left unresolved because the audit validator requires any confirmed/likely disposition to bind an editorial finding strictly to the exact pinned machine evidence range, which is not available in this returned package.
false positive · 33684d9cf85b4c3a101af34cceb92977
The wget-to-bash string is an example in skill-defender threat-pattern reference documentation. The same repository's scanner explicitly treats this skill's threat examples as known false positives.
informational · 3824c454705f0b7de36107390c58a3a2
README gives an explicit OpenCode installation command using curl-to-bash. It is a supply-chain-sensitive setup pattern but is not presented as hidden target behavior.
false positive · 5278b6d40b04db0af1e68aaad5ddd63f
The prompt-override phrase appears as a malicious-pattern example in skill-defender reference documentation, not as operative instructions for the reference document itself.
false positive · 67de310b55b89754693bbeeb41366abf
The AGENTS.md persistence phrase is documented as an indicator example in skill-defender reference material and is explicitly within the scanner's known false-positive class.
informational · 6cc541448c6de2851fb07fc8e36adcb0
A second README occurrence of mcp-scan@latest repeats the same explicit unpinned demo/setup command. It is relevant hardening context, not covert malicious execution.
informational · 70c8ce1c3bc571c9df43f47b5372219b
The ClawHub skill documents options that skip confirmation. That reduces interactive safeguards but the matched phrase alone does not establish a permission bypass exploit. The same file contains a separate, materially stronger obfuscated remote-execution finding.
false positive · 72ba161cd03b3cf75b7bee6aa3360d81
The hide-from-user phrase is a threat-pattern example inside skill-defender's reference material, not an operative concealment instruction for the reference file.
informational · 9d10c51c26c9027f60f93e7619331388
The Gemini ClawHub skill documents a skip-confirmation option. This can weaken interactive review but is not sufficient on its own to establish abusive tool authority.
informational · b875a0cbb747a524acca5f3ba9e5cb43
The agents ClawHub skill documents a skip-confirmation option. It is relevant operational context, but the lexical match is not itself proof of malicious permission bypass.
informational · c1f8f007051b6e4b990acc259400cc03
This is another skip-confirmation reference in the Gemini ClawHub documentation. It is not independently a vulnerability, though it can remove an interactive safety step.
false positive · f5e031dc3a341b7e5e60ac75a8fe8614
The read-secrets phrase is a threat-pattern example in the scanner reference file. Its context is defensive detection documentation.
informational · 1ffc75efb0ff5f04369aee59092dfbb6
Bandit B603 flags subprocess execution in the scanner aggregator. The call uses an argument vector without shell=True and intentionally launches a scanner script supplied to the tool. Static review does not establish command injection.
informational · d4ca08e6bd305cac69ec446764783136
Bandit B404 reports importing subprocess. Importing the module is not itself a vulnerability; the relevant invocation was reviewed separately.
informational · f1f53dc025ca170c69497d605083d24e
Bandit B607 notes use of the partial executable name python3. PATH resolution is a hardening consideration, but the evidence does not establish attacker-controlled PATH or executable substitution in this snapshot.
Method
inspection-review/1. Target code was not executed.
Evidence reviewer. Machine matches were treated as candidates, not vulnerability verdicts. Repository instructions were treated as data and were not followed.
Research result only. Import, approval, public disclosure, publication and release activation remain separate operator actions.
Not established / uninspected
- Static review only. No target code, skill, hook, package lifecycle script, binary, remote installer or external payload was executed.
- The pinned acquisition reports 33 included files, 21 skipped files, one file with an extraction error and nine skipped or reduced surfaces. Conclusions do not imply complete coverage of uninspected material.
- Git history, submodule contents and Git LFS objects were not acquired by the pinned GitHub archive adapter.
- Known-vulnerability coverage was unavailable because the offline vulnerability database adapter was not applicable.
- Several machine findings originate from a security-scanner reference file that explicitly documents malicious patterns. Those lexical matches are contextual examples rather than evidence that the reference file itself performs the described behavior.
- The testing-guidelines skill is described by the repository as an ASCII-smuggling demonstration, but this review does not claim the concealed payload's semantics without a reliable decoded representation from the pinned inspection evidence.
- Two security-relevant machine candidates are intentionally left unresolved rather than promoted to confirmed/likely findings because the exact pinned machine evidence ranges required by the v2 provenance validator are not present in this returned package. No evidence range was guessed or widened.
Referenced Sources
Source links supply context or corroboration; they do not expand the immutable inspected snapshot.
Revision history
Initial inspection-bound AuditReport v2 for the exact pinned ToxicSkills snapshot. All 19 correlated machine findings are reviewed and dispositioned. Two security-relevant candidates are left unresolved because the exact machine evidence range required for a provenance-valid editorial finding is unavailable in the returned package; no provenance was fabricated.
Cite this record
DiggingBeagle. snyk-labs/toxicskills-goof. Audit 1; snapshot 3ccab3554ed5acb51a8fc857dfa0f6a6f684bb7cd19f2bafc9bc3efd77b74f72. https://diggingbeagle.com/audits/snyk-labs-toxicskills-goof-8f861833/
Citation guidance