Back to skill

Security audit

Journal Club Presenter

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a straightforward journal-club outline generator, but its script can overwrite arbitrary writable files through an unrestricted output path.

Review before installing or running in an environment with broad write access. Use only for journal-club presentation outlines, choose an output path inside the intended workspace, and avoid letting untrusted content control the --output argument until path validation and overwrite safeguards are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:132
Finding

Unrestricted Output Path Allows Arbitrary File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/main.py, lines 132 and 149–150
Vulnerability Type: Unrestricted file write and path traversal
Risk Level: Medium

Vulnerable Code

python
parser.add_argument("--output", "-o", default="journal_club_outline.txt", help="Output file")
python
with open(args.output, 'w') as f:
    f.write(outline)

Technical Analysis

The command-line caller has complete control over args.output, which is passed directly to open() in write mode. The implementation performs no path normalization, workspace-boundary validation, parent-directory traversal rejection, symlink check, target-type check, or overwrite confirmation.

Python's 'w' mode creates a missing file or truncates an existing file before writing. It also follows symbolic links. Consequently, an attacker who can influence the script's command-line arguments can select any target writable by the process. Relative traversal paths such as ../../target and writable absolute paths are accepted.

This behavior conflicts with the intended control in SKILL.md, which states that output should be restricted to the workspace.

Attack Path

  1. An attacker influences the --output argument supplied by an agent, automation system, or user.
  2. The attacker supplies a traversal path, writable absolute path, or path to a symbolic link, for example:
    bash
    python scripts/main.py \
      --title "Example" \
      --output "../../writable-target"
    
  3. The script passes that path directly to open(args.output, 'w').
  4. The operating system resolves the path or follows the symbolic link.
  5. If the process has write permission, the selected file is created or truncated and replaced with the generated outline.

Impact Assessment

Exploitation does not grant privileges beyond those already held by the Python process. However, it allows an attacker to overwrite any file writable ...[truncated 472 chars]

Remediation
View remediation

Remediation Suggestions

  1. Define an explicit, trusted workspace output directory in configuration rather than accepting unrestricted destinations.
  2. Resolve the requested path and verify that it remains under the resolved workspace root:
    python
    from pathlib import Path
    
    workspace = Path("outputs").resolve()
    workspace.mkdir(parents=True, exist_ok=True)
    
    requested = (workspace / args.output).resolve()
    if requested == workspace or workspace not in requested.parents:
        parser.error("Output path must remain inside the output workspace")
    
  3. Prefer accepting only a filename rather than an arbitrary path, and reject absolute paths and .. components.
  4. Reject symbolic links and existing non-regular targets. Where practical, open files using operating-system flags that prevent symlink following.
  5. Use exclusive creation ('x') by default to prevent silent truncation, or require an explicit trusted --overwrite option.
  6. Apply restrictive file permissions and run the skill with the minimum necessary filesystem privileges.
  7. Add tests for absolute paths, ../ traversal, nested traversal, symlink targets, existing files, and destinations outside the workspace.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises executable behavior that can write files via scripts/main.py, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens policy enforcement and reviewability because a host system or operator cannot clearly constrain filesystem actions from the skill metadata alone.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'When to Use' section expands the trigger from journal club slide generation to broad 'academic writing tasks,' which can cause the skill to be invoked for requests beyond its validated scope. Over-broad routing increases the chance that users or orchestrators run the packaged script on mismatched inputs, leading to unsafe file handling, poor guardrail fit, or misleading outputs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.