Back to skill

Security audit

Response Tone Polisher

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent reviewer-response tone polisher, but its script can read and overwrite arbitrary local files and asks users to install unnecessary unpinned packages.

Review before installing. Use this only in a sandboxed workspace, avoid running the pip install step unless the dependencies are removed or pinned, and do not pass absolute paths, parent-directory paths, symlinks, or sensitive files as inputs or outputs. Expect local files to be read or written when using file-based or interactive modes.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
requirements.txt:1
Finding

Unnecessary and Unpinned Third-Party Dependencies Shadow Standard-Library Modules

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/main.py:552
Finding

Unrestricted User-Controlled File Reads and File Overwrites

Content
View full analysis
Remediation
View remediation
Path: candidate = (WORKSPACE / value).resolve() if candidate != WORKSPACE and WORKSPACE not in candidate.parents: raise ValueError("Path must remain within the workspace") return candidate ``` 3. Apply containment validation separately to both input and output paths. 4. Reject symbolic links where they are unnecessary. For stronger protection, use descriptor-based operations and platform-supported no-follow flags to reduce time-of-check/time-of-use races. 5. Do not infer whether an argument is text or a filename solely from whether a same-named file exists. Use separate, explicit options such as `--reviewer-file` and `--reviewer-text`. 6. Refuse to overwrite existing files by default. Use exclusive creation mode (`x`) or require an explicit `--overwrite` option. 7. For intentional replacement, write to a securely created temporary file in the same approved directory and atomically replace the destination after successful completion. 8. Run the Skill under a dedicated least-privilege account with access only to its designated workspace. 9. Add tests covering absolute paths, `../` traversal, symbolic links, existing output files, and paths outside the workspace. ]]>
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (11)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill documentation indicates local script execution plus file read/write behavior, but it does not declare any explicit tool scope such as allowed-tools or permissions. That omission weakens sandboxing and review controls because an agent may invoke filesystem-capable code without a clear least-privilege contract, increasing the chance of unintended file access or writes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The 'When to Use' section includes generic activation conditions about academic writing, fallback paths, and missing inputs that could match many unrelated skills. Because this is a markdown file, these broad trigger descriptions risk unintended invocation beyond response-letter tone polishing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a text-polishing skill, but the implementation also persists results to user-specified files in interactive mode. Writing files is not an obvious requirement of tone transformation itself and expands the behavior beyond purely polishing text.

Content

No source excerpt is available for this finding.

Tainted flow: 'save' from input (line 543, user input) → open (file write)

Medium
Category
Data Flow
Confidence
95% confidence
Finding

The interactive save path is taken directly from user input and passed to open() for writing without validation, allowing the program to create or overwrite any file the current user can access. In a skill/agent context, arbitrary file writes can be abused to clobber configuration, shell startup files, or other local data, even though the feature appears intended as a convenience save option.

Content

Scanner excerpt · scripts/main.py (reported line 552)May include surrounding context.

python
"improvements": result.improvements,
            "suggestions": result.suggestions
        }
        with open(save, 'w') as f:
            json.dump(output, f, indent=2)
        print(f"✅ Saved to {save}")

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The code supports reading arbitrary local files as inputs and writing the generated response to a user-chosen path. The manifest only states that the skill polishes response letters by transforming language, not that it has general local file read/write behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The limitation 'Best for English-language responses' establishes a language constraint in the skill's natural-language instructions. While mild, it does not explicitly offer language choice or explain a required regional/compliance reason, so it may conflict with language/locale neutrality expectations.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · references/tone_patterns.md (reported line 199)May include surrounding context.

md
Don't promise changes you won't make.

❌ "We will conduct additional experiments..." (if you won't)
✅ "We respectfully note that additional experiments are beyond the scope..."

## Quick Reference: Severity Levels

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
dataclasses
enum

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
60% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · requirements.txt (reported line 2)May include surrounding context.

text
dataclasses
enum

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The interactive save flow can overwrite or create files without any warning, confirmation, or visibility into the consequences. While this is more of a safety/usability weakness than a direct exploit primitive, in an automated or semi-automated environment it increases the chance of accidental data loss or unintended modification of sensitive files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The CLI output option writes directly to the user-supplied path with no disclosure or overwrite protection, which can lead to accidental file clobbering. In a skill context, this matters because users may not expect an agent tool to modify local files silently when given an output argument.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.