Back to skill

Security audit

Claude Code Statusline

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to install a Claude Code status line, but its installer persistently changes Claude configuration and has avoidable risks that could overwrite or corrupt user settings.

Review before installing. This skill does not show evidence of malicious exfiltration, but it will persistently alter Claude Code configuration and can overwrite an existing statusLine setting. Back up ~/.claude/settings.json and ~/.claude/settings.local.json first, inspect ~/.claude for symlinks or unexpected files, and only run install/configure/uninstall commands when you explicitly want those changes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/statusline_installer.py:81
Finding

Malformed Claude settings are silently replaced during installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/statusline_installer.py:202
Finding

Installer follows symlinks when writing or replacing security-sensitive files

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
93% confidence
Finding

The skill modifies ~/.claude/settings.local.json and installs an executable script under ~/.claude/scripts/, directly affecting the agent's runtime behavior. Any feature that writes to agent configuration directories is high impact because it creates persistence, can alter future command execution, and could be abused to run unintended code every time the status line is rendered.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

md
## How It Works

1. **install** -- Copies `statusline.py` to `~/.claude/scripts/`, creates config at `~/.claude/statusline.config` (perms 600), updates `~/.claude/settings.local.json` with `python3 ~/.claude/scripts/statusline.py` command.

2. **status** -- JSON output: script installed, config state, settings configured, git availability.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

This subprocess explicitly copies all current environment variables into the git child process. In a statusline skill that may execute within sensitive developer or agent sessions, this increases the chance that secrets in the environment become accessible to child-process chains, external helpers, or repository-influenced git behaviors.

Content

Scanner excerpt · scripts/statusline.py (reported line 154)May include surrounding context.

python
result = subprocess.run(
            ["git", "-C", cwd, "symbolic-ref", "--short", "HEAD"],
            capture_output=True, text=True, timeout=5,
            env={**os.environ, "GIT_TERMINAL_PROMPT": "0"},
        )
        if result.returncode == 0:
            return _sanitize(result.stdout.strip(), 128)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

As with the other git calls, the full environment is inherited by the subprocess even though the command only needs limited runtime context. In the skill context this is more dangerous because the script is intended to run automatically and repeatedly, potentially inside repositories or sessions controlled by untrusted projects while secrets are present in environment variables.

Content

Scanner excerpt · scripts/statusline.py (reported line 162)May include surrounding context.

python
result = subprocess.run(
            ["git", "-C", cwd, "rev-parse", "--short", "HEAD"],
            capture_output=True, text=True, timeout=5,
            env={**os.environ, "GIT_TERMINAL_PROMPT": "0"},
        )
        if result.returncode == 0:
            return _sanitize(result.stdout.strip(), 128)

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
89% confidence
Finding

The code forwards the entire parent environment into a child git process via os.environ. In an agent context, environment variables commonly contain API keys, tokens, proxy settings, and other secrets; passing them wholesale to subprocesses unnecessarily broadens exposure to git hooks, helper programs, credential helpers, or misconfigured tooling invoked under git.

Content

Scanner excerpt · scripts/statusline.py (reported line 173)May include surrounding context.

python
def get_git_ahead_behind(cwd):
    """Get ahead/behind counts vs upstream. Returns e.g. '↑2↓1', '↑3', '↓1', or ''."""
    git_env = {**os.environ, "GIT_TERMINAL_PROMPT": "0"}
    try:
        # Check upstream exists
        check = subprocess.run(

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill describes file reads/writes, environment access, and shell execution but does not declare any explicit tool scope or permission boundaries. That makes the automation less auditable and easier to invoke with broader-than-necessary capabilities, increasing the chance of unintended filesystem or command execution during installation and configuration.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger list includes broad, natural phrases like 'install status bar', 'show token usage', and generic customization requests, which could cause the skill to activate when a user intended a different task. Because this skill performs installation and configuration steps that modify local agent settings, accidental invocation can lead to unintended persistent changes.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/statusline.py (reported line 151)May include surrounding context.

python
def get_git_branch(cwd):
    """Get current git branch or short hash. Returns str or empty string."""
    try:
        result = subprocess.run(
            ["git", "-C", cwd, "symbolic-ref", "--short", "HEAD"],
            capture_output=True, text=True, timeout=5,
            env={**os.environ, "GIT_TERMINAL_PROMPT": "0"},

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/statusline.py (reported line 159)May include surrounding context.

python
if result.returncode == 0:
            return _sanitize(result.stdout.strip(), 128)
        # Detached HEAD -- try short hash
        result = subprocess.run(
            ["git", "-C", cwd, "rev-parse", "--short", "HEAD"],
            capture_output=True, text=True, timeout=5,
            env={**os.environ, "GIT_TERMINAL_PROMPT": "0"},

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/statusline.py (reported line 176)May include surrounding context.

python
git_env = {**os.environ, "GIT_TERMINAL_PROMPT": "0"}
    try:
        # Check upstream exists
        check = subprocess.run(
            ["git", "-C", cwd, "rev-parse", "--abbrev-ref", "@{u}"],
            capture_output=True, text=True, timeout=5, env=git_env,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/statusline.py (reported line 183)May include surrounding context.

python
if check.returncode != 0:
            return ""

        ahead_result = subprocess.run(
            ["git", "-C", cwd, "rev-list", "HEAD...@{u}", "--left-only", "--count"],
            capture_output=True, text=True, timeout=5, env=git_env,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/statusline.py (reported line 187)May include surrounding context.

python
["git", "-C", cwd, "rev-list", "HEAD...@{u}", "--left-only", "--count"],
            capture_output=True, text=True, timeout=5, env=git_env,
        )
        behind_result = subprocess.run(
            ["git", "-C", cwd, "rev-list", "HEAD...@{u}", "--right-only", "--count"],
            capture_output=True, text=True, timeout=5, env=git_env,
        )

Static analysis

No suspicious patterns detected.