Back to skill

Security audit

File Organizer

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local file organizer, but it needs Review because it can permanently move or delete user files and its safety controls are incomplete.

Install only if you are comfortable giving the skill local file-management authority. Use it on a small, explicitly chosen folder, keep backups, review the move plan carefully, and avoid the automatic duplicate-delete option unless the script is fixed to use safer hashing, byte comparison, and trash or quarantine instead of permanent deletion.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check_duplicates.py:17
Finding

Collision-Unsafe Duplicate Detection Can Delete Distinct Files

Content
View full analysis
1 } ``` ```python for md5, files in data['duplicates'].items(): sorted_files = sorted(files, key=lambda x: x['mtime']) for file_info in sorted_files[1:]: filepath = Path(target_dir) / file_info['path'] if not dry_run: try: filepath.unlink() deleted_count += 1 freed_space += file_info['size'] except OSError as e: print(f"Warning: unable to delete {filepath}: {e}", file=sys.stderr) ``` ### Technical Analysis The duplicate detector treats matching MD5 digests as conclusive proof that files have identical contents. MD5 is collision-broken: two different byte sequences can be deliberately constructed to produce the same digest. The implementation does not perform a secondary verification based on file size, a collision-resistant digest, or byte-for-byte comparison before calling `Path.unlink()`. Consequently, distinct files with a colliding MD5 value are placed in the same duplicate group, and all but the file with the earliest modification timestamp are permanently deleted when deletion mode is approved. User confirmation reduces accidental activation but does not make the duplicate classification trustworthy. The report explicitly labels colliding files as du ...[truncated 1172 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:94
Finding

Unsafe Filename Enumeration Can Corrupt or Inject Generated Shell Operations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/check_duplicates.py:173
Finding

Undefined Reporting Variable Causes Failure After Destructive Deletion

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill claims to safely analyze files, generate a classification plan, and wait for user confirmation before acting, but the documented behavior does not actually provide a trustworthy implementation of those safeguards. In a file-management context, mismatches between declared and real behavior are dangerous because they can lead to unintended file moves or deletion-capable actions, especially since duplicate handling includes a destructive delete path.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The script reads arbitrary files across a target directory to compute hashes, but the skill metadata does not declare a corresponding file-read capability. In an agent setting, undeclared filesystem access weakens permission boundaries and can expose sensitive local data if the skill is invoked on broad directories such as Downloads or user home paths.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Although the tool is presented as a duplicate checker/reporter, it also contains a destructive deletion path activated by command-line flags. This mismatch is dangerous because users or higher-level agents may trust it as read-only and invoke it in automation, leading to unintended irreversible data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill description is written entirely in Chinese and does not indicate that users may choose another language or locale. Under the stated policy, forcing a specific language without opt-in is a natural-language policy violation unless the constraint is documented and justified.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 20)May include surrounding context.

将此技能放置在以下位置之一:

text
~/.claude/skills/file-organizer/SKILL.md

或项目本地:

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 26)May include surrounding context.

将此技能放置在以下位置之一:

text
~/.claude/skills/file-organizer/SKILL.md

或项目本地:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest description and the rest of the skill are written entirely in Chinese, with no indication that the user may choose another language or locale. This can amount to a language-policy violation if the organization requires language choice rather than implicit enforcement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough to match many ordinary requests about files, downloads, or cleaning folders, which can cause the skill to activate in situations where the user did not clearly request bulk file reorganization. In a skill that can create directories, move files, and potentially delete duplicates, over-broad activation increases the chance of unintended destructive operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function comment says it keeps the earliest created file, but the implementation sorts by modification time and preserves the oldest mtime instead. That discrepancy can cause the wrong file to be retained, which matters when metadata or content history differs and can result in unintended loss of the preferred original copy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The destructive mode executes deletions based solely on flags, without any interactive confirmation or explicit pre-deletion warning at the point of action. In an agent or scripted environment, this makes accidental invocation far more likely and can rapidly remove large numbers of files without a final human checkpoint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The title and all guidance in this file are written exclusively in Chinese, and line L118 further constrains naming to Chinese or English without any user opt-in or language-selection instruction. For a general reference skill, this can be interpreted as a locale/language policy issue because it presents a single-language experience by default rather than offering choice.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

All user-facing natural-language strings, including the module description, usage text, warnings, and report output, are hard-coded in Chinese. The file does not offer a language choice or document that the tool is intentionally limited to a Chinese-speaking context, which creates a locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.