Back to skill

Security audit

Logfmt

Security checks for vulnerabilities and agentic risk

Overview

LogFMT is a small local log-colorizing tool with no network access or persistence, though users should be aware it prints raw log control characters to the terminal.

Install only if you want a simple local log highlighter. Avoid using it for hostile or attacker-controlled logs unless terminal escape sanitization is added, and invoke the packaged script name rather than relying on the README examples as written.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
tool.py:41
Finding

Terminal Escape-Sequence Injection Through Untrusted Log Content

Content
View full analysis

Vulnerability Details

File Location: tool.py, lines 41–49 and 86
Vulnerability Type: Improper neutralization of terminal control sequences
Risk Level: Medium

Vulnerable Code

python
def format_line(line: str) -> str:
    # Colorize timestamps
    for pattern in TIMESTAMP_PATTERNS:
        line = pattern.sub(colorize_timestamp, line)
    
    # Colorize log levels
    line = LEVEL_PATTERN.sub(colorize_level, line)
    
    return line
python
formatted = format_line(line.rstrip('\n'))
print(formatted)

Technical Analysis

The program treats log lines as untrusted input but writes them directly to the terminal after only applying regular-expression substitutions for timestamps and log levels. It does not remove, encode, or otherwise neutralize preexisting terminal control characters.

Consequently, ANSI CSI sequences, OSC sequences, and other terminal control codes embedded in a malicious log entry remain intact and are interpreted by the user's terminal. The highlighting codes intentionally added by the application do not protect against attacker-supplied control sequences.

Attack Path

  1. An attacker causes an application or service to record a crafted string containing terminal escape sequences.
  2. The crafted content is stored in a log file or reaches a log stream processed by this tool.
  3. A user opens or follows that log using tool.py.
  4. format_line() preserves the attacker's escape sequences.
  5. print(formatted) sends those sequences to the terminal.
  6. The terminal interprets them, potentially rewriting displayed content, hiding security-relevant log entries, altering terminal state, or activating terminal-specific OSC features.

Impact Assessment

Exploitation occurs with the privileges and capabilities of the terminal emulator used by the person reviewing the log. It does not directly grant shell execution or elevated operating-system privileges in the audited code.

A successful attack can falsify ...[truncated 290 chars]

Remediation
View remediation

Remediation Suggestions

Sanitize every untrusted log line before adding application-controlled highlighting:

  1. Remove or visibly encode ANSI CSI, OSC, DCS, APC, PM, and related escape sequences.
  2. Remove or escape unsafe C0 and C1 control characters while explicitly allowing only required formatting characters, such as tabs.
  3. Apply trusted color highlighting only after sanitization.
  4. Consider rendering control characters in a visible form, such as \x1b, so analysts can inspect malicious content safely.
  5. If raw terminal controls are required, expose them only through an explicit, clearly documented opt-in option.
  6. Add regression tests using CSI cursor movement, screen-clearing sequences, OSC title changes, OSC clipboard payloads, carriage returns, backspaces, and malformed or truncated escape sequences.
  7. Prefer a well-tested terminal-sanitization implementation rather than an incomplete regular expression that handles only a subset of escape syntax.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.