Back to skill

Security audit

Review Skill

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate review purpose, but its instructions include unsafe caller-controlled shell and file-write patterns that need review before installation.

Install only if the caller or harness controls the arguments. Prefer revising the skill to validate git refs before use, avoid shell-string interpolation, restrict report output to a safe workspace directory, and avoid overwriting existing files without explicit approval.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:25
Finding

Shell Command Injection Through an Unvalidated Base Branch Argument

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:15,25
Vulnerability Type: Shell command injection
Risk Level: High

Vulnerable Code Snippet:

markdown
- `--base <branch>`: Base branch for diff comparison (default: `main`)
bash
git diff --name-only $(git merge-base HEAD <base>)..<HEAD> | grep -E '(SKILL\.md|skills/[^/]+/)'

Technical Analysis

The caller-controlled --base value is inserted unquoted into a shell command and nested command substitution. The workflow does not require validation that the value is a legitimate Git reference or prohibit shell metacharacters and option-like input.

If the agent substitutes a malicious argument verbatim and executes the documented command through a shell, command separators, substitutions, or other shell syntax in the value can alter the intended operation. The nested $(...) expression makes this especially dangerous because injected syntax may be evaluated as part of command construction.

Attack Path

  1. An attacker supplies a crafted value through the documented --base argument.
  2. The agent substitutes that value for <base> in the command at line 25.
  3. The resulting command is passed to a shell without quoting or strict validation.
  4. The shell interprets attacker-provided metacharacters rather than treating the entire value as a Git branch name.
  5. Injected commands execute with the same operating-system privileges and filesystem access as the agent process.

Impact Assessment

Successful exploitation can provide arbitrary command execution within the agent's security context. The attacker could read or modify accessible repository files, overwrite configuration, extract locally available data, manipulate audit results, or invoke other installed tools. The scope is bounded by the operating-system privileges, sandbox restrictions, credentials, and network access available to the agent.

Remediation
View remediation

Remediation Suggestions

  • Validate the supplied base branch before use, such as with git check-ref-format --branch.
  • Reject values containing whitespace, shell metacharacters, control characters, or a leading hyphen.
  • Do not construct commands by interpolating input into a shell string. Invoke Git through an argument-array API so the branch value remains a single literal argument.
  • Resolve and verify the revision separately, then pass the validated revision to git merge-base and git diff.
  • Use appropriate -- option terminators where supported to prevent option injection.
  • Abort safely with a clear error if validation or revision resolution fails.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:59
Finding

Unrestricted Caller-Controlled Output File Write

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:14,18,59
Vulnerability Type: Arbitrary file overwrite
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- `$ARGUMENTS`: Output file path for review results (required, passed by the calling harness or the user)
markdown
Extract the output path from `$ARGUMENTS`. If no path is provided, default to `.review-output.md`.
markdown
Write all findings to the output path specified in Step 1, using the exact format below.

Technical Analysis

The skill instructs the agent to write review results to a path controlled by the caller. It imposes no destination-directory restriction, canonicalization requirement, symlink protection, file-type validation, or overwrite confirmation.

Consequently, absolute paths and traversal paths can target any file writable by the agent. A path that resolves through a symbolic link could also redirect the write to an unintended destination. Although the generated content is Markdown, overwriting configuration, instructions, source files, or user data can still damage integrity or influence later agent behavior.

Attack Path

  1. An attacker invokes the skill with an output argument naming a sensitive writable file, a traversal path, or a symbolic link.
  2. The skill accepts the path without validation.
  3. The review workflow generates its report.
  4. The agent writes the report to the attacker-selected destination.
  5. The existing target is replaced or corrupted if the underlying write operation permits overwriting.

Impact Assessment

Exploitation permits modification of files writable by the agent process. Potential effects include repository corruption, replacement of local configuration or agent instruction files, loss of user data, and manipulation of later workflows that consume the overwritten file. This finding does not independently grant privileges beyond those already held by the ag ...[truncated 59 chars]

Remediation
View remediation

Remediation Suggestions

  • Restrict report output to a dedicated directory within the active workspace.
  • Resolve the requested path to its canonical absolute form and verify that it remains beneath the approved output directory.
  • Reject absolute paths, traversal components, device paths, and destinations outside the workspace.
  • Refuse symbolic-link destinations and validate parent path components to mitigate symlink traversal.
  • Avoid silently replacing existing files; use exclusive creation or require explicit overwrite authorization.
  • Write to a securely created temporary file in the destination directory and use an atomic rename after validation.
  • Apply least-privilege filesystem permissions to the agent process.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
1. Read the full `SKILL.md` (not just diff lines)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill accepts a user- or harness-supplied output path and then writes review results to that path without any explicit safety constraints or warning. While writing an output file is part of the skill's intended function, an attacker or misconfigured caller could direct output to an unintended location, causing overwrite of repository files or other accessible paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.