Back to skill

Security audit

Algernon Feynman

Security checks for vulnerabilities and agentic risk

Overview

This study skill is mostly purpose-aligned, but it needs review because it uses unsafe database and shell command patterns and can save or export study summaries without clear per-run consent.

Review this skill before installing. It appears intended for legitimate OpenAlgernon study sessions, but use it only with trusted material names and card content, and prefer an implementation that validates slugs, uses parameterized SQLite queries, writes summaries safely, and asks before sending anything to Notion or saving learning-history notes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:33
Finding

SQL Injection Through Unvalidated Material Slug Substitution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 33-46
Vulnerability Type: SQL injection
Risk Level: High

Vulnerable Code

bash
sqlite3 "$DB" \
  "SELECT c.id, c.front, c.back, c.tags
   FROM cards c
   JOIN decks d ON d.id = c.deck_id
   JOIN materials m ON m.id = d.material_id
   WHERE m.slug = 'SLUG'
   ORDER BY
     CASE WHEN c.tags LIKE '%N3%' THEN 1
          WHEN c.tags LIKE '%N2%' THEN 2
          ELSE 3 END,
     RANDOM()
   LIMIT 5;"

Technical Analysis

The Skill instructs the agent to replace SLUG inside a quoted SQL statement. The material slug originates from the user's invocation, but the documented query does not use parameter binding or require validation of that value.

If the agent performs direct textual substitution, a slug containing a single quote can terminate the intended SQL string. Additional SQL syntax may then alter the selection criteria or introduce additional statements supported by the SQLite command-line interface.

For example, a malicious value could close the string literal, append attacker-selected SQL, and comment out the remainder of the original query. The exact payload depends on how the agent constructs and submits the command, but the vulnerable trust boundary is the direct placement of user-controlled data into SQL source.

Attack Path

  1. An attacker invokes the Skill with a crafted material slug containing SQL metacharacters.
  2. The agent replaces the SLUG placeholder directly in WHERE m.slug = 'SLUG'.
  3. The injected quote terminates the intended SQL literal.
  4. Attacker-provided SQL changes the query or adds another SQLite statement.
  5. The sqlite3 process executes the resulting SQL with the invoking user's access to the study database.
  6. The attacker may disclose, modify, or delete records in study.db, subject to database and filesystem permissions.

Impact Assessment

Successful exploitation coul ...[truncated 483 chars]

Remediation
View remediation

Remediation Suggestions

  • Store the requested slug in a separate value rather than substituting it into SQL source.
  • Use SQLite parameter binding, such as a named @slug parameter with WHERE m.slug = @slug.
  • Validate slugs against a strict allowlist before database access. If the intended slug format permits only letters, digits, underscores, and hyphens, enforce ^[A-Za-z0-9_-]+$.
  • Reject values containing quotes, SQL comments, statement separators, control characters, or characters outside the documented slug format.
  • Open the database in read-only mode for this operation where feasible, limiting the impact of any query-construction error.
  • Avoid asking an agent to construct executable SQL through placeholder replacement. Prefer a fixed helper script or structured database API that binds parameters automatically.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:94
Finding

Potential Shell Command Injection Through Dynamic Summary and Markdown Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 94-109
Vulnerability Type: Shell command injection through unsafe interpolation
Risk Level: High

Vulnerable Code

bash
### Save to Notion (optional)

If `$NOTION_CLI` is available and `$NOTION_PAGE_ID` is set:

```bash
"$NOTION_CLI" append --page-id "$NOTION_PAGE_ID" --content "MARKDOWN"

Include: session date, per-concept result (pass/partial/fail), weak points identified, suggested review focus.

Save Memory

bash
echo "[HH:MM] feynman session -- MATERIAL_NAME | Concepts: N | Passed: X | Needs work: LIST" \
  >> "${ALGERNON_HOME}/memory/conversations/YYYY-MM-DD.md"
text

### Technical Analysis

The documented commands contain placeholders for generated Markdown, the material name, and the list of concepts needing review. Those values can be derived from user input or database content. The instructions do not define a safe serialization mechanism and visually place the placeholders inside shell command literals.

If an implementation replaces these placeholders directly in the command source, double quotes alone do not provide a safe boundary. Shell constructs such as command substitution remain active inside double-quoted strings, and injected quote characters can terminate the quoted argument and introduce additional shell syntax.

This issue applies both to the optional Notion command and the local memory command. Exploitation depends on the agent constructing shell source through textual placeholder replacement rather than passing already separated argument values to a process API.

### Attack Path

1. An attacker supplies a crafted material name, concept, weak-point description, or other content that reaches `MARKDOWN`, `MATERIAL_NAME`, or `LIST`.
2. The crafted value contains shell syntax, such as a closing quote followed by a command, or command-substitution syntax.
3. The agent directly replaces the placeholder 
...[truncated 877 chars]
Remediation
View remediation

Remediation Suggestions

  • Never replace dynamic placeholders directly inside shell source.
  • Invoke external programs through a structured process API that supplies each argument separately without shell evaluation.
  • Store generated Notion content in a safely created file and use a supported file-input option, if available.
  • If a shell is unavoidable, assign data through a non-evaluating channel and preserve it as a quoted variable. Do not use eval, command-string concatenation, or generated scripts.
  • Use printf '%s\n' "$summary" rather than embedding dynamic data in an echo command literal.
  • Validate NOTION_PAGE_ID according to the identifier format accepted by the Notion client.
  • Treat material names, card contents, weak-point descriptions, and generated Markdown as untrusted data.
  • Create the destination memory directory explicitly with restrictive permissions before writing, and verify that the destination is not an attacker-controlled symbolic link.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrases are broad enough that the skill may activate from casual language like 'feynman' or 'me testa explicando' without strong scope checks. That can cause unintended access to study materials and launch a workflow that reads from the local study database, which is risky even if the skill is not overtly malicious.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill can send session content, weak points, and review notes to Notion when environment variables are set, but it does so without explicit user consent or a visible warning. This creates an external data exfiltration path for potentially sensitive educational content and self-assessment information to a third-party service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill persists session summaries to a local memory file containing study activity, timestamps, material names, and concepts needing work, but the description does not warn the user that this data will be stored. Silent retention of learning history can expose sensitive interests or performance information to other local processes or users with filesystem access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.