T09 · Insecure Skill Coding Practices
- Location
index.js:62- Finding
Caller-Controlled Storage Root Enables Unauthorized Filesystem Writes
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real local security-monitoring skill, but it records broad agent activity continuously and can write monitoring files to caller-chosen locations without enough controls.
Install only if you are comfortable with local, persistent recording of agent prompts, tool activity, skill activity, baselines, and anomaly events. Use it in a private workspace, avoid shared or sensitive directories, review or restrict the input.path behavior, and plan how .security logs will be rotated or deleted.
index.js:62Caller-Controlled Storage Root Enables Unauthorized Filesystem Writes
index.js:20Anomaly Detection Logic Permits False Negatives and Unreachable Severity Classification
The skill explicitly logs every user prompt, tool invocation, and skill result to local files, but it does not provide a clear warning about the collection and retention of potentially sensitive user input and system activity. This creates a privacy and data-handling risk because secrets, personal data, file paths, and operational details may be captured in persistent logs without informed user awareness or minimization.
The skill persistently records behavioral metrics to disk without any notice, consent flow, or documented retention controls. Even though the feature is aligned with anomaly detection, undisclosed telemetry can collect sensitive usage patterns, paths, and session details, creating privacy and surveillance risk if the data is later accessed, misused, or retained too broadly.
Persistent anomaly logs can expose potentially sensitive security events, behavioral deviations, and correlated activity data without the user's awareness. In the context of a monitoring skill, the logging is expected functionally, but silent persistence increases privacy risk and creates a useful intelligence source for anyone who can read the log files.
Writing derived baseline statistics to disk is less sensitive than raw event logging, but it still creates persistent monitoring artifacts without disclosure. Those artifacts can reveal behavioral norms and operational patterns that may be sensitive in some environments, especially if stored in shared workspaces or with weak access controls.
No suspicious patterns detected.