Back to skill

Security audit

context-map

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate project-scanning purpose, but its documented command can execute Python code from the project being scanned, which makes it unsafe for untrusted repositories.

Use this skill only on repositories you trust or after changing the scanner invocation to use a fixed, verified scanner path outside the target project. Review or disable `.codesight/` file generation if you want read-only analysis, and avoid broad automatic activation until the triggers and execution path are narrowed.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:53
Finding

Untrusted Python Module Execution Through Attacker-Controlled PYTHONPATH

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 53–57
Vulnerability Type: Untrusted local tool/module hijacking
Risk Level: High

bash
PYTHONPATH="$(find . -path '*/conserve/scripts' -type d \
  -print -quit 2>/dev/null || \
  echo 'plugins/conserve/scripts')" \
  python3 -m context_scanner .

Technical Analysis

The documented procedure searches the project being inspected for the first directory matching */conserve/scripts, places that directory in PYTHONPATH, and then executes the context_scanner module with python3 -m.

Because the scanned project is untrusted input, an attacker can add a directory such as conserve/scripts containing a malicious context_scanner.py module. Python will resolve and execute that attacker-controlled module under the privileges of the user or agent running the skill. The discovered path is neither restricted to a trusted plugin installation nor authenticated before execution.

This converts what appears to be a project-analysis operation into an arbitrary local code-execution primitive.

Attack Path

  1. An attacker adds conserve/scripts/context_scanner.py to a repository.
  2. A user or agent opens that repository and invokes the context-map skill.
  3. The find command discovers the attacker-controlled conserve/scripts directory.
  4. The command prepends that directory to PYTHONPATH.
  5. python3 -m context_scanner . imports and executes the malicious module.
  6. The module runs with the invoking user's permissions and can access any resources available to that process.

Impact Assessment

Successful exploitation provides arbitrary code execution with the privileges of the user or agent invoking the skill. Depending on the execution environment, an attacker could:

  • Read source code, configuration files, credentials, and environment variables accessible to the process.
  • Modify or delete workspace files.
  • Tamper with generated analysis results.
  • Execute additional local ...[truncated 310 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not derive executable module paths from the untrusted project being scanned.
  • Resolve context_scanner from a fixed, absolute installation path outside the target repository.
  • Invoke a trusted scanner using an absolute script or executable path, and pass the project root only as a data argument.
  • Validate that the trusted scanner path is owned by an expected user or package and is not writable by the scanned project.
  • Pin and verify the scanner package or artifact using an approved package source and integrity checks.
  • Sanitize inherited Python import settings such as PYTHONPATH and consider isolated mode where compatible.
  • Run project scanning in a sandbox with minimal filesystem permissions, no unnecessary credentials, and restricted network access.
  • Fail safely when the trusted scanner is unavailable instead of falling back to a path inside the target project.

A safer invocation pattern is conceptually:

bash
env -u PYTHONPATH python3 -I /absolute/trusted/path/context_scanner.py .

The exact command should use the verified installation location appropriate to the deployment environment.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger list contains generic terms like context, scanning, and exploration, which are likely to match many normal conversations and auto-activate the skill outside the user's specific intent. In a skill that can invoke project-wide scanning and write files, over-broad activation increases the chance of unintended execution, unnecessary repository exposure, and surprise side effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill is presented as a context-generation utility, but its documented default behavior includes writing per-topic wiki artifacts to .codesight/. Undisclosed or under-emphasized filesystem writes are security-relevant because they can modify the repository state, create unreviewed artifacts, and affect later tooling or commits in ways the user may not expect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation describes generating wiki articles under .codesight/ but does not prominently warn that using the skill may modify the filesystem. Silent or poorly disclosed writes are dangerous in agent workflows because they can pollute the workspace, introduce files that are later committed, and violate user expectations around read-only analysis.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The procedural documentation describes a straightforward flow where scanner output is presented to the user, suggesting direct stdout-based reporting. Later, the documented --wiki-only mode indicates an alternate behavior that generates articles without stdout, contradicting the earlier stated execution model for how output is delivered.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.