T09 · Insecure Skill Coding Practices
- Location
SKILL.md:10- Finding
Shell Command Injection Through User-Controlled Knowledge-Gap Text
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent purpose, but it asks the agent to run a shell command using user question text and store a persistent knowledge-gap log without enough safeguards.
Review before installing. This skill should only be used if the logger is present and audited, the agent invokes it without shell interpolation, and users understand that unanswered questions may be stored for later review. Add consent, redaction, retention limits, and safer structured logging before broad use.
SKILL.md:10Shell Command Injection Through User-Controlled Knowledge-Gap Text
The trigger condition is broad: any time Hans 'cannot answer' or says phrases like 'I don't know,' the skill instructs the agent to execute a logging command. Ambiguous activation increases the chance the skill runs in unintended contexts, causing unnecessary command execution and logging of user content that may be sensitive or unrelated to a true knowledge-gap event.
The skill mandates a fixed German-language response regardless of the user's language or preferences. While not a direct security exploit, it can mislead users, reduce transparency, and create unsafe UX behavior by forcing a canned confirmation message after an external action without ensuring language appropriateness or informed consent.
No suspicious patterns detected.