Back to skill

Security audit

Superpowers Requesting Code Review

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent code-review workflow that shares git changes with a one-time review subagent, with a minor local temporary-file hygiene risk.

Install only if you are comfortable with a review subagent receiving repository diffs and change summaries. Prefer sending the diff directly or using a private mktemp-created directory instead of the documented fixed /tmp/review-diff.patch path, especially for proprietary code.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:36
Finding

Predictable Shared Temporary File Enables Symlink Attacks and Review Data Exposure

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 36
Vulnerability Type: Predictable and insecure temporary file usage
Risk Level: Medium

Vulnerable Code:

bash
git diff BASE_SHA HEAD > /tmp/review-diff.patch

Technical Analysis

The documented workflow writes potentially sensitive source-code changes to the fixed, globally predictable path /tmp/review-diff.patch. Shell output redirection follows an existing symbolic link and truncates its target before writing. A local attacker who can create that path before the command runs could therefore redirect the write to another file writable by the victim account.

The fixed path also creates concurrency and confidentiality risks. Multiple review processes can overwrite or consume one another's patch data. Depending on the invoking process's umask and the resulting file permissions, proprietary source changes may be readable by other local users.

Attack Path

  1. A local attacker predicts that the documented review workflow will use /tmp/review-diff.patch.
  2. Before the workflow runs, the attacker creates that path as a symbolic link to a file writable by the victim account, or places a competing patch file at that location.
  3. The victim executes:
    bash
    git diff BASE_SHA HEAD > /tmp/review-diff.patch
    
  4. The shell follows the symbolic link and truncates or overwrites its target, or overwrites the attacker's competing file.
  5. Alternatively, the attacker reads or modifies the generated patch if local permissions allow it.
  6. The review subagent may subsequently receive attacker-modified review input, while legitimate source changes may be exposed or lost.

Exploitation requires local access to the shared temporary directory and favorable timing or prior placement of the predictable path.

Impact Assessment

The vulnerability does not independently grant additional operating-system privileges. Its impact is limit ...[truncated 618 chars]

Remediation
View remediation

Remediation Suggestions

Replace the predictable shared path with a securely created, private temporary directory or file. Apply restrictive permissions before creating the patch and guarantee cleanup:

bash
umask 077
review_dir="$(mktemp -d)" || exit 1
trap 'rm -rf -- "$review_dir"' EXIT

review_patch="$review_dir/review-diff.patch"
git diff BASE_SHA HEAD > "$review_patch"

Additional hardening measures:

  • Do not use a fixed filename directly under /tmp.
  • Keep every invocation's artifacts in a unique temporary directory.
  • Quote all generated path variables.
  • Ensure temporary artifacts are removed on normal exit and interruption.
  • Avoid running the review workflow with elevated privileges.
  • Pass the diff directly to the review subagent when practical, avoiding filesystem storage entirely.
  • If the patch must persist, store it in a project-controlled directory with explicit owner-only permissions and validate ownership before use.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill's title, instructions, examples, and operational guidance are entirely in Chinese, and the review prompt template also directs interaction in Chinese. There is no indication that the user can opt into another language or that the locale restriction is required for a region-specific purpose, which conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.