Back to skill

Security audit

Paste Rs

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says by uploading user-provided text to paste.rs, but its default local file persistence in shared /tmp uses unsafe predictable filenames and leaves pasted content behind.

Install only if you are comfortable sending pasted content to a public third-party service and leaving a local .md copy behind. Review and redact snippets before use, avoid uploading secrets or whole private files, prefer a private output directory, and treat --no-redact as unsafe for logs or configs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/paste_rs.py:69
Finding

Predictable and Symlink-Unsafe Temporary File Creation

Content
View full analysis

Vulnerability Details

File Location: scripts/paste_rs.py, lines 69–73 and 80–88
Vulnerability Type: Unsafe temporary file handling
Risk Level: Medium

Vulnerable Code

python
def _write_markdown_file(text: str, out_dir: Path) -> Path:
    out_dir.mkdir(parents=True, exist_ok=True)
    ts = datetime.now(timezone.utc).strftime("%Y%m%d-%H%M%S")
    path = out_dir / f"paste-rs-{ts}.md"
    path.write_text(text, encoding="utf-8", errors="replace")
    return path


def upload(text: str, timeout: int = 30, out_dir: str | None = None) -> tuple[str, Path]:
    """Write to a local .md file first, then upload its contents to paste.rs.

    Returns: (url, saved_path)
    """
    if not text:
        raise ValueError("Refusing to upload empty content")

    saved_path = _write_markdown_file(text, Path(out_dir or "/tmp"))

The command-line configuration also establishes /tmp as the default destination:

python
p.add_argument(
    "--outdir",
    default="/tmp",
    help="Directory to save the .md file before uploading (default: /tmp)",
)

Technical Analysis

The script creates a file in the shared /tmp directory using a name derived only from the current UTC timestamp with one-second precision. The resulting path is predictable, and concurrent executions during the same second use the same filename.

Path.write_text() opens the selected path for writing without requesting exclusive creation and follows an existing symbolic link. A local attacker with access to the shared temporary directory can therefore pre-create the predicted path as a symbolic link. When a more privileged or different user invokes the Skill, the script may follow that link and truncate or overwrite a target file that the invoking user is authorized to modify.

The implementation also leaves the local copy on disk after uploading. Its permissions depend on the process umask rather than an explicit restrictive mode, potentially allowing unintended local disclos ...[truncated 2057 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace timestamp-based creation with tempfile.NamedTemporaryFile() or tempfile.mkstemp() so the file has a cryptographically unpredictable name and is created atomically with exclusive semantics.
  2. Create temporary files with mode 0600, independent of the caller's umask.
  3. Prefer a private per-user temporary directory rather than writing directly into shared /tmp.
  4. Do not reopen the temporary file by pathname for upload. Write and read through the securely created file descriptor where practical.
  5. Delete the temporary file in a finally block after the upload unless the user explicitly requests retention.
  6. If persistent output is required, add an explicit option such as --keep, use exclusive creation, and fail safely if the destination already exists.
  7. Validate user-selected output directories and reject symbolic-link destinations where applicable.
  8. Handle simultaneous invocations without collisions.

A secure implementation can use the following pattern:

python
import os
import tempfile
from pathlib import Path

def _write_markdown_file(text: str, out_dir: Path) -> Path:
    out_dir.mkdir(parents=True, exist_ok=True)

    fd, raw_path = tempfile.mkstemp(
        prefix="paste-rs-",
        suffix=".md",
        dir=out_dir,
        text=True,
    )

    try:
        os.fchmod(fd, 0o600)
        with os.fdopen(fd, "w", encoding="utf-8", errors="replace") as f:
            f.write(text)
        return Path(raw_path)
    except Exception:
        os.close(fd)
        Path(raw_path).unlink(missing_ok=True)
        raise

The upload flow should additionally remove the file after use unless local retention was explicitly requested.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents capabilities that read files, write local files, and send data over the network, but it does not declare any tool scope or permissions boundaries. That omission can cause an agent or reviewer to underestimate the skill’s access and increases the chance that sensitive local content is uploaded without explicit authorization controls.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The skill explicitly instructs users to POST stdin or file contents to an external paste service, which is a real data exfiltration path. In this skill’s context, external transmission is core functionality, which makes the behavior expected, but also more dangerous because users may paste logs, configs, or command output that contain secrets or internal data and the service is described as public.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

bash
# stdin
some_command | curl -fsS https://paste.rs -d @-

# file
curl -fsS https://paste.rs -d @./file.txt

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The example command performs real external transmission by sending stdin or a local file to https://paste.rs. While this matches the intended function of the skill, it is still security-relevant because it can exfiltrate sensitive data if users follow the example with logs, configs, or other files that contain secrets.

Content

Scanner excerpt · references/paste-rs-api.md (reported line 11)May include surrounding context.

bash
# stdin
printf 'hello\n' | curl -fsS https://paste.rs -d @-

# file
curl -fsS https://paste.rs -d @README.md

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation shows direct upload of stdin and local files to a public paste service without any warning that the contents leave the local environment and become externally accessible by URL. In a skill specifically designed to upload snippets and logs, this omission increases the risk that users paste secrets, credentials, tokens, internal configs, or sensitive command output unintentionally.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tool advertises itself as pasting content to paste.rs, but it also persists the full content locally in a Markdown file under /tmp or a user-specified directory before upload. For a skill intended to share logs/config snippets, this creates an additional unintended data exposure surface: sensitive material may remain on disk, be readable by other local users or processes depending on filesystem permissions, and survive longer than the user expects even if remote redaction/upload is the primary goal.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Lines L43-L44 switch to Indonesian for important safety guidance about automatic redaction and the unsafe --no-redact option. This can violate language/locale expectations because users reading the English skill file may miss or misunderstand critical instructions, and no opt-in or language alternative is provided.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The top-level documentation describes the tool as uploading text and returning a URL, but omits that it first stores a local copy. This documentation mismatch is security-relevant because users may choose this skill specifically to share sensitive snippets safely, and incomplete disclosure can cause them to expose data locally without informed consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.