Back to skill

Security audit

edo-tensei

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent and disclosed, but its ZIP import script can write outside the chosen workspace if a crafted migration package is imported.

Install only if you are comfortable reviewing the code or waiting for a fixed importer. Do not import ZIP packages from other people or untrusted workspaces until path traversal and pre-write verification are fixed; exported handoff packages may also contain sensitive project files or private links, so inspect them before sharing.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/import_package.py:223
Finding

Untrusted Migration Package Allows Arbitrary File Writes Through Path Traversal

Content
View full analysis

Vulnerability Details

File Location: scripts/import_package.py, lines 223–319
Vulnerability Type: ZIP archive path traversal leading to arbitrary file writes
Risk Level: High

Technical Analysis

The documented import workflow accepts migration ZIP files that may originate from another workspace, device, or package provider. Both the ZIP member names and the package's PROVENANCE.json are therefore package-controlled inputs.

The default namespace is derived from the untrusted source_node field without restricting path separators or traversal components:

python
with zipfile.ZipFile(args.package, "r") as z:
    raw = z.read("PROVENANCE.json").decode("utf-8", "ignore")
prov = json.loads(raw)
source_node = prov.get("source_node", "")
first_code = source_node.split(",")[0].strip() or "R0"

# ...

prefix = args.namespace or ("B-" + first_code)

# ...

ns_dir = os.path.join(ws, prefix)
os.makedirs(ns_dir, exist_ok=True)

More critically, landed_of() validates absolute paths and .. components only in its fallback branch. Entries beginning with handoffs/ or artifacts/ are joined directly to destination directories without containment validation:

python
def landed_of(rel: str):
    rel = rel.replace("\\", "/")
    if rel == "INDEX.excerpt.md":
        return os.path.join(ns_dir, "INDEX.excerpt.md")
    if rel.startswith("handoffs/"):
        base = rel[len("handoffs/"):]
        return os.path.join(ho_dir, f"{prefix}_{base}")
    if rel.startswith("artifacts/"):
        rest = rel[len("artifacts/"):]
        return os.path.join(ns_dir, "artifacts", rest)
    # Other files, such as top-level CONTEXT_DIGEST.md, are placed at
    # the namespace root.
    # Safety guard: reject absolute paths and .. traversal
    if os.path.isabs(rel) or ".." in rel.split("/"):
        return None
    return os.path.join(ns_dir, rel)

Consequently, a member such as:

text
artifacts/../../../../.config/application/config.py

produces a d ...[truncated 4128 chars]

Remediation
View remediation

Remediation Suggestions

  1. Validate every archive member before extraction

    • Convert separators to a canonical form.
    • Reject absolute, drive-qualified, UNC, empty, and NUL-containing paths.
    • Reject any . or .. path component.
    • Apply these checks uniformly to handoffs/, artifacts/, and all fallback entries.
  2. Enforce destination containment

    • Resolve both the extraction root and candidate destination with realpath.
    • Use os.path.commonpath() to ensure the resolved destination remains under its designated root.
    • Perform containment checks after joining paths, not only against the original member name.
    • Use separate roots for artifacts, handoffs, and namespace-level files.
  3. Constrain namespace values

    • Validate --namespace and PROVENANCE.source_node against a strict allowlist, such as letters, digits, _, and -.
    • Reject path separators, drive delimiters, control characters, . components, and traversal sequences.
    • Do not use package metadata directly as a filesystem path component without validation.
  4. Validate before writing

    • Read and validate the entire member list and manifest before creating any destination files.
    • Require every non-directory content member to appear exactly once in PROVENANCE.files.
    • Reject undeclared members and duplicate or normalized-name collisions.
    • Verify member hashes in a private temporary directory first.
  5. Use transactional extraction

    • Extract into a securely created temporary directory.
    • Complete path validation and hash verification there.
    • Move the validated tree into the workspace atomically.
    • On any failure, remove the temporary tree and leave the destination workspace unchanged.
  6. Fail closed

    • Abort immediately on a missing file, hash mismatch, unsafe path, duplicate member, malformed provenance record, or unsupported entry type.
    • Do not update provenance records or INDEX.md after failed ver ...[truncated 386 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documentation advertises session splitting, import/export orchestration, and DAG management, while the implementation reportedly includes cryptographic key generation, signing/verification, and filesystem freeze/unlock behavior unrelated to those verbs. Security-sensitive admin functionality that is not clearly disclosed increases the chance of misuse, privilege overreach, and operator confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation advertises session splitting, import/export orchestration, and DAG management, while the implementation reportedly includes cryptographic key generation, signing/verification, and filesystem freeze/unlock behavior unrelated to those verbs. Security-sensitive admin functionality that is not clearly disclosed increases the chance of misuse, privilege overreach, and operator confusion.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documentation advertises session splitting, import/export orchestration, and DAG management, while the implementation reportedly includes cryptographic key generation, signing/verification, and filesystem freeze/unlock behavior unrelated to those verbs. Security-sensitive admin functionality that is not clearly disclosed increases the chance of misuse, privilege overreach, and operator confusion.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities that involve filesystem reads/writes and environment-dependent behavior, but it does not declare any explicit tool scope such as allowed-tools or permissions. That creates an authorization ambiguity where a host agent may grant broader-than-necessary access, and users cannot easily audit what the skill is expected to touch.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrase '控制塔' is very broad and likely to appear in ordinary product, planning, or organizational conversations. Overly generic triggers can cause accidental activation of a skill with file and conversation-management capabilities, increasing the risk of unintended data access or writes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill claims primarily local workspace management, but it also instructs use of remote conversation_search and reads a local conversation database for discovery. That expands the data boundary to historical conversation content and metadata, creating privacy and scope-creep risks beyond what a user may expect from a local control-tower tool.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill bundles package-maintenance, signing, verification, and freeze/unlock capabilities that are not necessary for normal end-user control-tower operations. Mixing routine workflow actions with admin-grade integrity tooling broadens the attack surface and may let a compromised or confused invocation perform unintended maintenance operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrases are short, generic, and action-oriented enough that they may activate the skill in unintended contexts, especially because terms like “控制塔” and “会话接管” can plausibly appear in ordinary discussion about session management. Since this skill performs coordination, takeover, export, and import of multi-session workspace state, accidental activation could cause unintended orchestration or data movement decisions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instruction '新会话启动第一句:先读本索引...' is written as a mandatory default workflow in Chinese, and the file overall presents the required operating convention only in Chinese. For a general project template, this creates a locale/language constraint without any stated user choice, opt-in, or justification for limiting use to Chinese-language operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The template explicitly instructs users to summarize and save prior-session context for reuse in new sessions, but it provides no guidance to exclude secrets, personal data, internal-only notes, or access tokens. In a skill designed for cross-session handoff, export, and workspace migration, that omission materially increases the chance that sensitive information is copied into durable markdown files and then propagated across devices or workspaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This section tells users to preserve complete remote URLs across sessions and export them with the handoff package, but does not warn that URLs may contain access tokens, document IDs, tenant identifiers, or links to private resources. Because the skill's purpose is multi-session and cross-workspace transfer, preserving full links without sanitization can leak privileged access paths or sensitive metadata beyond the original context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document promises a self-contained, workspace-local storage model, but later instructs reading a global user-level SQLite database under ~/.workbuddy/workbuddy.db. That mismatch can cause operators to underestimate the skill's true data reach and authorize it in contexts where access to unrelated session metadata should not occur. In a session-management skill, hidden expansion from workspace-local data to global local history materially increases privacy and scope risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation claims operations only read and write within the current workspace, yet later guidance explicitly instructs reading global user-level files such as ~/.workbuddy/workbuddy.db and project-resources. This kind of scope contradiction weakens user trust boundaries and can lead to unauthorized exposure of metadata from other workspaces, projects, or deleted/archived sessions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The design authorizes direct reads of a global local SQLite ledger containing titles, IDs, status, deletion markers, project IDs, and timestamps for sessions beyond the current workspace. That exceeds the minimum privilege needed for ordinary control-tower/session-splitting behavior and creates a sensitive local-enumeration capability that could expose unrelated conversations and project metadata if misused or if workspace filtering is imperfect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document describes reading a sensitive local SQLite session ledger with real conversation IDs, titles, statuses, deletion markers, project IDs, and timestamps, but does not provide strong privacy warnings, minimization requirements, or consent UX. For a collaboration/control-tower skill, this context makes the issue more dangerous because users may expect project-local coordination, not enumeration of broader local conversation history.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The section labeled "ChatGPT / 通用版(精简)" provides the entire operative prompt only in English, including the assistant role and rules, while other platform variants are presented in Chinese. This imposes a language choice on that platform-specific skill variant without any opt-in or alternative locale option, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The export logic intentionally permits copying files outside the declared workspace by mapping them under artifacts/_external, and it does so for both INDEX-listed artifacts and explicit --artifacts input. In a tool designed for packaging and moving conversation/work artifacts across workspaces/devices, this expands the trust boundary and can silently exfiltrate arbitrary local files if session metadata or operator inputs are influenced by untrusted content.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The heuristic collector scans handoff documents for path-like tokens and automatically includes any existing local files it finds, even if they were not explicitly selected by the user. Because handoff text is effectively untrusted content in this skill’s multi-session control-tower model, a crafted or polluted handoff can cause over-collection of sensitive local files and package them for export without clear operator intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/gen_seal.py (reported line 96)May include surrounding context.

python
sys.exit(1)

    # 安全闸(§〇 安全铁律):改写技能包 SEAL 属维护操作,禁止普通动词调用;
    # 目标若在技能包目录下,必须显式 --allow-package-write 才放行。
    _skills = os.path.abspath(os.path.expanduser("~/.workbuddy/skills")).replace("\\", "/").lower()
    _sd = skill_dir.replace("\\", "/").lower()
    if _sd == _skills or _sd.startswith(_skills + "/"):

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code file contains extensive natural-language documentation and runtime messages exclusively in Chinese, including usage, behavior descriptions, errors, and status output. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script extracts and writes all package contents to the target workspace before completing integrity verification. That means a tampered or malicious ZIP can plant files on disk even when later hash checks fail, which defeats the stated trust boundary and creates a time-of-check/time-of-use problem for imported content. In this skill’s context, that is more dangerous because the tool is explicitly designed for cross-workspace/package transfer, so it will often process less-trusted artifacts from other sessions, devices, or environments.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Manifest将该技能描述为多会话上下文控制塔,围绕会话拆分、纳管、导出导入与配置展开;而本文件公开的子命令实际用于生成签名密钥、签署/验证SEAL、以及对目录树施加或解除系统只读属性。这些是技能包供应链/部署维护能力,而不是面向所述会话管理用途的直接实现细节。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This file contains substantial normative text in both Chinese and English, including conditions in L13-L15 that are only stated in Chinese. Under the policy rule for natural-language constraints, this can be a language/locale issue because users are not given a language choice and key obligations are not consistently accessible in one documented locale.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The documentation says users only need to remember five verbs and presents those as the exclusive interface. Later sections instruct users to run additional direct Python scripts for export/import/config as well as package verification, seal generation, signing, freezing, and unlocking, which contradicts the simplified intent of a five-verb-only interface.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The file includes user-facing natural-language metadata in Chinese, such as the skill name, author label, and notes, but does not indicate that the skill is China/Chinese-specific or provide any language alternative. This can violate the language/locale policy criterion because it implicitly forces one language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/export_package.py:52