Back to skill

Security audit

Email Template

Security checks for vulnerabilities and agentic risk

Overview

The advertised email-template generator is mostly coherent, but the package also includes an unrelated prompt-assistant script that can persist user inputs locally without clear disclosure.

Review this skill before installing. The email template generator itself appears local and non-destructive, but the package also contains an unrelated prompt-assistant CLI that writes command input history under the user's local data directory. Avoid passing confidential prompts, customer data, or business details to the email-template command unless the publisher removes or documents that logging behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:35
Finding

Undisclosed Persistent Plaintext Logging of User-Supplied Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:5-7, scripts/script.sh:35, and scripts/script.sh:37-60, 73-94
Vulnerability Type: Persistent storage of potentially sensitive user input in plaintext
Risk Level: Medium

Complete Vulnerable Code

bash
DATA_DIR="${EMAIL_TEMPLATE_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/email-template}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

User-controlled command arguments are passed to this logging function:

bash
cmd_prompt() {
    echo "  Role: $1
      Task: ${2:-assist}
      Format: ${3:-text}"
    _log "prompt" "${1:-}"
}

cmd_system() {
    echo "  You are an expert $1. Be precise, helpful, and concise."
    _log "system" "${1:-}"
}

cmd_chain() {
    echo "  Step 1: Understand | Step 2: Plan | Step 3: Execute | Step 4: Verify"
    _log "chain" "${1:-}"
}

cmd_template() {
    echo "  1. Zero-shot | 2. Few-shot | 3. Chain-of-thought | 4. Role-play"
    _log "template" "${1:-}"
}

cmd_compare() {
    echo "  GPT-4 vs Claude vs Gemini: benchmark comparison"
    _log "compare" "${1:-}"
}
bash
cmd_optimize() {
    echo "  Tips: Be specific | Add examples | Set format | Constrain length"
    _log "optimize" "${1:-}"
}

cmd_evaluate() {
    echo "  Check: accuracy | relevance | completeness | tone"
    _log "evaluate" "${1:-}"
}

cmd_safety() {
    echo "  1. No harmful content | 2. No personal data | 3. Cite sources"
    _log "safety" "${1:-}"
}

cmd_tools() {
    echo "  ChatGPT | Claude | Gemini | Perplexity | Midjourney"
    _log "tools" "${1:-}"
}

Technical Analysis

The _log function persistently appends command arguments to history.log without redaction, encryption, retention controls, or explicit user consent. Inputs supplied to commands such as `prompt ...[truncated 2039 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove argument-content logging unless it is strictly required.
  2. Make logging explicitly opt-in and document exactly what data is retained, where it is stored, and how users can delete it.
  3. Log only non-sensitive event metadata, such as command type and timestamp; do not record raw prompt or system-role content.
  4. If content must be retained, apply field-level redaction, a defined retention period, and appropriate encryption.
  5. Create the data directory and log file with restrictive permissions, such as directory mode 0700 and file mode 0600.
  6. Validate redirected storage paths and refuse symbolic-link log targets. Open the log using a mechanism that prevents symbolic-link traversal where the platform supports it.
  7. Add tests confirming that sensitive command arguments never appear in persistent files by default.
  8. Align scripts/script.sh with the declared email-template functionality or remove the unrelated prompt-engineering CLI to reduce undocumented behavior and attack surface.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

A description-behavior mismatch is security-relevant because users may invoke the skill expecting only harmless email-template generation while hidden or undocumented functions perform additional actions such as logging, model comparison, or prompt-cost processing. This undermines informed consent and can conceal data handling or side effects that broaden the attack surface beyond the declared purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script's behavior and help text implement a generic AI/prompt-engineering assistant rather than the declared email-template library. This capability mismatch is dangerous because it misleads users and reviewers about what the skill does, increasing the chance of unintended use, hidden data handling, or policy bypass under a trusted label.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The FAQ states the tool is suitable for '任何需要email-template的人,无论是个人还是企业用户,' which is an extremely broad applicability statement without boundaries or exclusions. In a markdown skill description, this can contribute to ambiguous invocation scope because it does not clarify when the skill should or should not be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This shell skill presents its interface and outputs in a mixed Chinese/English format, including command descriptions in Chinese and template content alternating between English and Chinese. Because the file does not state that it is region-specific or provide any language/locale opt-in, it forces a language choice pattern that may violate organizational language policy.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The inline documentation explicitly describes the tool as an 'AI and prompt engineering assistant,' contradicting the advertised email-template purpose. In skill ecosystems, deceptive or inconsistent documentation is a security concern because it obscures operator intent and makes risky behavior harder for users and auditors to detect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The logging helper writes command arguments directly to a persistent history file without notice, and those arguments may contain sensitive prompts, personal data, or business content. Silent retention creates a privacy and security risk because users may unknowingly disclose confidential information to disk where other local processes or users could later access it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The description is presented in both Chinese and English, but the skill does not state how it chooses the response language or whether the user can opt in to a preferred language. This may violate language/locale policy expectations when a skill implicitly forces or defaults to a language behavior without user choice.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The script creates a persistent data directory and log storage in the user's home data path without clearly informing the user. While common in CLI tools, undisclosed persistence is still a security and privacy concern in this context because the tool also records command activity, making retained local artifacts more sensitive.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.