Back to skill

Security audit

Landing

Security checks for vulnerabilities and agentic risk

Overview

This landing-page helper is coherent and disclosed, but users should treat its generated HTML as unsafe for untrusted input unless they add escaping.

Install only if you are comfortable with a small local bash helper. Use trusted title and description input, review generated HTML before publishing it, and add HTML escaping before using it with user-submitted or third-party content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:88
Finding

Unescaped User Input Allows HTML and Script Injection in Generated Pages

Content
View full analysis
" echo ''$2'

'$2'

'$3'

' } ``` ### Technical Analysis The `create` command places the values of `$2` and `$3` directly into HTML element and attribute contexts without HTML encoding or input validation. An attacker can supply HTML closing tags, new elements, event handlers, or `

``` 2. `cmd_create` concatenates the payload directly into the HTML document without contextual encoding. 3. A user or automation process redirects the generated output into an `.html` file. 4. The resulting file is ...[truncated 877 chars]

Remediation
View remediation
`, `"`, and `'`. 2. Use the local variables rather than positional parameters after validation. 3. Keep every shell variable expansion quoted and use `printf` instead of concatenating unquoted values with `echo`. 4. Correct the argument indexing so the handler consumes `$1` as the title and `$2` as the description after dispatch performs `shift`. 5. If rich HTML is intentionally supported, sanitize it with a well-maintained allowlist-based HTML sanitizer rather than accepting arbitrary markup. 6. Add tests covering closing tags, script elements, event-handler attributes, quotes, ampersands, whitespace, wildcard characters, and missing arguments. A safer structure would be: ```bash html_escape() { local value=$1 value=${value//&/&} value=${value///>} value=${value//\"/"} value=${value//\'/'} printf '%s' "$value" } cmd_create() { local title="${1:-}" local description="${2:-}" [ -n "$title" ] && [ -n "$description" ] || die "Usage: $SCRIPT_NAME create <description>" local safe_title safe_description safe_title=$(html_escape "$title") safe_description=$(html_escape "$description") printf '%s\n' \ "<!DOCTYPE html><html><head><title>${safe_title}

${safe_title}

${safe_description}

" } ``` ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says "Use when creating web pages," which is broad and overlaps with many ordinary website-authoring tasks beyond this skill's specific landing-page template workflow. It does not define clearer trigger boundaries, exclusions, or narrower invocation conditions, increasing the chance of unintended activation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
70% confidence
Finding

The skill explicitly states that data is stored in ~/.local/share/landing/, indicating persistence across sessions. Persistent local storage can retain user-provided titles, descriptions, generated pages, or metadata beyond the current task, which may expose sensitive project content or enable unintended reuse of stale data in later runs.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

create

bash
scripts/script.sh create <title description>

template

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 9)May include surrounding context.

sh
DATA_DIR="$HOME/.local/share/landing"
mkdir -p "$DATA_DIR"

#
#
#
#

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This shell script writes to the filesystem by creating $HOME/.local/share/landing, but there is no visible user-facing message, confirmation, or explanatory comment disclosing that behavior. For code files, filesystem writes should have some form of disclosure unless they are clearly documented as part of the skill behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.