Back to skill

Security audit

Roast Generator

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it advertises a roast generator while shipping an additional utility that silently stores and logs user-provided text locally.

Install only if you are comfortable with a package that may create local roast-generator data files and retain command arguments or added text. Avoid passing secrets, private names, confidential workplace text, or sensitive search terms unless the publisher documents storage, deletion, and permission behavior more clearly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T01 · Skill Instruction Hijacking

Note
Location
scripts/roast.sh:21
Finding

Unconditional Promotional Output Contaminates Skill Results

Content
View full analysis

Vulnerability Details

File Location: scripts/roast.sh:21
Vulnerability Type: Unconditional output injection
Risk Level: Low

Evidence

python
print("\nPowered by BytesAgain | bytesagain.com\nAll in good fun!")

Technical Analysis

The script unconditionally appends third-party branding to standard output on every invocation. This includes invocations where standard output is expected to contain only the requested roast or command result.

Because SKILL.md instructs consumers to treat standard output as the command result, an agent integrating this skill may relay the promotional content directly to users. The injected text is fixed and does not execute code or change agent safety constraints, but it modifies agent-visible output for a purpose unrelated to the requested operation.

Attack Path

  1. An agent invokes scripts/roast.sh to generate a roast or display command information.
  2. The Python program processes the requested command.
  3. Line 21 appends the promotional message regardless of the command or user preference.
  4. The agent captures standard output as the skill result.
  5. The unsolicited promotional message is relayed to the user alongside the legitimate result.

Impact Assessment

No additional operating-system privileges, code execution, or data access can be obtained through this behavior. The scope is limited to output integrity: generated results are predictably contaminated with unsolicited advertising, which may mislead users about whether the agent endorsed or generated that content.

Remediation
View remediation

Remediation Suggestions

  • Remove the unconditional promotional message from normal standard output.
  • If attribution is required, expose it only through an explicit command such as info or an opt-in flag such as --credits.
  • Keep standard output limited to the requested command result.
  • Send optional diagnostic or attribution information to standard error only when verbose mode is explicitly enabled.
  • Add output tests ensuring that generation commands return only documented result content.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Undisclosed Persistent Logging of User-Supplied Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:5-8, 29, 31-75
Vulnerability Type: Undisclosed plaintext data retention
Risk Level: Medium

Evidence

bash
DATA_DIR="${ROAST_GENERATOR_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/roast-generator}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

Representative commands pass user-controlled arguments to the logging function:

bash
cmd_run() {
    echo "  Running: $1"
    _log "run" "${1:-}"
}
bash
cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}
bash
cmd_search() {
    grep -i "$1" "$DB" 2>/dev/null || echo "  Not found: $1"
    _log "search" "${1:-}"
}

Technical Analysis

The script creates a persistent data directory immediately upon execution. Most operational commands then append their first user-supplied argument to history.log without disclosure, consent, redaction, retention limits, or explicit permission hardening.

Arguments may contain names, roast subjects, search terms, or other user-provided text. This information remains available after the command and agent session terminate. The files are created subject to the caller's current umask; the script does not enforce owner-only permissions.

No shell command injection is present in the shown logging operation because arguments are quoted. The security concern is undisclosed plaintext retention and potentially insufficient file-permission control.

Attack Path

  1. A user or agent invokes a supported command with sensitive or private text, such as run, add, or search.
  2. The command handler passes at least the first argument to _log.
  3. _log appends the command name, argument, and timestamp to $DATA_DIR/history.log.
  4. For add, the complete argument list is also a ...[truncated 693 chars]
Remediation
View remediation

Remediation Suggestions

  • Disable argument logging by default and require explicit, informed opt-in before retaining user content.
  • Do not record raw command arguments unless they are essential to the documented function.
  • Redact or hash sensitive values and store only the minimum metadata required.
  • Apply umask 077 before creating the directory and files.
  • Create the directory with owner-only permissions, such as mkdir -p -m 700 "$DATA_DIR".
  • Ensure data and history files use mode 0600.
  • Document the exact data collected, storage location, retention period, and deletion procedure.
  • Provide commands to inspect, clear, and disable history.
  • Avoid creating persistent storage for informational commands such as help and version.

other

Note
Location
scripts/script.sh:11
Finding

Implementation Exposes Undocumented Generic Data-Management Functionality

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:23-31, 38-50; scripts/script.sh:11-26, 31-91
Vulnerability Type: Undisclosed out-of-scope functionality and misleading interface
Risk Level: Low

Evidence

The skill documentation advertises roast modes:

text
  gentle          gentle
  savage          savage
  friend          friend
  celebrity       celebrity
  self            self
  battle          battle

It also states:

text
- Run `roast-generator help` for all commands

## Commands

Run `roast-generator help` to see all available commands.

## Output

Results go to stdout. Save with `roast-generator run > output.txt`.

The primary utility script instead advertises generic persistent data-management commands:

bash
Commands:
  run                  Execute main function
  config               Configuration
  status               Show status
  init                 Initialize
  list                 List items
  add                  Add entry
  remove               Remove entry
  search               Search
  export               Export data
  info                 Show info
  help                 Show this help
  version              Show version

The generic commands operate on persistent local files:

bash
cmd_list() {
    [ -f "$DB" ] && cat "$DB" || echo "  (empty)"
    _log "list" "${1:-}"
}

cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

cmd_search() {
    grep -i "$1" "$DB" 2>/dev/null || echo "  Not found: $1"
    _log "search" "${1:-}"
}

cmd_export() {
    [ -f "$DB" ] && cat "$DB" || echo "No data"
    _log "export" "${1:-}"
}

Technical Analysis

The documented interface and actual implementation materially diverge. The documented modes gentle, savage, celebrity, self, and battle are not implemented by scripts/script.sh. ...[truncated 1615 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the generic utility implementation with the documented roast-generation functionality, or remove it from the package.
  • Ensure every documented mode is implemented and tested.
  • Remove commands unrelated to the declared purpose unless they are explicitly required and documented.
  • Document all filesystem writes, logging behavior, storage locations, and export behavior before users invoke the skill.
  • Maintain a single authoritative command implementation to prevent divergence between roast.sh, script.sh, and SKILL.md.
  • Add automated interface tests comparing documented commands with actual help output and command dispatch behavior.
  • Fail safely without creating files or directories when users request unsupported commands.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description and title content are presented bilingually across L04-L05 and L12, but the file does not state whether output language follows user preference or allow opt-in language selection. This can violate language/locale policy because the skill appears to impose mixed-language behavior by default.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill states it is suitable for anyone who needs a roast generator, including enterprise users, without defining clear scope, safety boundaries, or appropriate use cases. Overly broad applicability can cause the agent to invoke the skill in unsuitable contexts, increasing the chance of harmful, abusive, or policy-incompatible content generation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script documentation presents the tool as 'roast-generator', implying a purpose related to generating roasts, but the actual command set implements generic data store actions like add, list, search, export, and status over a local log file. This is an active contradiction between the code's stated identity/purpose and what the code actually does, not just an omitted detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The _log function records command usage and user-supplied arguments to a history file without warning. If users provide secrets or sensitive search terms, those values will be silently persisted, increasing exposure to other local users, backups, or later compromise of the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The add command writes user-supplied content to persistent local storage without notifying the user that the data will be retained. This can cause unintentional storage of sensitive information, especially if users pass secrets, personal data, or confidential text assuming the tool is transient.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.