Back to skill

Security audit

Sleep Tracker

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a local sleep and wellness tracker, but it stores sleep journal data in a shared temporary file and its documentation does not clearly match its behavior.

Review this skill before installing if you plan to record personal sleep or health notes, especially on shared machines. Prefer a version that stores journals in a private per-user directory with restrictive permissions and has documentation that clearly states which script and commands are intended to be used.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sleep.sh:9
Finding

Predictable Shared Temporary File Exposes Sleep Journal Data and Enables Symlink Attacks

Content
View full analysis

Vulnerability Details

File Location: scripts/sleep.sh, lines 9 and 470
Vulnerability Type: Predictable unsafe temporary file
Risk Level: Medium

bash
JOURNAL_FILE="/tmp/sleep_journal.txt"
bash
echo "${date} | ${bedtime}-${waketime} | ${sleep_h}h${sleep_m}m | Q:${quality}/10 | ${notes}" >> "$JOURNAL_FILE"

Technical Analysis

The script stores health-related sleep journal records at a fixed, predictable path in the globally shared /tmp directory. It neither creates the file with an explicitly restrictive permission mode nor verifies that the destination is a regular file owned by the current user.

An attacker with local access can anticipate the path and pre-create the file, manipulate its permissions, or replace it with a symbolic link. Shell append redirection follows symbolic links, so the journal entry can be redirected to another file writable by the victim. An attacker can also seed fabricated records that will subsequently appear in the journal's seven-day history.

Attack Path

  1. A local attacker predicts the fixed path /tmp/sleep_journal.txt.
  2. Before the victim invokes the journal command, the attacker creates that file with permissive access or creates a symbolic link at that path to another victim-writable file.
  3. The victim runs a command such as bash sleep.sh journal ....
  4. The shell follows the existing path and appends the journal entry using the victim's privileges.
  5. Depending on the attack setup, the attacker can read sensitive sleep records, inject false history, corrupt the journal, or cause attacker-selected data to be appended to another file writable by the victim.

Impact Assessment

The vulnerability can disclose health-related sleep times, quality ratings, and free-form notes to another local user. It can also compromise journal integrity through record injection or corruption.

A successful symlink attack permits append operations with the invoking user's privileges, but only aga ...[truncated 225 chars]

Remediation
View remediation

Remediation Suggestions

  • Store the journal in a private per-user data directory, such as ${XDG_DATA_HOME:-$HOME/.local/share}/sleep-tracker.
  • Create the directory with mode 0700 and the journal file with mode 0600.
  • Set a restrictive umask, such as umask 077, before creating or writing sensitive files.
  • Before writing, reject symbolic links and verify that an existing destination is a regular file owned by the current user.
  • Avoid fixed names in shared temporary directories. If temporary storage is genuinely required, create a private directory or file with mktemp and arrange secure cleanup.
  • Use atomic, race-resistant file operations where possible rather than performing a separate check followed by ordinary shell redirection.

A hardened storage setup could begin with:

bash
DATA_DIR="${XDG_DATA_HOME:-$HOME/.local/share}/sleep-tracker"
umask 077
mkdir -p -- "$DATA_DIR"
chmod 700 -- "$DATA_DIR"
JOURNAL_FILE="$DATA_DIR/sleep_journal.txt"

if [ -L "$JOURNAL_FILE" ]; then
  echo "Refusing to write through a symbolic link" >&2
  exit 1
fi
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest and title present a sleep-focused tool, but the documented behavior is a generic health tracker with unrelated functions and missing claimed sleep-specific capabilities. This mismatch can mislead users and downstream agents into invoking the skill for sensitive sleep guidance or analysis that it does not actually provide, undermining trust and potentially causing unsafe reliance on incomplete health functionality.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation describes a broad health and wellness tracker even though the manifest advertises a sleep-focused skill. In a health context, capability confusion is risky because users may disclose sensitive data or rely on the tool for sleep-related guidance that is not actually specialized or implemented.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The listed commands do not support several sleep-specific capabilities claimed in the manifest, including analysis, environment optimization, nap guidance, and schedule planning. This creates an integrity and safety issue because users may assume they are receiving tailored sleep support when they are only using generic logging and reminder commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill handles sensitive health-related entries and offers export functionality, but it provides no privacy warning or guidance about local storage, retention, or the risks of sharing exported data. In the health context, this increases the chance of accidental exposure of personal wellness data through logs, shell redirection, backups, or shared systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a sleep-focused tool for sleep analysis, schedule planning, environment optimization, nap guidance, and sleep journaling. In contrast, the script labels itself as a 'Health and wellness tracker' and includes generic wellness behaviors like hydration, movement reminders, and arbitrary goal tracking that go beyond sleep-specific functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill writes sleep journal entries to a shared /tmp file without warning users that their sleep logs will persist locally. In the context of a sleep-tracking tool, the stored content can include dates, schedules, and notes about health or habits, so undisclosed storage in a shared temporary location increases privacy and tampering risk.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The naming and manifest framing imply a sleep-focused utility, yet the introductory documentation immediately redefines it as a versatile CLI for broad health habits. This is an intent-level contradiction in the documentation itself, not just an omission of detail.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The built-in health tip states 'Sleep 7-8 hours' as a fixed recommendation. This is a natural-language policy concern because it imposes a one-size-fits-all guideline without offering user choice, personalization, or noting that sleep needs can vary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest claims sleep analysis, improvement recommendations, schedule planning, environment optimization, nap guidance, and sleep diary features. The code only logs free-form entries, shows simple counts/history, echoes reminders, and prints generic tips; there is no actual sleep analysis, environment optimization, or nap-specific guidance implemented.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script stores user sleep journal entries in a fixed world-accessible path under /tmp, which is a shared temporary directory on multi-user systems. Even though the data is not highly privileged, it is personal health-related information and can be exposed, overwritten, or tampered with by other local users or via symlink attacks depending on system configuration.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help text says schedule <wake_time> [cycles] and implies the second argument affects the output. However, cmd_schedule reads min_cycles but never uses it, instead hardcoding the cycle counts in the loop.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The inline help/documentation actively states a configurable cycles argument with a default range of 5-6. In practice, the function does not use the provided value at all and always outputs fixed 6/5/4/3-cycle recommendations, contradicting the documented behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This file contains user-facing instructional text entirely in Chinese, which can constitute a language policy issue when no opt-in or alternative language option is provided. The content does not indicate that the skill is intentionally region- or language-specific, so it may exclude users expecting default-language neutrality.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.