Back to skill

Security audit

Trivia Quiz

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local trivia and study helper that saves notes and command history on the user's machine, with no evidence of network access, credential use, privilege escalation, or destructive behavior.

Install only if you are comfortable with the skill keeping plaintext notes and command history under ~/.local/share/trivia-quiz or TRIVIA_QUIZ_DIR. Avoid entering sensitive personal, proprietary, or credential-like information, and delete that directory if you want to remove stored history.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a trivia/knowledge quiz skill centered on playing quizzes with facts, categories, and daily challenges. The code instead implements a broad command-line study assistant with placeholder outputs for learning, summaries, roadmaps, resources, and tests. It also writes note content and command history to local files under a data directory, which is an undeclared capability. While flashcards, review, and progress tracking are loosely related to the description, the primary purpose is materially broader and different from a quiz-playing skill, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The code is related to trivia quizzes, so the high-level domain matches the description. However, the declared description overstates the functionality. The implementation only outputs prewritten questions and answers and lists categories. There is no state, scorekeeping, user answer handling, progress tracking, flashcard workflow, or daily challenge feature. Because several prominent described capabilities are absent and the actual behavior is much narrower than the declared purpose, this is a description-behavior mismatch.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 62)May include surrounding context.

md
# Run a quick quiz on Docker
trivia-quiz quiz docker

# Create a flashcard
trivia-quiz flashcard "What is a closure?"

# Review with spaced repetition

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file header and help text describe the tool as a general learning and study assistant, which conflicts with the manifest's narrower 'Trivia Quiz' identity. This discrepancy undermines informed consent and review accuracy because the operator may not realize the true breadth of features or data processing behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script creates a data directory and persists activity to local files even though the manifest presents the skill as a trivia quiz. Undisclosed persistence expands the skill's effective scope and can surprise users by retaining study activity or note content on disk, creating privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The implemented command set materially exceeds the manifest's stated purpose of a trivia quiz by providing general study-assistant capabilities such as notes, summaries, roadmaps, and resource discovery. This mismatch is dangerous because users and reviewers may grant the skill permissions or trust based on a narrower description while the code performs broader functions, including data handling not clearly disclosed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documented commands advertise broader study workflows than the manifest claims, indicating a scope discrepancy between declared and actual behavior. Such discrepancies are dangerous in agent skills because they can hide capability creep and reduce the effectiveness of human or automated security review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The logging function writes command activity into a persistent history file without any explicit warning, consent, or retention controls. Even if the content seems low risk, command arguments may contain sensitive study topics or personal notes, so silent persistence creates a privacy issue and can expose user data to other local users or later compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The note command stores arbitrary user-supplied text to a persistent local log file without warning about retention or sensitivity. In the context of a study assistant, users may enter personal, academic, or proprietary information, so undisclosed storage materially increases privacy risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.