Back to skill

Security audit

Config

Security checks for vulnerabilities and agentic risk

Overview

This local config-log skill does not show exfiltration, but it needs Review because it persistently records configuration text and command history in plaintext while some advertised management features are misleading or incomplete.

Use this only as a simple local notes/history log. Do not store passwords, tokens, private endpoints, or production secrets in it; restrict the storage directory permissions yourself; and do not rely on `config remove` to delete data unless the implementation is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Configuration and Command Data May Be Stored with Overly Permissive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:5-7, scripts/script.sh:34, and scripts/script.sh:53-55
Vulnerability Type: Insecure local storage and plaintext argument logging
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${CONFIG_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/config}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

Technical Analysis

The script creates its data directory and log files without establishing a restrictive umask or explicitly assigning secure permissions. Their effective permissions therefore depend on the invoking process's environment. Under a common umask of 022, the directory may be created as mode 0755 and files as mode 0644, making stored content readable by other local users.

The add operation writes the complete supplied text to data.log. It also copies the first argument into history.log. The documented use cases encourage users to record configuration changes, endpoints, environment information, and deployment notes. Such values may include confidential infrastructure details or accidentally supplied credentials.

The CONFIG_DIR override can also point storage at a shared or otherwise insufficiently protected location. The script does not validate the ownership or permissions of that directory before writing data.

Attack Path

  1. A user invokes the utility with confidential configuration information, for example through config add.
  2. The script creates data.log and history.log using permissions inherited from the current umask.
  3. With a permissive umask or shared CONFIG_DIR, another local account can traverse the data directory and read one or both files.
  4. The attacker obtains the recorded ...[truncated 669 chars]
Remediation
View remediation

Remediation Suggestions

  • Set a restrictive process mask before creating any storage:

    bash
    umask 077
    
  • Create the data directory with mode 0700 and log files with mode 0600.

  • Validate that DATA_DIR is owned by the current user and is not group- or world-writable before using it.

  • Avoid recording raw command arguments in history.log. Log only the command name or redact values likely to contain secrets.

  • Document explicitly that credentials, tokens, private keys, and passwords must not be supplied as entries.

  • Where practical, accept sensitive input through protected files or standard input rather than command-line arguments, which may also be visible in process listings and shell history.

  • Review and correct permissions on existing installations during initialization.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:64
Finding

Search Terms Beginning with a Hyphen Are Interpreted as grep Options

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:64-67
Vulnerability Type: Command option injection
Risk Level: Low

Vulnerable Code

bash
cmd_search() {
    grep -i "$1" "$DB" 2>/dev/null || echo "  Not found: $1"
    _log "search" "${1:-}"
}

Technical Analysis

Although the search argument is quoted and therefore does not enable shell metacharacter injection, it is passed to grep without the -- end-of-options delimiter. An attacker-controlled search value beginning with - can consequently be interpreted as one or more grep command-line options rather than as the intended search pattern.

Certain supplied options can change pattern handling, input processing, output behavior, or whether grep waits for standard input. This is an option-injection flaw, not arbitrary shell command execution: quoting prevents the argument from being split into separate shell words or evaluated as shell syntax.

Attack Path

  1. An attacker or untrusted automation controls the argument passed to config search.
  2. The attacker supplies an option-like value beginning with a hyphen, such as -e or another supported grep flag.
  3. grep parses that value as an option instead of the requested keyword.
  4. Search behavior is altered, potentially causing failed searches, unintended output, blocking on input, or excessive processing depending on the option and execution environment.

Impact Assessment

The primary impact is availability and integrity of search behavior. An attacker who can influence command arguments may cause unreliable results or disrupt an automation process that invokes the utility.

This flaw does not directly grant additional system privileges and does not provide arbitrary command execution. Its practical scope is limited to the invoked grep process and data accessible to the account already running the utility.

Remediation
View remediation

Remediation Suggestions

Terminate option parsing before passing the user-controlled pattern:

bash
cmd_search() {
    grep -i -- "$1" "$DB" 2>/dev/null || echo "  Not found: $1"
    _log "search" "${1:-}"
}

If the documented operation is intended to perform a literal keyword search rather than accept regular expressions, use fixed-string matching as well:

bash
grep -iF -- "$1" "$DB"

Also validate that a non-empty search argument was supplied and return a clear usage error when it is missing.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a configuration manager, but the documented behavior is a broader local logging utility that stores arbitrary entries and command history on disk. This mismatch can cause users or an orchestrating agent to invoke it in contexts involving sensitive configuration data, leading to unintended persistence, disclosure, or misuse of data under a misleading trust boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest claims a configuration-file manager, but the documentation describes a generic data logger with search, export, and remove capabilities. In an agent ecosystem, this semantic mismatch is security-relevant because tool selection may be based on metadata, causing the skill to be used on sensitive config tasks it does not safely or accurately implement.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

A broad invocation description can cause the skill to be selected for generic configuration-related requests beyond its safe or intended scope. In agent-driven environments, ambiguous routing increases the likelihood of sensitive data being passed to a tool that persistently logs arbitrary input.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The top-level docs frame the skill as a configuration tool, while the command/storage sections reveal it mainly logs arbitrary entries and command history. This increases the chance that secrets, deployment notes, or environment details are stored in plain local logs when users believe they are managing structured configuration safely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Labeling the skill as "multi-purpose" with generic task language makes its operational boundary unclear. That ambiguity can lead users or agents to treat it as a safe general utility and supply data types it should not handle, especially when it writes content and command history to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation states that added entries and every command are stored in local logs, but it does not warn that these records may contain sensitive information such as configuration values, environment details, or secrets embedded in command arguments. This omission materially increases the risk of accidental secret persistence and later disclosure from plaintext files under the user's home directory.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file comment labels the script as a 'Multi-purpose utility tool', while the manifest says the skill is for managing app configuration files with specific config-oriented operations. This is an active documentation-level contradiction about the skill's intended purpose, not merely an omitted detail.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for managing app configuration files with init, list, and add operations, but the help text and command set present the tool as a broader 'Multi-purpose utility tool' with additional commands like run, status, remove, search, export, and info. This expands the skill beyond the stated configuration-focused purpose and creates a mismatch between the advertised intent and actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script appends user-influenced content to a persistent local history file without any clear user-facing disclosure. While this is not remote code execution, it creates an undisclosed persistence/privacy risk because user inputs and command activity may be stored on disk unexpectedly, potentially exposing sensitive configuration values or search terms to other local users or future processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The add command persists arbitrary user input directly to disk and echoes it back, with no warning that the data will be stored. In a config-related skill, users may provide tokens, endpoints, credentials, or environment-specific details, so undisclosed persistence increases the risk of sensitive information being retained locally and later exposed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.