Back to skill

Security audit

Consent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Review item because it is advertised for cookie consent/GDPR work but mainly documents and ships a local security-style logger that encourages credential-like inputs and stores data in plain text.

Review before installing. Do not provide real passwords, API keys, tokens, passphrases, regulated personal data, or confidential consent records to this skill. It appears local-only and I found no exfiltration or destructive behavior, but its purpose is mislabeled and its intended storage/export model is not appropriate for sensitive compliance or credential data without redesign.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:6
Finding

Security-sensitive inputs are stored and disclosed in plaintext

Content
View full analysis
> "$DATA_DIR/history.log"; } ``` ```bash store) shift if [ $# -eq 0 ]; then echo "Recent store entries:" tail -20 "$DATA_DIR/store.log" 2>/dev/null || echo " No entries yet. Use: consent store " else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/store.log" local total=$(wc -l < "$DATA_DIR/store.log") echo " [Consent] store: $input" echo " Saved. Total store entries: $total" _log "store" "$input" fi ;; ``` The same plaintext logging pattern is repeated for security-oriented commands including `generate`, `check-strength`, `rotate`, `hash`, and `verify` in `scripts/script.sh:141-309`. ### Technical Analysis The Skill documentation encourages users to submit API keys, database passwords, credentials, tokens, passphrases, and consent records. The implementation writes each submitted value verbatim to a command-specific log and then writes it again to `history.log`. It also echoes the value to standard output. No encryption, one-way hashing, secret redaction, access-control validation, or restrictive `umask` is applied. `mkdir -p` therefore relies on the caller's ambient umask. Under a common `0022` umask, newly created files can be readable by other local users. The command named `hash` also follows this logging pattern rather than hashing its input. The argument-taking branches currently use `local` outside a function, which normally causes Bash execution to fail at that statement. This functional defect limits ordinary command-line exploitation in the current version, but it does not ...[truncated 1479 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:60
Finding

Unescaped JSON and CSV exports permit data corruption and spreadsheet formula injection

Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "" >> "$out" echo "]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ;; txt) echo "=== Consent Export ===" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue echo "--- $(basename "$f" .log) ---" >> "$out" cat "$f" >> "$out" echo "" >> "$out" done ;; *) echo "Formats: json, csv, txt"; return 1 ;; esac echo "Exported to $out ($(wc -c < "$out") bytes)" } ``` ### Technical Analysis Log values are attacker-controlled or user-controlled data. The JSON exporter interpolates these values directly inside quoted JSON strings without escaping quotation marks, backslashes, control characters, or newlines. A crafted value can therefore produce malformed JSON or alter the logical structure of the exported document. The CSV ...[truncated 1834 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill’s declared purpose is cookie-consent/GDPR banner management, but the documented behavior is a generic local logging toolkit that includes token, credential, hashing, verification, and export features. This mismatch is dangerous because it can mislead users or downstream agents into invoking a tool under a benign privacy/compliance label while actually collecting and persisting arbitrary sensitive inputs in plain-text logs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest and top-level documentation present the skill as a cookie-consent/GDPR utility, but the actual documented behavior is a broad security and credential logging toolkit. In an agent ecosystem, this kind of semantic disguise increases the chance that sensitive values are routed to the skill under false assumptions about its purpose and safety boundaries.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Commands for credential rotation, token generation, hashing, verification, and revocation are unjustified in a cookie-consent banner/compliance skill and materially expand the blast radius of misuse. Users may provide secrets, passwords, API keys, or security metadata to a tool they believe is only handling consent records, resulting in unnecessary collection and exposure of sensitive data.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The examples explicitly normalize logging secrets such as API keys, database passwords, and passphrases into retrievable local logs. In context, this is especially dangerous because the skill is mislabeled as a consent/compliance utility, making it more likely that operators will not treat it as a secret-handling system and will inadvertently expose credentials.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says this skill should build cookie consent banners, audit cookies, and track opt-in compliance. Instead, the help text advertises a broad 'security toolkit' with generic commands like generate, rotate, hash, verify, and store, and the implementation simply logs arbitrary inputs to local files rather than performing consent-banner generation or cookie/compliance logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

User-supplied input is persistently written verbatim to log files in the user’s home directory with no minimization, masking, consent notice, retention policy, or file-permission hardening. In a consent/GDPR context, those inputs may include identifiers, cookie values, policy text, audit artifacts, or other regulated data, creating a confidentiality and compliance risk if local files are read by other processes, backed up, or later exported.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly reframes the module as a 'Security toolkit' while the manifest advertises consent/GDPR functionality, creating contradictory trust signals. This inconsistency makes it easier for users and automated systems to misunderstand the tool’s data-handling behavior and overlook the risk of logging sensitive material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill does not prominently warn that command inputs are logged to local plain-text files, even though the examples and command semantics invite users to submit potentially sensitive consent records, tokens, credentials, and passphrases. This omission materially increases the likelihood of accidental secret disclosure and improper retention of regulated data.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The usage guidance encourages storing, auditing, exporting, and reporting arbitrary user-provided data in plaintext, including compliance-related and potentially sensitive records. Export and search capabilities further amplify the risk by making bulk disclosure and secondary processing of stored sensitive data easier.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill grants unrestricted tool access without appropriate constraints. An agent with unfettered tool access can perform arbitrary actions including file modification, network requests, and code execution.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
## Tips

- Run any command without arguments to see its recent entries — great for quick review
- Use `consent recent` to see a timeline of all activity across all commands
- Pipe exports to other tools: `consent export csv && cat ~/.local/share/consent/export.csv | head`
- Combine `search` with grep for complex queries: `consent search "2025" | grep "policy"`

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-of-file comments label the script 'Consent — security tool,' and the help banner says 'Consent v2.0.0 — security toolkit.' That documentation conflicts with the declared skill intent of building cookie consent banners and tracking GDPR opt-in compliance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

For a skill whose stated purpose is GDPR consent implementation and cookie auditing, commands like check-strength, rotate, hash, and verify are not an obvious requirement. In code, these commands do not even implement those security functions; they just persist arbitrary user input under those labels, further indicating unjustified capability surface beyond the stated consent scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The export function aggregates all stored records into json/csv/txt files on disk without access controls, redaction, or user safety guidance. Because the tool’s context involves consent/compliance data, bulk export increases the blast radius of any sensitive records already captured and makes accidental disclosure through copied files, backups, or shared workstations more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.