Back to skill

Security audit

Diary

Security checks for vulnerabilities and agentic risk

Overview

This diary skill is really a local plaintext productivity logger with a misleading description and weak privacy/export handling, so users should review it before installing.

Install only if you are comfortable with a simple local plaintext logger. Avoid storing secrets, regulated data, or very private diary content, and treat exported JSON/CSV/TXT files as sensitive. The publisher should align the public description with the actual productivity-log behavior, add deletion/retention and privacy guidance, and fix JSON/CSV export encoding before this is considered low-risk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:57
Finding

Improper Output Encoding in JSON and CSV Exports

Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "" >> "$out" echo "]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ;; ``` ### Technical Analysis Diary entry values are user-controlled and are written directly into JSON and CSV exports without format-specific encoding. For JSON output, quotation marks, backslashes, control characters, and embedded newlines are not escaped. An entry containing these characters can terminate the intended JSON string, inject additional JSON properties or objects, or make the exported document syntactically invalid. For CSV output, fields are not enclosed in quotes and embedded quotes are not escaped. Commas and newlines can therefore alter the exported row and column structure. In addition, values beginning with spreadsheet formula indicators such as `=`, `+`, `-`, or `@` may be interpreted as formulas when the resulting CSV file is opened in compatible spreadsheet software. This issue does not constitute shell command injection in the diary script itself because the values are passed as quoted arguments to `printf` or `echo`. Exploit ...[truncated 1768 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The manifest and description present this as a personal diary with mood tracking, photos, and monthly summaries, but the documented behavior is a broader local productivity logger with export and search features and no visible implementation of those advertised diary-specific features. This mismatch can mislead users into entrusting sensitive personal data under false assumptions about functionality and privacy expectations, which is a security-relevant integrity and trust issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation materially diverges from the declared diary purpose and exposes a much broader set of productivity/task-management behaviors than users would reasonably expect from the manifest. This kind of scope mismatch is dangerous because it undermines informed consent and review boundaries, making it easier for hidden or overbroad functionality to be deployed under a benign-looking description.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
84% confidence
Finding

The skill is explicitly designed for persistent local storage of user entries and history, which creates session persistence of potentially sensitive information. While persistence is core to the tool's purpose rather than inherently malicious, it still increases privacy risk if users are not clearly informed about retention and local exposure.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
source: https://github.com/bytesagain/ai-skills
license: MIT-0
tags: [diary, tool, utility]
description: "Write diary entries with mood tracking, photos, and monthly summaries. Use when recording thoughts, tracking moods, reviewing monthly patterns."
---

# Diary

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill claims diary-oriented capabilities involving moods, photos, and monthly summaries, but the body describes a multi-category operational logging toolkit instead. In a security context, deceptive or materially inaccurate capability descriptions increase the risk of unsafe use because users may disclose sensitive personal or work information believing they are using a narrower-purpose diary feature set.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill encourages recording diary and work-log content and states that entries are stored locally with activity history, but it does not warn users that these records may contain highly sensitive personal or business information. Lack of explicit privacy guidance can lead to unintentional persistence of secrets, health-related details, or confidential work data on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The export feature writes aggregated diary/log data to JSON, CSV, or text files without any warning that exports may create easily copied, synced, or exfiltrated plaintext artifacts. Exported files often broaden exposure beyond the original storage location and can be opened by other tools or included in backups unintentionally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The inline comments and help text explicitly brand the script as a general productivity toolkit, contradicting the diary-specific manifest. While not directly exploitable code execution, this discrepancy is a trust and transparency issue that can conceal overbroad capabilities and weaken security review assumptions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The command set includes broad planning, prioritization, reporting, archiving, and other general-purpose productivity functions that are not justified by the stated diary context. In a skill ecosystem, unjustified extra capabilities increase attack surface and create opportunities for misuse under a misleading label.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script stores diary content persistently in plaintext local log files under the user's home directory without warning, consent, retention controls, or protection for potentially sensitive personal data. In the context of a diary skill, this is more dangerous because users are likely to enter intimate thoughts, moods, and other private information that may later be exposed to other local users, backups, or support tooling.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.