Back to skill

Security audit

Goal Setter

Security checks for vulnerabilities and agentic risk

Overview

This goal-tracking skill is purpose-aligned, but its command script can execute unintended local Python code when given crafted goal text or related inputs.

Review this skill carefully before installing. Its local goal storage is normal for its purpose, but until the script is fixed to pass user inputs to Python as data rather than source code, do not use it with goal names, milestones, deadlines, or progress values from untrusted text or automated sources.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/goal_setter.sh:29
Finding

Arbitrary Python Code Execution Through Unsanitized Shell Argument Interpolation

Content
View full analysis
[deadline]"; exit 1; } python3 << PYEOF import json, time with open("$DB") as f: goals = json.load(f) gid = max([g.get("id",0) for g in goals]+[0]) + 1 goals.append({"id":gid,"goal":"$goal","deadline":"$deadline","progress":0, "milestones":[],"status":"active","created":time.strftime("%Y-%m-%d"), "notes":""}) with open("$DB","w") as f: json.dump(goals, f, indent=2, ensure_ascii=False) print("🎯 Goal #{} set: $goal".format(gid)) if "$deadline": print(" Deadline: $deadline") PYEOF ;; milestone) goal="${1:-}"; step="${2:-}" [ -z "$goal" ] || [ -z "$step" ] && { echo "Usage: milestone "; exit 1; } python3 -c " import json with open('$DB') as f: goals = json.load(f) for g in goals: if g['goal'] == '$goal' or str(g.get('id','')) == '$goal': g.setdefault('milestones',[]).append({'step':'$step','done':False}) print('📍 Milestone added to {}: $step'.format(g['goal'])) break with open('$DB','w') as f: json.dump(goals, f, indent=2, ensure_ascii=False) ";; progress) goal="${1:-}"; pct="${2:-0}" [ -z "$goal" ] && { echo "Usage: progress "; exit 1; } python3 -c " import json with open('$DB') as f: goals = json.load(f) for g in goals: if g['goal'] == '$goal' or str(g.get('id','')) == '$goal': g['progress'] = int('$pct') bar = '█' * (int('$pct')//10) + '░' * (10-int('$pct')//10) print('📊 {} [{}] {}%'.format(g['goal'], bar, '$pct')) if int('$pct') >= 100: ...[truncated 4289 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill advertises local data storage and the analysis detected file-write capability, but the manifest does not declare any explicit tool scope such as permissions or allowed-tools. This creates an unnecessary trust gap: a user or host system cannot easily verify what write actions are intended, increasing the risk of unauthorized or overly broad filesystem modification if the implementation writes outside expected storage paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says 'Personal daily-use tool for tracking and organizing your life' and 'Use when you need Goal Setter capabilities,' which does not define specific trigger phrases or clear boundaries for when the skill should or should not activate. This broad wording overlaps with many common productivity requests and could cause unintended invocation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script creates a goal storage directory and initializes a JSON database file in the user's home directory, but there is no comment or other disclosure near that behavior. For code files, persistent file writes should have some visible explanation unless they are clearly disclosed elsewhere; these writes happen implicitly on startup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Several commands rewrite the persistent goals JSON file after updates, but the write action itself is not explicitly disclosed through comments or warnings. Although modification is part of the tool's purpose, the persistent overwrite behavior would be clearer and safer with a visible note that user data is being changed on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.