Back to skill

Security audit

Blog

Security checks for vulnerabilities and agentic risk

Overview

This is a local blog-note logging skill with disclosed plaintext persistence and no evidence of hidden network, credential, or destructive behavior.

Use this only for simple local blog workflow notes. Do not paste passwords, API keys, embargoed drafts, or sensitive business plans unless you are comfortable with them being stored as plaintext under ~/.local/share/blog; be cautious with CSV exports in spreadsheet apps and manually manage or delete retained logs when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:52
Finding

Improper JSON and CSV Export Encoding

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 52-54 and 65-67
Vulnerability Type: Improper output encoding and spreadsheet formula injection
Risk Level: Medium

Vulnerable Code

bash
while IFS='|' read -r ts val; do
    [ $first -eq 1 ] && first=0 || echo "," >> "$out"
    printf '  {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out"
bash
echo "type,time,value" > "$out"
for f in "$DATA_DIR"/*.log; do
    [ -f "$f" ] || continue
    local name=$(basename "$f" .log)
    while IFS='|' read -r ts val; do
        echo "$name,$ts,$val" >> "$out"
    done

Technical Analysis

Values read from the log files are inserted directly into JSON and CSV output without format-specific encoding.

For JSON, embedded double quotes, backslashes, control characters, or newlines are not escaped. A crafted value can therefore make the export syntactically invalid or alter its apparent object structure when processed by downstream software.

For CSV, fields containing commas, quotes, or newlines are not quoted according to CSV rules. In addition, values beginning with spreadsheet formula indicators such as =, +, -, or @ are exported unchanged. Spreadsheet applications may interpret such cells as formulas rather than text.

The normal content-writing commands currently fail before writing because they use local outside a function. Nevertheless, the export routines process any existing or externally created .log files in the documented user-writable data directory, so crafted records can still reach the vulnerable export path.

Attack Path

  1. An attacker or untrusted local process places a crafted record in a .log file under ~/.local/share/blog/, or supplies content through a workflow that populates these files.
  2. The victim runs blog export json or blog export csv.
  3. The script copies the crafted value in ...[truncated 1021 chars]
Remediation
View remediation

Remediation Suggestions

  • Generate JSON with a proper serializer such as jq, rather than interpolating untrusted values into JSON syntax.
  • If external dependencies are prohibited, implement and thoroughly test escaping for quotes, backslashes, control characters, and newlines.
  • Encode CSV according to RFC 4180: wrap fields in double quotes and replace each embedded double quote with two double quotes.
  • When exports are intended for spreadsheet use, neutralize cells beginning with =, +, -, @, tab, or carriage return by applying a documented safe-text policy.
  • Add automated tests covering commas, quotes, backslashes, multiline values, Unicode, and formula-leading content.
  • Correct the unrelated use of local outside functions so write-command behavior can be tested consistently.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:6
Finding

Predictable Log and Export Paths Lack Permission and Symlink Protections

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 6-7; related writes at lines 49, 59, and 70
Vulnerability Type: Insecure file creation and symbolic-link handling
Risk Level: Low

Vulnerable Code

bash
DATA_DIR="${HOME}/.local/share/blog"
mkdir -p "$DATA_DIR"

Related export writes use predictable paths without checking whether the destination is a symbolic link:

bash
local out="$DATA_DIR/export.$fmt"
bash
echo "[" > "$out"
bash
echo "type,time,value" > "$out"

Technical Analysis

The data directory and output filenames are predictable. The script does not establish a restrictive umask, explicitly set directory and file permissions, verify ownership, or reject symbolic links before opening output files.

Consequently, file permissions depend on the invoking user's environment. Under a permissive umask, locally stored blog content may be readable by other local users. If an expected export destination is already a symbolic link, shell redirection follows that link and truncates or overwrites its target.

Exploitation requires the attacker to be able to modify the user's blog data directory or otherwise influence its contents. This normally limits the issue to same-account processes, improperly shared home directories, or environments where the directory has unsafe permissions.

Attack Path

  1. A local attacker or compromised process obtains write access to ~/.local/share/blog/.
  2. The attacker creates a symbolic link such as export.json pointing to another file writable by the victim.
  3. The victim runs blog export json.
  4. The redirection operation follows the symbolic link and truncates or replaces the linked target with generated export data.
  5. Separately, if the victim uses a permissive umask, newly created logs or exports may be readable by unintended local users.

Impact Assessment

Successful symbolic-link ex ...[truncated 479 chars]

Remediation
View remediation

Remediation Suggestions

  • Set umask 077 before creating the data directory or any files.
  • Create the directory with mode 0700 and ensure log and export files use mode 0600.
  • Verify that the data directory is owned by the current user and is not a symbolic link.
  • Reject export destinations that are symbolic links, or create a new temporary file securely in the same directory and atomically rename it into place.
  • Avoid check-then-open races by using file operations that prevent symbolic-link following where the platform permits.
  • Document that the stored content is plaintext and should not contain credentials or other highly sensitive information.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description suggests a functional blog-post management tool with drafts, scheduling, and SEO optimization. The code instead implements a generic local journaling/logging utility for blog-related commands, storing raw user input into per-command .log files under ~/.local/share/blog. Commands like draft, optimize, and schedule merely append timestamped text to logs; there is no real article creation workflow, metadata handling, publication-date management, SEO analysis, or integration with a blog platform. Additionally, the script exposes several undeclared capabilities such as export, search, recent activity, stats, and many extra content categories. This is a material description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

The skill persistently stores user-provided content in plaintext under ~/.local/share/blog/, which can include unpublished drafts, scheduling details, social copy, and translation notes. While this appears intentional and local-only, persistent plaintext retention can expose sensitive business content or embargoed publication plans to other local users, backups, or malware on the host.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

Social media preparation

bash
# Create hashtag sets
blog hashtags "#remotework #developer #productivity #coding #devtips"

# Write hooks for social posts

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file header and help text present the script as a functional blog content tool, implying active content operations. In practice, the command handlers simply append the provided text to per-command log files and echo it back, which contradicts the documented intent of performing substantive blog actions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a relatively focused blog-management skill centered on drafts, scheduling, and SEO optimization. The command surface exposed in help includes multiple broader copywriting and text-transformation capabilities that go beyond that stated scope, indicating the implemented behavior is materially wider than what the skill advertises.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-supplied blog content is persistently written to plaintext files under ~/.local/share/blog without clear prior disclosure or consent. In this skill context, inputs may contain unpublished drafts, SEO plans, credentials accidentally pasted by users, or sensitive business content, creating confidentiality and retention risks if the host is shared, backed up, or later inspected.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.