Back to skill

Security audit

Dice

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local game-themed logger, but it is presented as a dice and score tool even though it does not actually roll dice or calculate scores.

Install only if you want a simple local logging tool for game notes, not an actual dice roller or score calculator. Avoid storing sensitive player or session information, and treat JSON/CSV exports as untrusted if entries may contain quotes, commas, newlines, or spreadsheet formula characters.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:62
Finding

Improper Escaping of User-Controlled Data in JSON Exports

Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" ``` ### Technical Analysis The export routine inserts log contents directly into JSON string literals without applying JSON escaping. The `value` field can contain user-controlled command arguments previously recorded in a log file. Quotes, backslashes, newlines, and other JSON control characters are therefore written verbatim. Shell quoting around `"$val"` prevents shell word splitting and command substitution at export time, but it does not make the value safe for a JSON context. A crafted entry can terminate the expected string, add properties or objects, or make the exported document syntactically invalid. For example, a stored value resembling the following can alter the logical structure of the output: ```text x","injected":true,"value":"y ``` This is an output-encoding vulnerability rather than direct shell command injection. ### Attack Path 1. An attacker or untrusted caller supplies a crafted value to an argument-bearing command such as `dice score`. 2. The application records the value without validating or encoding it. 3. The user invokes `dice export json`. 4. The export routine interpolates the crafted value directly into a JSON string. 5. A downstream program consumes the resulting export. 6. Depending on the payload, the JSON is rejected, interpreted with attacker-injected fields, or processed differently from the structure intended by the application. ### Impact Assessment The vulnerability can compromise the integrity and availability of generated JSON exports. It may permit injection of misleading fields or records into data consumed by another application. The impact ...[truncated 238 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:70
Finding

Spreadsheet Formula Injection and Invalid Encoding in CSV Exports

Content
View full analysis
"$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f" done ``` ### Technical Analysis User-controlled log values are concatenated into CSV rows without quoting or escaping. Values containing commas, double quotes, carriage returns, or newlines can alter the expected row and column structure. In addition, spreadsheet applications may interpret cells beginning with characters such as `=`, `+`, `-`, or `@` as formulas. Because the exporter does not neutralize formula-leading values, an attacker can place spreadsheet expressions into an exported cell. This does not execute a shell command when the Skill creates the export. Exploitation occurs later if the CSV file is opened by spreadsheet software that evaluates the injected formula. The exact effect depends on the spreadsheet program and its security settings. ### Attack Path 1. An attacker supplies a value beginning with a spreadsheet formula marker to a command that records input. 2. The raw value is stored in the corresponding log file. 3. The victim invokes `dice export csv`. 4. The exporter copies the value into the CSV without contextual escaping or formula neutralization. 5. The victim opens the generated CSV in a spreadsheet application. 6. The spreadsheet may evaluate the attacker-controlled cell as a formula. 7. Depending on supported functions and security settings, the formula may display deceptive content, reference other cells, initiate external requests, or expose spreadsheet data. Separately, embedded commas, quotes, or newlines can corrupt row boundaries and produce misleading exports even where formula evaluation is disabled. ### Impa ...[truncated 595 chars]
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description suggests an active tabletop gaming assistant that rolls dice and manages scores, rankings, history, and stats. The code instead implements a shell-based note/log tracker: for commands like roll, score, rank, and others, it simply records the provided text input with a timestamp into per-command log files. There is no dice randomization, no score calculation, no ranking algorithm, and no meaningful statistics beyond counting log lines/files. It also exposes undeclared capabilities such as exporting data, searching logs, recent activity, and status reporting, and it persists all data under ~/.local/share/dice. While the overall theme is game-related, the actual behavior is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says the skill should be used when rolling dice, which implies generating or evaluating dice results. Instead, the roll command just appends the caller's input string to roll.log and echoes it back, so the core behavior does not match the claimed purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

Documenting a reset command without warning about destructive behavior can lead users or higher-level agents to invoke it and unintentionally erase stored game history or score data. In this skill, the local persistent datastore makes that omission more meaningful because users may assume commands are non-destructive unless clearly labeled otherwise.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a narrowly scoped dice and score-tracking tool, but the command surface advertised in help includes several generic activity verbs with no clear dice or tabletop-stats semantics. In code, these commands merely persist arbitrary text to separate log files, expanding the skill into a generic event logger rather than a focused dice/statistics utility.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline documentation in help says 'stats' provides summary statistics, creating the expectation that it analyzes stored data. However, the earlier case branch for stats only shows recent entries or appends arbitrary input to stats.log, contradicting that documented intent; the actual summary function is shadowed by the duplicate stats case and is never reached.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persistently stores arbitrary user-provided input under ~/.local/share/dice/*.log and echoes some of it back through history, search, export, and status features without clearly warning the user. In an agent-skill context, users may provide game notes, player names, or accidentally sensitive text believing they are performing ephemeral actions like 'roll', creating a privacy risk through undisclosed local retention and later disclosure to other local users, backups, or support workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.