Back to skill

Security audit

Draw

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly aligned with its advertised SVG drawing purpose and instead persists user-provided design text in local logs.

Review before installing. This package appears to be a local design-note logger, not an SVG diagram generator. Avoid entering secrets, proprietary prompts, or sensitive project details unless you are comfortable with them being stored under ~/.local/share/draw; also note that the artifact does not document a built-in purge or retention control.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:64
Finding

Unsafe JSON and CSV Generation from Untrusted Log Values

Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "" >> "$out" echo "]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ;; ``` ### Technical Analysis Values read from the log files are derived from command-line input and therefore must be treated as untrusted. The export implementation inserts these values directly into JSON strings without escaping quotation marks, backslashes, control characters, or line breaks. A crafted value can consequently invalidate the generated document or inject additional JSON properties and objects. The CSV implementation similarly concatenates fields without RFC 4180 quoting. Commas, quotation marks, and newlines can alter the exported record structure. In addition, a value beginning with `=`, `+`, `-`, or `@` may be interpreted as a formula when the file is opened in spreadsheet software. Depending on the spreadsheet and its security settings, such a formula may initiate external requests, disclose data, or mislead the user. The current command dispatcher cont ...[truncated 1588 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:118
Finding

Stored Terminal Control-Sequence Injection

Content
View full analysis
> "$DATA_DIR/history.log"; } ``` The recent-activity function subsequently writes persisted content directly to the terminal: ```bash _recent() { echo "=== Recent Activity ===" if [ -f "$DATA_DIR/history.log" ]; then tail -20 "$DATA_DIR/history.log" | while IFS='' read -r line; do echo " $line" done else echo " No activity yet." fi } ``` Command branches also persist and display the arbitrary input. The palette branch is representative of the same pattern used by the other logging commands: ```bash palette) shift if [ $# -eq 0 ]; then echo "Recent palette entries:" tail -20 "$DATA_DIR/palette.log" 2>/dev/null || echo " No entries yet. Use: draw palette " else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/palette.log" local total=$(wc -l < "$DATA_DIR/palette.log") echo " [Draw] palette: $input" echo " Saved. Total palette entries: $total" _log "palette" "$input" fi ``` ### Technical Analysis The script accepts arbitrary command arguments and writes them unchanged to per-command logs and `history.log`. It later emits those values directly to an interactive terminal through `echo`, `tail`, and search output. Terminal emulators interpret ANSI escape sequences and, in some environments, Operating System Command sequences. An attacker-controlled value can therefore manipulate colors, cursor ...[truncated 1533 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill metadata advertises SVG diagram creation, but the documented behavior is a local logging/journaling CLI that stores user-provided data in the home directory and supports search/export over that stored history. This mismatch is dangerous because users or agents may invoke the skill expecting graphics generation while unintentionally persisting potentially sensitive prompts or project data to disk.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest frames the skill as an SVG diagram tool, but the body describes a design/color logging utility with no diagram-generation functionality. Security-wise, deceptive capability descriptions undermine informed consent and can cause agents to route unrelated or sensitive content into a persistent local datastore.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level description promises diagram/SVG generation, while the rest of the file documents color/design journaling and log management. In an agent setting, this discrepancy increases the chance of unsafe data handling because the operator may not realize the skill is retaining activity history and enabling later retrieval/export of prior inputs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill advertises diagram/SVG generation, but the implementation instead stores arbitrary user inputs and exports accumulated logs. This mismatch is dangerous because users may provide sensitive design prompts or content under false assumptions, and the script turns the skill into a covert collection/export mechanism rather than the claimed functionality.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file-level documentation describes a design tool, but the code behaves as a command logger and exporter. That deception materially increases risk because it can induce users to submit sensitive information to a tool that is not performing the promised task and is instead retaining their inputs for later retrieval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script creates a persistent data directory and writes activity/history logs unrelated to a normal drawing utility's core purpose. In the context of a skill expected to process creative inputs, silent collection of user-provided text increases the risk of retaining sensitive prompts, proprietary diagram content, or internal notes without user awareness.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script not only records all user inputs but also implements search, recent-history review, status reporting, and bulk export of the collected content. In a skill context where users expect diagram generation rather than data warehousing, this creates a straightforward natural-language exfiltration path for sensitive prompts and accumulated user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

At this location and throughout similar command handlers, arbitrary user input is appended to persistent logs without upfront notice in the CLI help or command output before collection occurs. This is dangerous because users are not informed that free-form inputs may be retained on disk, making accidental storage of secrets, proprietary content, or personal data more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

Although the file mentions the storage location, it does not clearly warn users at the point of use that routine commands create persistent logs and export files under the user's home directory. This can lead to inadvertent retention of sensitive design notes, prompts, or internal project information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.