Back to skill

Security audit

Golang

Security checks for vulnerabilities and agentic risk

Overview

This skill is a local logger packaged as a Go tooling skill, so it may save development details while not actually building, testing, linting, or formatting code.

Treat this as a local plaintext development journal, not as a Go build, test, lint, or formatting tool. Do not enter secrets, tokens, proprietary source snippets, or sensitive incident details unless you are comfortable storing them under ~/.local/share/golang/ and exporting them later. Review generated CSV/JSON carefully before sharing or opening in spreadsheet tools.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:102
Finding

Option Injection Through the Search Term

Content
View full analysis
}" echo "Searching for: $term" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local m=$(grep -i "$term" "$f" 2>/dev/null || true) if [ -n "$m" ]; then echo " --- $(basename "$f" .log) ---" echo "$m" | sed 's/^/ /' fi done } ``` ### Technical Analysis The value of `term` is supplied by the user and passed to `grep` without an end-of-options marker: ```bash grep -i "$term" "$f" ``` Quoting the variable prevents shell word splitting and shell metacharacter injection, but it does not prevent `grep` from interpreting a value beginning with `-` as an option. Consequently, input intended to be a search pattern can change `grep` behavior. Depending on the supplied option, an attacker can cause recursive searching, load patterns from a local file, alter matching semantics, or consume excessive system resources. This is argument or option injection rather than shell command injection; arbitrary shell commands cannot be executed directly through this code. ### Attack Path 1. An attacker influences the argument passed to `golang search`. 2. The attacker supplies a value beginning with `-`, such as a recursive-search or pattern-file option. 3. `_search` assigns that value to `term` without validating it. 4. `grep` parses the attacker-controlled value as an option instead of a search expression. 5. The resulting `grep` invocation may inspect unintended files under the process's working directory, produce misleading results, or consume excessive resources. ### Impact Assessment The injected options execute with the permissions of the user running the Skill. The flaw does not independently elevate privileges or provide arbitrary ...[truncated 255 chars]
Remediation
View remediation
/dev/null || true) ``` If regular-expression functionality is not required, use fixed-string matching to reduce ambiguity and regular-expression denial-of-service risks: ```bash local m m=$(grep -iF -- "$term" "$f" 2>/dev/null || true) ``` Additional hardening should include: 1. Rejecting empty search terms. 2. Applying a reasonable maximum input length. 3. Avoiding command substitution for potentially large output; stream matches directly where practical. 4. Testing terms beginning with `-`, including `-R`, `-f`, and `--help`, to verify that they are treated as literal data. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:55
Finding

Unsafe JSON and CSV Export of Attacker-Controlled Log Values

Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "\n]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f" done ;; ``` ### Technical Analysis Values written to the command logs originate from command-line input. The export implementation inserts those values directly into JSON and CSV output without format-specific encoding. For JSON, characters such as `"`, `\`, carriage returns, newlines, and other control characters are not escaped. A crafted value can therefore invalidate the document or inject additional apparent properties or records into the exported text. For CSV, values containing commas, quotes, or line breaks are not enclosed and escaped according to CSV rules. This permits column and row injection. The project documentation explicitly presents CSV as suitable for spreadsheet review. If an attacker creates an injected cell beginning with a spreadsheet formula indicator such as `=`, `+`, `-`, or `@`, opening the export in affected spreadshee ...[truncated 1547 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a Go build/test/lint/format toolkit, but the documented behavior is a persistent local logging and journaling system that stores user-provided inputs in ~/.local/share/golang/. This mismatch is dangerous because users may provide sensitive source code details, file paths, build output, or internal notes believing they are invoking normal development tooling, while the skill instead performs undeclared data retention and search/export operations over that collected data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The manifest and header describe a development tool for compiling, testing, linting, and formatting Go projects, but the file defines a local activity logger instead. In a security context, deceptive capability claims can cause users or agents to send operationally sensitive information to a component they would not otherwise trust for storage, creating confidentiality and audit-integrity risks.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The banner, help text, and command names present the script as a Go development toolkit, but the implementation merely records arbitrary user input. This kind of disguised behavior is especially dangerous in a skill ecosystem because it can trick users into supplying repository content, commands, or troubleshooting details that are then stored instead of processed as expected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script materially misrepresents its purpose: instead of building, testing, linting, or formatting Go projects, it implements a generic input collection, logging, search, and export utility. In an agent-skill context, this deception is dangerous because users and orchestrators may pass source code, secrets, file paths, or operational data expecting Go tooling behavior, while the skill silently persists that data for later retrieval.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples and top-level wording imply that commands like lint, format, generate, and fix perform real code operations, but the documented behavior only records arbitrary text. This can mislead users into thinking code was checked or remediated when nothing actually happened, leading to false assurance, missed defects, and unnecessary exposure of development details in stored logs.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The tool not only stores all supplied inputs in plaintext logs but also provides built-in mechanisms to search and export them, making previously entered data easy to retrieve in bulk. In the context of a supposedly benign Go helper, this creates a covert data collection channel that can expose sensitive development information far beyond the user's immediate command invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The export, search, statistics, and retained-history features are unrelated to a Go devtool and expand the skill's capability to collect, index, and exfiltrate prior user inputs. These unnecessary data-handling functions increase attack surface and make any sensitive information supplied to the tool easy to enumerate and dump from local storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-provided input is written verbatim to persistent log files under the home directory without meaningful notice, consent, minimization, or sanitization. In practice, users may provide source snippets, tokens, internal paths, or incident details, and those will remain on disk where other local processes or users may later read them.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.