Back to skill

Security audit

Llm Chain

Security checks for vulnerabilities and agentic risk

Overview

This package is labeled like a LangChain4j Java integration but actually provides a local Bash logging and export tool that stores user-entered LLM workflow data in plaintext.

Review this before installing because the package name and description do not match the actual behavior. If you use it, treat everything entered into llm-chain as persistent plaintext on your machine, avoid secrets or regulated data, and be careful opening exported CSV files in spreadsheets.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:58
Finding

Unsafe JSON and CSV Export Serialization

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 58-80
Vulnerability Type: Improper output encoding and CSV formula injection
Risk Level: Medium

bash
_export() {
    local fmt="${1:-json}"
    local out="$DATA_DIR/export.$fmt"
    case "$fmt" in
        json)
            echo "[" > "$out"
            local first=1
            for f in "$DATA_DIR"/*.log; do
                [ -f "$f" ] || continue
                local name=$(basename "$f" .log)
                while IFS='|' read -r ts val; do
                    [ $first -eq 1 ] && first=0 || echo "," >> "$out"
                    printf '  {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out"
                done < "$f"
            done
            echo "\n]" >> "$out"
            ;;
        csv)
            echo "type,time,value" > "$out"
            for f in "$DATA_DIR"/*.log; do
                [ -f "$f" ] || continue
                local name=$(basename "$f" .log)
                while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f"
            done
            ;;

Technical Analysis

Log values originate from command-line input and are stored without validation. During export, these values are interpolated directly into JSON strings and CSV fields without format-specific escaping.

In JSON output, embedded quotation marks, backslashes, and control characters can terminate or alter string values, corrupting the document or injecting attacker-controlled JSON structure. The generated closing line also uses echo "\n]", whose handling of the backslash is implementation-dependent and can further produce invalid JSON.

In CSV output, commas, quotation marks, carriage returns, and line feeds are not encoded according to CSV rules. More importantly, values beginning with spreadsheet formula indicators such as =, +, -, or @ remain executable fo ...[truncated 1560 chars]

Remediation
View remediation

Remediation Suggestions

  • Generate JSON with a serializer that correctly escapes all string values. For example, use jq -n with --arg parameters rather than constructing JSON with printf.
  • Generate the complete JSON array through the serializer and validate it before reporting a successful export.
  • Encode CSV according to RFC 4180: enclose each field in double quotes, replace every embedded double quote with two double quotes, and preserve record boundaries safely.
  • Neutralize spreadsheet formulas in user-controlled CSV fields. If spreadsheet use is intended, prefix values beginning with =, +, -, or @ with an apostrophe or apply another documented formula-injection mitigation.
  • Add regression tests covering quotation marks, backslashes, commas, pipes, carriage returns, line feeds, Unicode, and formula-leading values.
  • Treat exports as untrusted data and document that CSV files should not be opened in spreadsheet applications without appropriate formula-evaluation protections.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest claims this skill is LangChain4j, a Java LLM integration library, but the documented behavior is a Bash-based local logging/export tool. This mismatch is dangerous because users may trust and invoke the skill under false assumptions, leading to unintended persistence of sensitive prompts, benchmark data, costs, or internal notes to local plain-text files.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill presents itself as a Java/LangChain4j integration artifact while documenting an unrelated shell logging utility. This is effectively deceptive documentation, which increases the risk of unsafe use, accidental data exposure, and bypass of normal user scrutiny because operators may not realize they are enabling broad local persistence and export features.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The file content is materially inconsistent with the declared skill metadata: instead of a Java LangChain4j integration, it implements a Bash CLI that captures, stores, searches, and exports user-provided text. This kind of disguised functionality is dangerous because it defeats user/operator expectations and can be used to introduce covert data collection under the cover of a benign-seeming package description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill encourages users to pass arbitrary free-text into commands but does not prominently warn that all such input is written to local plain-text logs and can later be exported or searched. In an LLM workflow context, those inputs can easily contain secrets, proprietary prompts, customer data, or evaluation artifacts, making silent persistence a meaningful confidentiality risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script creates a persistent data directory and records arbitrary user inputs into multiple log files, then provides search and export capabilities over that collected content. In the context of a purported LangChain4j library, this is unjustified data collection behavior and can expose prompts, secrets, internal notes, or other sensitive text entered by users.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool is designed to retain and later reveal user-provided inputs in plaintext via recent/history, search, status, and export operations. Plaintext retention of arbitrary free-form input is dangerous because sensitive data can be exposed to other local users, backup systems, support channels, or anyone with access to the home directory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The export feature aggregates historical logs into JSON, CSV, or text files without clearly warning that prior entries may contain sensitive content. This increases exposure by making bulk extraction of accumulated user data trivial and easy to move, share, or exfiltrate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The command handlers append user-supplied text directly to on-disk logs without a clear, upfront warning that input will be retained. Users may enter API keys, prompts, customer data, or proprietary content believing it is ephemeral, creating an avoidable confidentiality risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The example prompt note includes the phrase "Let me think step by step," which is natural-language guidance associated with eliciting chain-of-thought style reasoning. While not inherently unsafe, embedding this as a recommended example can conflict with organizational policies that discourage requesting hidden reasoning unless the documentation clarifies acceptable use.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.