Back to skill

Security audit

Meditation Guide

Security checks for vulnerabilities and agentic risk

Overview

The meditation skill is mostly coherent, but one timer script can run unintended shell commands from a crafted timer argument.

Review before installing. The skill does not show hidden networking, credential access, or malicious persistence, but avoid using the Bash timer with untrusted or generated arguments unless the script is fixed to validate a simple bounded integer. Be aware that session history is stored locally and that intense breathing exercises should be treated cautiously, especially for users with relevant medical conditions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:97
Finding

Arbitrary Command Execution Through Unsafe Bash Arithmetic Expansion

Content
View full analysis
" echo 'Meditation timer: ${2:-10} minutes'; echo 'Starting...'; sleep $((${2:-10}*60)) 2>/dev/null && echo 'Session complete' } ``` ### Technical Analysis The timer argument is inserted directly into a Bash arithmetic expansion: ```bash $((${2:-10}*60)) ``` Bash arithmetic expressions do not accept only integer literals. They can resolve variable and array expressions, and crafted array subscripts can trigger command substitution during evaluation. Because the value is not validated as a bounded decimal integer before arithmetic evaluation, an attacker-controlled argument can cause arbitrary shell commands to execute. There is also an argument-indexing error. The dispatcher shifts the command name before calling `cmd_timer`: ```bash timer) shift; cmd_timer "$@" ;; ``` After this shift, the documented `timer ` value is available as `$1`, but `cmd_timer` reads `$2`. Consequently, an ordinary invocation does not work as intended, while a crafted additional argument can reach the vulnerable arithmetic expression. ### Attack Path 1. An attacker supplies arguments to the documented `scripts/script.sh timer` command. 2. `main` removes the `timer` command name with `shift`. 3. `cmd_timer` incorrectly reads its second argument rather than its first. 4. The attacker places a crafted Bash arithmetic expression in that second argument, such as an array expression containing a command substitution. 5. The value is interpolated into `$((${2:-10}*60))`. 6. Bash evaluates the command substitution while parsing the arithmetic expression. 7. The injected command runs with the same operating-system identity, environment, filesystem access, and privileges as the Skill process. ## ...[truncated 662 chars]
Remediation
View remediation
= 1 && 10#$minutes <= 1440 )) || die "Minutes must be between 1 and 1440" ``` 4. Perform arithmetic only after validation, explicitly treating the input as base 10: ```bash local seconds=$((10#$minutes * 60)) sleep "$seconds" ``` 5. Keep expansions quoted when passed to commands and avoid placing unvalidated external input directly inside arithmetic, conditional, or indirect variable expressions. A hardened implementation would be: ```bash cmd_timer() { local minutes="${1:-}" [ -z "$minutes" ] && die "Usage: $SCRIPT_NAME timer " [[ "$minutes" =~ ^[0-9]+$ ]] || die "Minutes must be a positive integer" (( 10#$minutes >= 1 && 10#$minutes <= 1440 )) || die "Minutes must be between 1 and 1440" local seconds=$((10#$minutes * 60)) echo "Meditation timer: $minutes minutes" echo "Starting..." sleep "$seconds" echo "Session complete" } ``` Add regression tests covering valid integers, missing arguments, negative values, very large values, nonnumeric input, arithmetic syntax, array syntax, and command-substitution payloads. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/meditate.sh (reported line 37)May include surrounding context.

sh
"mindfulness": {"duration": 5, "steps": [
        "Sit comfortably. Close your eyes.",
        "Focus on your breath. In... Out...",
        "When thoughts arise, notice them without judgment.",
        "Label them: thinking, planning, remembering...",
        "Gently return focus to your breath.",
        "Notice sounds around you. Accept them.",

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · scripts/meditate.sh (reported line 67)May include surrounding context.

sh
}

PROMPTS = [
    "What am I feeling right now, without judging it?",
    "What would I do today if fear were not a factor?",
    "Name three things I can see, hear, and feel right now.",
    "What am I holding onto that I can release?",

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes the 'Wim Hof Method' and other breath-control techniques without any safety warning, contraindications, or advice to stop if dizzy. In a wellness context, users may attempt potentially stressful breathing exercises despite underlying medical conditions, which can create real physical safety risk.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 9)May include surrounding context.

sh
DATA_DIR="$HOME/.local/share/meditation-guide"
mkdir -p "$DATA_DIR"

#
#
#
#

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The natural-language title mixes English with Chinese ("冥想与正念工具") without indicating whether the skill is intended specifically for Chinese-speaking users or offering a language/locale option. This can conflict with language policy expectations when a skill implicitly forces or assumes a language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script appends meditation session metadata to $HOME/.local/share/meditation-guide/sessions.jsonl, creating a persistent local history. While the command name suggests session tracking, there is no confirmation prompt, warning, or explanatory comment near the write operation to disclose that user activity will be stored on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.