Back to skill

Security audit

Movie Review

Security checks for vulnerabilities and agentic risk

Overview

This is a local movie-review content logging tool with disclosed on-disk storage, but its advertised scope is broader than what it actually implements.

Install only if you are comfortable with review text and other command inputs being saved under ~/.local/share/movie-review and included in exports. Do not paste secrets or embargoed/private drafts unless you plan to manage or delete those files yourself, and treat CSV/JSON exports cautiously because special characters are not safely escaped.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:64
Finding

Unescaped User Content Enables JSON Structure Injection

Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" ``` ### Technical Analysis The `value` field originates from user-supplied content stored in log files. It is interpolated directly into a JSON string without escaping JSON metacharacters such as double quotes, backslashes, carriage returns, or control characters. An attacker can submit content containing a quote followed by additional JSON syntax. When the data is exported, this content can terminate the intended string and inject fields, objects, or malformed structure into `export.json`. Because the script constructs JSON through `printf` rather than a standards-compliant serializer, the resulting file cannot safely preserve arbitrary user input. ### Attack Path 1. An attacker or untrusted user supplies crafted text to a content command, such as `draft`. 2. The command stores that text verbatim in a log under `~/.local/share/movie-review/`. 3. A user invokes `movie-review export json`. 4. `_export` reads the attacker-controlled value and inserts it directly between JSON quotation marks. 5. The crafted characters alter or invalidate the exported JSON structure. 6. A downstream service that trusts and processes the export may consume attacker-created fields or records, depending on its parsing and validation behavior. ### Impact Assessment The vulnerability does not directly grant shell execution or additional operating-system privileges. Its scope is the integrity and availabi ...[truncated 396 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:75
Finding

CSV Formula Injection and Record Corruption Through Unescaped Export Fields

Content
View full analysis
"$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" ``` ### Technical Analysis The script writes attacker-controlled values directly into CSV records without quoting or escaping them. Values containing commas, double quotes, carriage returns, or line breaks can alter the intended columns or create additional records. More importantly, spreadsheet applications may interpret cells beginning with `=`, `+`, `-`, or `@` as formulas. An attacker can store a formula-like value and cause it to be included verbatim in `export.csv`. If a user opens the exported file in vulnerable or permissively configured spreadsheet software, the formula may be evaluated. The exact formula capabilities vary by spreadsheet product and security configuration. Possible behavior can include deceptive hyperlinks, external data access, or other spreadsheet-supported actions. ### Attack Path 1. An attacker provides content beginning with a spreadsheet formula marker, or content containing CSV delimiters and line breaks. 2. A content command stores the value verbatim in its log file. 3. The user invokes `movie-review export csv`. 4. The exporter appends the unquoted value directly to the CSV record. 5. The user opens or imports `export.csv` in spreadsheet software. 6. The spreadsheet may interpret the attacker-controlled cell as a formula, while delimiter or newline characters may also create unintended fields and records. ### Impact Assessment The script itself does not execute the injected formula and does not grant direct system privileg ...[truncated 486 chars]
Remediation
View remediation
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill’s declared purpose says it handles recommendations, watchlists, spoiler control, and side-by-side film comparison, but the documented behavior instead focuses on generic content-marketing workflows and local persistence/export of user text. This mismatch is security-relevant because users or orchestrators may grant or invoke the skill under false assumptions, causing unexpected data retention and broader-than-expected handling of user content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a movie-focused assistant for reviews, recommendations, watchlists, and spoiler-aware comparisons. However, the exposed commands are generic content operations such as optimize, schedule, hashtags, hooks, cta, translate, tone, headline, and outline, and the code only records arbitrary text to local log files rather than implementing movie review, recommendation, watchlist, or spoiler-control behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description presents the skill as a narrow film-review assistant, while the body documents a broader blogging and content-marketing toolkit including SEO, scheduling, hashtags, hooks, CTAs, translation, and headline generation. Understating scope can mislead users and policy systems about what the skill actually does and what kinds of content it will store and process.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest claims recommendation, watchlist, and spoiler-control capabilities that are not reflected in the documented commands. While not direct code execution risk, this is a trust and safety issue because it creates false expectations and can lead users to rely on nonexistent safeguards or data-management features.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill advertises persistent local storage but does not warn that user-entered review text, prompts, and activity history will be retained on disk. This can expose sensitive or proprietary content to other local users, backups, endpoint tooling, or accidental export without the user realizing retention is happening.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file documents per-command logs, unified history, timestamps, and export formats, but does not caution users that all entered content may be recorded and easily exported. Detailed logging materially increases the risk of unintended disclosure of private drafts, embargoed content, API secrets pasted by mistake, or other sensitive text.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
## When to Use

1. **Drafting a movie review** — use `draft` to capture your initial thoughts, then `edit` and `rewrite` to polish
2. **Preparing social media posts** — use `hashtags`, `hooks`, and `cta` to create engaging content around your review
3. **Planning a review series** — use `outline` to structure your content and `schedule` to plan publishing dates
4. **Optimizing for reach** — use `optimize` for SEO, `headline` for click-worthy titles, and `tone` to match your audience
5. **Tracking your review portfolio** — use `stats` to see totals, `recent` for latest activity, and `export` to back up everything

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The inline documentation says 'Movie Review — content tool' and the help banner says 'content toolkit,' which frames the skill as a general content-production utility rather than a movie-review assistant. This directly conflicts with the manifest's specific intent around film reviews, recommendations, watchlists, and spoiler control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The export function aggregates previously stored logs into new json/csv/txt files without an explicit warning or confirmation, increasing the number of on-disk copies of potentially sensitive user content. That broadens exposure by creating secondary artifacts that may be easier to share accidentally, indexed by backup/sync tools, or left behind after the user believes content exists in only one place.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

User-supplied text is silently persisted to disk in per-command log files and a history log under ~/.local/share/movie-review. In the context of a review-writing skill, users may enter unpublished drafts, personal opinions, account details, or other sensitive content expecting ephemeral processing, so undisclosed retention creates a privacy and data-exposure risk on shared systems or through later compromise of the account.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.