Back to skill

Security audit

Nda Generator

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly looks like an NDA template generator, but it also includes an unrelated utility script that silently stores user-entered text in persistent plaintext files.

Review this skill before installing if you may enter real party names, deal details, or confidential business information. The NDA generation script itself outputs templates locally, but the bundled nda-generator utility can retain arbitrary input in plaintext local files and does not provide clear deletion, redaction, or opt-in controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Plaintext Persistent Storage of Potentially Confidential User Input

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:5-7, scripts/script.sh:32, scripts/script.sh:55-57, and scripts/script.sh:77-80
Vulnerability Type: Plaintext storage and logging of potentially sensitive data
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${NDA_GENERATOR_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/nda-generator}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}
bash
case "${1:-help}" in
    run) shift; cmd_run "$@" ;;
    config) shift; cmd_config "$@" ;;
    status) shift; cmd_status "$@" ;;
    init) shift; cmd_init "$@" ;;
    list) shift; cmd_list "$@" ;;
    add) shift; cmd_add "$@" ;;
    remove) shift; cmd_remove "$@" ;;
    search) shift; cmd_search "$@" ;;
    export) shift; cmd_export "$@" ;;
    info) shift; cmd_info "$@" ;;
    help|-h) show_help ;;
    version|-v) echo "nda-generator v$VERSION" ;;
    *) echo "Unknown: $1"; show_help; exit 1 ;;
esac

Technical Analysis

The generic add command appends all supplied arguments to data.log. It then passes the first argument to _log, which appends that value to history.log. Both files are persistent and stored beneath a user-controlled or default data directory.

The code does not apply data classification, sensitive-value redaction, retention limits, encryption, or explicit restrictive file permissions. Consequently, resulting permissions depend on the invoking process's umask and pre-existing directory state. The directory can also be redirected through NDA_GENERATOR_DIR.

This storage functionality is not necessary for generating NDA text and is especially risky in the context of an NDA utility, where supplied arguments may includ ...[truncated 1807 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove scripts/script.sh if its generic persistent data-store functionality is not required for NDA generation.

  2. If persistence is necessary, make it explicit and opt-in. Inform users exactly which values will be retained before writing them.

  3. Do not log NDA content, party identities, secrets, credentials, or unrestricted command arguments. Use an allowlist of non-sensitive metadata and redact sensitive values.

  4. Create private storage with restrictive permissions:

    bash
    umask 077
    install -d -m 700 -- "$DATA_DIR"
    touch -- "$DB" "$DATA_DIR/history.log"
    chmod 600 -- "$DB" "$DATA_DIR/history.log"
    
  5. Validate NDA_GENERATOR_DIR before use and reject unsafe or unexpected destinations where appropriate.

  6. Add configurable retention limits and a command that reliably deletes retained records. Clearly document that backups may preserve deleted data.

  7. Avoid exposing sensitive records through unrestricted list, search, or export operations. Require explicit confirmation or access controls when the execution environment supports them.

  8. Add automated tests verifying restrictive permissions, redaction behavior, opt-in persistence, and safe handling of sensitive arguments.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest says "Use when you need nda generator capabilities" and "Triggers on: nda generator," which does not clearly define specific activation phrases or limits. The surrounding description also repeats broad terms like "保密协议" and "NDA," increasing the chance of unintended invocation from ordinary mentions rather than explicit requests to run the skill.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The identifier nda-generator suggests a document-generation tool for NDAs, but the documented behavior is 'Multi-purpose utility tool' with commands for adding, listing, searching, and exporting log-style entries. The implemented functions also only store and retrieve arbitrary text records, which contradicts the apparent intent conveyed by the tool name and documentation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The logging function writes user-supplied command arguments to a persistent history file under the user’s data directory without any disclosure or consent prompt. This can unintentionally retain sensitive data such as names, search terms, or confidential text entered by the user, increasing privacy and local data exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The add command appends arbitrary user input directly into a persistent local database file with no explicit notice that the content will be stored. In the context of a tool named like an NDA generator, users may reasonably enter sensitive contractual or business information, making silent retention more dangerous due to confidentiality expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description forces a bilingual Chinese/English presentation in the natural-language skill text, but it does not state whether the user can choose their preferred language. Under the policy, language behavior should be user-selectable or clearly justified when a specific locale or language is imposed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This shell script contains natural-language and default behavior that steer users toward a specific locale and jurisdiction: the help text advertises a default of the People's Republic of China, the parser sets that as the default governing law, and the generated agreement is formatted bilingually in English and Chinese. Under the policy, forcing a specific language or locale without user opt-in can be a natural-language policy violation unless clearly justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/nda.sh (reported line 113)May include surrounding context.

sh
1.1 "Confidential Information" means any and all non-public information,
    whether in written, oral, electronic, visual, or other form, disclosed
    by either Party (the "Disclosing Party") to the other Party (the
    "Receiving Party"), including but not limited to:

    (a) Trade secrets, inventions, patents, copyrights, trademarks, and
        other intellectual property;

Scope Creep

Low
Category
Excessive Agency
Confidence
70% confidence
Finding

Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.

Content

Scanner excerpt · scripts/nda.sh (reported line 321)May include surrounding context.

sh
1.1 "Confidential Information" means any and all non-public information,
    whether in written, oral, electronic, visual, or other form, disclosed
    by either Party (the "Disclosing Party") to the other Party (the
    "Receiving Party"), including but not limited to:

    (a) Trade secrets, inventions, patents, copyrights, trademarks, and
        other intellectual property;

Static analysis

No suspicious patterns detected.