Back to skill

Security audit

Notification

Security checks for vulnerabilities and agentic risk

Overview

This skill is presented as a terminal notification manager, but the shipped script mainly stores arbitrary command inputs in local log files and does not implement the advertised scheduling, alert delivery, filtering, or delivery tracking.

Review this carefully before installing. It should not be relied on for real alerts, scheduled notifications, filtering, or delivery confirmation. Treat it as a local plaintext logging utility, avoid entering secrets or sensitive notification content, and inspect or remove ~/.local/share/notification if you test it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Notification Content Stored in Plaintext with Potentially Permissive Filesystem Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:5-8, with user-controlled logging sinks at scripts/script.sh:135-142 and equivalent command handlers through line 289
Vulnerability Type: Insecure storage of potentially sensitive data
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${HOME}/.local/share/notification"
mkdir -p "$DATA_DIR"

_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

A representative command handler stores the supplied content twice:

bash
local input="$*"
local ts=$(date '+%Y-%m-%d %H:%M')
echo "$ts|$input" >> "$DATA_DIR/run.log"
local total=$(wc -l < "$DATA_DIR/run.log")
echo "  [Notification] run: $input"
echo "  Saved. Total run entries: $total"
_log "run" "$input"

The same storage pattern is repeated for the check, convert, analyze, generate, preview, batch, compare, export, config, status, and report handlers.

Technical Analysis

The script creates its data directory and log files without explicitly enforcing restrictive filesystem permissions. Their resulting modes depend on the invoking process's umask. For example, a permissive or common 022 umask can create the directory as mode 0755 and newly redirected log files as mode 0644, allowing other local users to traverse the directory and read notification records.

Arbitrary command arguments are retained in plaintext in a command-specific log and duplicated in history.log. Because notification content may include user messages, operational details, identifiers, or other private information, relying on ambient umask settings violates least-privilege storage principles.

The issue is conditional on the effective filesystem permissions and local account separation. The script does not transmit this information over a network and does not grant an attacker elevated privileges.

Attack Path

  1. A user runs a command conta ...[truncated 1095 chars]
Remediation
View remediation

Remediation Suggestions

  1. Set a restrictive process umask before creating any storage:

    bash
    umask 077
    
  2. Create and verify the data directory with owner-only permissions:

    bash
    install -d -m 700 -- "$DATA_DIR"
    chmod 700 -- "$DATA_DIR"
    
  3. Create log files with mode 0600 before appending data:

    bash
    touch -- "$DATA_DIR/history.log"
    chmod 600 -- "$DATA_DIR/history.log"
    

    Apply the same protection to every command-specific log.

  4. Avoid duplicating complete user input in history.log. Record only the event type and timestamp, or store a redacted summary.

  5. Add configurable retention limits and a command that securely removes stored history.

  6. Warn users that supplied arguments are persisted locally, and advise against passing credentials, access tokens, or other secrets.

  7. On startup, validate that the data directory is owned by the current user, is not an unexpected symbolic link, and is not accessible to group or other users. Refuse operation or repair permissions when validation fails.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises notification features such as scheduling, alert sending, filtering, and delivery tracking, but the documented behavior is largely generic local logging/search/export. This mismatch can mislead an agent or user into selecting the skill for operational notification tasks it cannot actually perform, causing silent failure of alerts, missed monitoring events, or incorrect trust in delivery/confirmation behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes notification-specific behavior such as scheduling, filtering, sending alerts, and delivery tracking. In contrast, the help text advertises broad utility-style commands, and the implementation merely stores arbitrary input strings into per-command log files without any notification delivery or scheduling logic.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Each command branch just appends user input to a local .log file and echoes it back, which is materially different from managing terminal notifications. There is no code for dispatching notifications, scheduling future alerts, filtering notification objects, or confirming delivery status.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is too vague to establish clear operational boundaries, making it easier for an agent to invoke it in the wrong context. In security-sensitive workflows, ambiguous scope can lead to misuse, incorrect assumptions about side effects, and reliance on a tool that does not meet the task's requirements.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Commands such as run, check, convert, analyze, generate, preview, batch, and compare are generic and undocumented, so an agent cannot reliably infer their inputs, outputs, or side effects. Ambiguous command names increase the chance of unintended execution paths, accidental data modification, or misuse in place of more appropriate tools.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The top-of-file comments identify this as a notification utility, which implies notification-centric behavior. However, the code implements arbitrary command logging for unrelated operations and does not perform notification management functions, creating an intent-to-code contradiction rather than mere incompleteness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Commands such as convert, analyze, generate, batch, compare, report, and config suggest a multi-purpose toolkit rather than a notification-focused skill. Those capabilities are not an obvious requirement for sending alerts, filtering notifications, or confirming delivery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The export function aggregates all prior logged content into json/csv/txt files on disk, potentially duplicating sensitive historical inputs into new artifacts without user awareness. This expands the exposure surface because confidential data may persist in multiple files, formats, and backup paths, making accidental disclosure more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-provided input is persistently written to local log files under the user's home directory with no warning, minimization, or consent controls. In a skill presented as a notification tool, users may enter sensitive message contents, tokens, or operational details, causing unintended long-term local disclosure to anyone with access to the account or backups.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.