Back to skill

Security audit

Paraphraser

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly presents itself as a paraphrasing helper, but it also ships an unrelated local data-management script that silently stores user input.

Review this skill before installing. The paraphrasing prompt script is consistent with the advertised purpose, but the package also includes a generic data logger/export tool that can retain text locally. Avoid passing sensitive drafts, credentials, proprietary text, or personal data to the paraphraser command unless the publisher removes or clearly documents the storage behavior and implements real deletion and retention controls.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Undisclosed Plaintext Persistence of User-Supplied Arguments

Content
View full analysis
> "$DATA_DIR/history.log"; } cmd_run() { echo " Running: $1" _log "run" "${1:-}" } cmd_config() { echo " Config: $DATA_DIR/config.json" _log "config" "${1:-}" } cmd_status() { echo " Status: ready" _log "status" "${1:-}" } cmd_init() { echo " Initialized in $DATA_DIR" _log "init" "${1:-}" } cmd_list() { [ -f "$DB" ] && cat "$DB" || echo " (empty)" _log "list" "${1:-}" } cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } cmd_remove() { echo " Removed: $1" _log "remove" "${1:-}" } cmd_search() { grep -i "$1" "$DB" 2>/dev/null || echo " Not found: $1" _log "search" "${1:-}" } cmd_export() { [ -f "$DB" ] && cat "$DB" || echo "No data" _log "export" "${1:-}" } cmd_info() { echo " Version: $VERSION | Data: $DATA_DIR" _log "info" "${1:-}" } ``` ### Technical Analysis The script creates persistent storage under the invoking user's data directory and records command arguments in plaintext. The `_log` function appends the first argument supplied to most commands to `history.log`. The `add` command additionally writes all supplied arguments to `data.log`. This persistence is not disclosed in `SKILL.md` and is unrelated to the skill's principal text-paraphrasing functionality. Text processed by a paraphrasing tool may contain confidential, personal, academic, or proprietary information. The implementation provides no consent mechanism, content filtering, retention limit, encryption, or explicit restrictive file-permission setu ...[truncated 2014 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill paraphrases and rewrites text in various styles. The supplied code does not implement any text transformation. Instead, it is a multi-purpose command-line data logger/manager that creates a local data directory, stores entries in a log file, lists/searches/exports them, and records command history. This is a materially different primary purpose and includes undeclared capabilities around local persistence and record management.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script's implemented behavior is materially inconsistent with the declared skill purpose. Instead of paraphrasing text, it provides a generic local data-management CLI with storage, search, and export capabilities, which creates an unjustified ability to collect and expose user data under a misleading skill identity. In skill ecosystems, capability mismatch is dangerous because users and reviewers may grant trust or sensitive input based on the advertised purpose.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The FAQ says the tool is suitable for '任何需要paraphraser的人' ('anyone who needs a paraphraser'), which is an extremely broad activation description with no limiting context or exclusion conditions. For a markdown skill description, this can contribute to unintended invocation because it does not define when the skill should or should not be used.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script's user-facing natural-language instructions and help output are written in Chinese throughout, including command descriptions and generated prompts. Because the skill does not offer any language selection or opt-in mechanism, it effectively forces a specific language/locale on all users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The inline description explicitly labels the tool as a 'Multi-purpose utility tool,' contradicting the stated paraphraser identity. This inconsistency is a security concern because deceptive or ambiguous documentation can conceal broader functionality and impair user consent, review accuracy, and policy enforcement. In this context, the mismatch increases suspicion rather than reducing it.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill creates a persistent data directory, stores records in local files, and supports exporting them, none of which is justified by a text-rewriting use case. Persistent storage of user-supplied content expands the attack surface for privacy leakage, unintended retention, and later exfiltration, especially when users may submit sensitive text for paraphrasing. The misleading context makes this more dangerous because users would not reasonably expect archival behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The logging function persists command arguments to history.log without any notice, and multiple commands pass user input into that log. For a paraphrasing skill, inputs may contain drafts, personal data, credentials, or proprietary text, so silent retention creates a meaningful confidentiality risk even without network exfiltration. The skill context makes this more dangerous because users are likely to paste sensitive content expecting ephemeral text transformation, not auditing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file contains user-facing guidance entirely in Chinese, beginning at the section heading on L03 and continuing through the rest of the document. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.