Back to skill

Security audit

Proofreader

Security checks for vulnerabilities and agentic risk

Overview

This proofreader includes a matching proofreading prompt script, but it also ships an unrelated local data-storage CLI that can retain user text without clear disclosure.

Review this package before installing. The proofreading prompt script appears benign, but the bundled generic script can persist text locally in plaintext and the documentation does not clearly explain that behavior. Avoid using it with sensitive drafts unless the generic storage script is removed or the package clearly scopes and discloses local retention.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:34
Finding

Undocumented Plaintext Retention of User-Supplied Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 6-8, 34, 36-39, and 62-65
Vulnerability Type: Undocumented plaintext storage of potentially sensitive input
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${PROOFREADER_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/proofreader}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
cmd_run() {
    echo "  Running: $1"
    _log "run" "${1:-}"
}
bash
cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

Technical Analysis

The script creates a persistent data directory whenever it starts. Its logging function then appends command names and user-supplied arguments to history.log without obtaining consent or filtering sensitive content. The add command additionally writes all supplied arguments to data.log.

This behavior is not disclosed in SKILL.md, which presents the project as a proofreading utility. Users may consequently provide confidential documents, personal information, or proprietary text without expecting command arguments to be retained.

The files are created using permissions determined by the caller's current umask; the script does not establish a restrictive mode such as owner-only access. The content is stored in plaintext and has no defined retention period. Generic list, search, and export commands can subsequently expose the stored data.

Attack Path

  1. A user invokes scripts/script.sh and supplies sensitive text to run or add.
  2. For run, the first argument is passed to _log and appended to history.log.
  3. For add, all arguments are appended to data.log, and the first argument is also written to history.log.
  4. The plaintext data remains under the configured PROOFREADER_DIR or the default ...[truncated 831 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove scripts/script.sh if it is not required for the documented proofreading functionality.
  2. Do not record raw document text or command arguments. Log only non-sensitive operational metadata when logging is necessary.
  3. Make all data retention explicit, documented, and opt-in rather than enabled by default.
  4. Establish restrictive permissions before creating files, for example with umask 077, and verify that the data directory and files are accessible only to their owner.
  5. Provide commands to inspect and securely delete retained information, together with a clearly defined retention period.
  6. Warn users before storing any supplied content and distinguish temporary processing from persistent storage.
  7. If persistent storage is genuinely required, minimize collected data and consider encryption appropriate to the threat model.
  8. Align the documented command set in SKILL.md with the actual executable behavior so users can make an informed decision before supplying sensitive content.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for proofreading and language-quality analysis. However, the code implements a generic command-line data manager with commands like add, list, search, export, status, and config, storing entries in local files under a data directory and logging activity. There is no logic for typo detection, grammar correction, style normalization, consistency checks, readability scoring, or proofreading reports. The primary purpose is materially different from the declared one, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script does not implement proofreading functionality at all; instead it behaves as a generic local data collection and logging utility. This mismatch is dangerous because users may provide sensitive text for proofreading while the tool silently stores inputs and metadata on disk, creating a trust-boundary violation and enabling deceptive data harvesting under a misleading skill identity.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The examples use generic commands like 'proofreader run' without showing required arguments, scope limitations, or what content will be processed. In agent ecosystems, underspecified broad invocation patterns can cause unintended triggering or execution against overly large or ambiguous inputs, increasing the chance of misuse or user confusion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script emits user-facing proofreading prompts and help text primarily in Chinese, which effectively forces a specific language experience. The file does not provide any opt-in, language selection mechanism, or justification that the skill is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The embedded documentation labels the tool as a 'Multi-purpose utility tool', which directly contradicts the advertised proofreader skill. In security-sensitive ecosystems, identity mismatch is a red flag because it obscures actual behavior and can mislead users into invoking a tool with expectations that do not match its real data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The logging helper writes command names and user-supplied arguments to a persistent history file without any user-facing notice. In the context of a purported proofreading skill, users may submit private drafts, credentials, or internal text for correction, so silent retention materially increases confidentiality risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The add operation appends arbitrary user input directly to a local data file, again without clear disclosure that submitted content is being stored. Because the advertised use case suggests users will input natural-language documents, this can unintentionally create a local repository of sensitive text that the user did not expect to persist.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The skill description and content are presented bilingually, but the file does not explain whether outputs will be in Chinese, English, or based on user preference. This can violate language/locale expectations because the skill appears to impose or default to specific languages without an explicit opt-in or selection mechanism.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file includes a Chinese-language section and Chinese-specific error guidance, but it does not state that the user can choose a language or that the content is intentionally limited to Chinese. Under the policy rule for language or locale constraints, forcing a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.