Back to skill

Security audit

Survey

Security checks for vulnerabilities and agentic risk

Overview

This skill looks like a local plaintext command logger presented as a survey builder, so users should review it before installing.

Review this as a local plaintext logging utility rather than a full survey tool. Avoid entering sensitive personal, customer, health, financial, or confidential survey data unless you are comfortable with it being stored under ~/.local/share/survey and potentially exported into local files. The artifact does not show exfiltration or destructive behavior, but its advertised capabilities and persistence behavior are under-scoped.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:6
Finding

Survey responses may be stored with overly permissive filesystem permissions

Content
View full analysis
> "$DATA_DIR/history.log"; } ``` A representative response-writing path is: ```bash run) shift if [ $# -eq 0 ]; then echo "Recent run entries:" tail -20 "$DATA_DIR/run.log" 2>/dev/null || echo " No entries yet. Use: survey run " else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/run.log" local total=$(wc -l < "$DATA_DIR/run.log") echo " [Survey] run: $input" echo " Saved. Total run entries: $total" _log "run" "$input" fi ``` The same storage pattern is repeated for other commands in lines 148-289. ### Technical Analysis The script creates its data directory and log files without establishing restrictive permissions. File and directory modes therefore depend on the invoking process's `umask`. With a common `umask` of `022`, the directory may be created as `0755` and newly created log files as `0644`. Command input is written in plaintext both to command-specific logs and to `history.log`. Because the project is presented as a survey utility, this input may include responses, reports, or other personal or confidential information. On a multi-user system, permissive modes can allow other local accounts to read that information. Exploitation is conditional on the effective filesystem permissions and the attacker already having local access. The code does not itself provide remote access or privilege escalation. ### Attack Path 1. A user runs a command containing confidential survey informa ...[truncated 805 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a survey/form management capability, but the code implements a generic command logger around survey-themed verbs. Most commands simply append the provided CLI text to corresponding .log files in ~/.local/share/survey and record activity in history.log. The only substantive functions are basic stats, text search, recent history, health/status output, and exporting logs to JSON/CSV/TXT. There is no functionality for creating survey schemas, rendering forms, validating or collecting structured responses, or performing meaningful trend analysis on survey data. The primary purpose is therefore materially different from the declared survey-building and response-analysis description.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description says to use the skill for broad activities like "analyzing trends" and "generating reports," which overlap with common, non-survey-specific tasks. It does not define constraints or exclusion conditions, so the activation scope may be wider than intended.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The help output claims commands like "export ", "search ", "recent", and "status" provide concrete utility behavior. However, the case statement already handles export at L243-L257 and status at L273-L287 as simple log-appending commands, so the later branches at L304-L307 that would call _export and _status are never reached, contradicting the documented intent of those commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The export function aggregates all locally stored activity logs into new export files, potentially duplicating and broadening exposure of sensitive data without warning. Because this skill presents itself as a survey tool, exported content may include survey responses or other user-entered material, increasing the chance of unintended disclosure through file sharing, sync, or later processing.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest describes a skill for building surveys, collecting responses, converting data, analyzing trends, and generating reports. In practice, the command handlers merely append raw user input strings to per-command log files and echo them back, with no code for creating forms, collecting structured responses, or performing meaningful survey analysis/report generation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script persistently stores arbitrary user-supplied input in plaintext log files under the user's home directory without clear notice or consent. In a survey-related context, users may provide sensitive response content, identifiers, or internal data, creating a privacy and confidentiality risk if the workstation is shared, backed up, or later accessed by other tools/users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The documentation states that data is stored in a local directory but does not warn that survey content and responses may contain sensitive personal or confidential information. This can lead users to store regulated or private data on disk without informed consent or retention expectations, increasing risk of unintended disclosure on shared or unmanaged systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.