Back to skill

Security audit

cognitive-enhancement-engine

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a local Python memory/planning engine, but its setup script silently makes a persistent shell-profile change with unsafe quoting.

Install the Python engine only if you are comfortable reviewing setup.sh first. Prefer copying or importing engine.py directly, or manually adding any launcher command yourself instead of running the one-click setup until the shell-profile modification is made explicit, opt-in, and safely escaped.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:42
Finding

Unsafe Persistent Shell-Profile Modification Allows Command Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/setup.sh, lines 42–50
Vulnerability Type: Persistent shell-profile command injection
Risk Level: Medium

Vulnerable Code

bash
SHELL_RC="$HOME/.bashrc"
[ -f "$HOME/.zshrc" ] && SHELL_RC="$HOME/.zshrc"

ALIAS_CMD="alias cognitive-enhance='cd $DIR && $PYTHON -c \"import sys; sys.path.insert(0, \\\"$DIR\\\"); from engine import CognitiveEnhancer; b = CognitiveEnhancer(); print(\\\"Cognitive Enhancement Engine loaded. Use b.perceive(), b.memorize(), b.recall() etc.\\\"); import code; code.interact(local=dict(b=b))\"'"

if ! grep -q "cognitive-enhance" "$SHELL_RC" 2>/dev/null; then
    echo "$ALIAS_CMD" >> "$SHELL_RC"
    echo "  Alias 'cognitive-enhance' added to $SHELL_RC"

Technical Analysis

The setup script automatically modifies the user's .bashrc or .zshrc, even though the action is described as optional. This modification is not required to install or verify the library and persists beyond the setup process.

The values of $DIR and $PYTHON are interpolated directly into executable shell-profile content without shell-safe escaping. In particular, $DIR is derived from the package's installation path. If that path contains quotes, command substitutions, or other shell metacharacters, it can break out of the intended alias syntax and inject additional commands into the profile.

The use of double quotes while constructing ALIAS_CMD does not safely serialize these values for later interpretation by another shell. The generated profile entry consequently crosses two parsing boundaries: first during setup and again whenever the shell profile is loaded.

Attack Path

  1. An attacker distributes or places the project in a directory whose path contains carefully constructed shell syntax.
  2. The victim follows the documented installation instruction and runs bash scripts/setup.sh.
  3. The script obtains the crafted directory through BASH_SOURCE[0] and places it in $DIR. 4 ...[truncated 938 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not modify .bashrc, .zshrc, or another startup file during the default setup process.
  2. Print an optional alias command for the user to inspect and install manually, or require explicit confirmation before making any persistent change.
  3. Serialize all dynamic values using robust shell escaping, such as printf '%q', before writing them into shell code.
  4. Use safe runtime quoting in the generated command, including cd -- "$DIR".
  5. Prefer a dedicated executable wrapper in a user-selected directory over injecting an alias into a shell profile.
  6. If profile integration remains supported, write a clearly marked block, create a backup, use an exact marker to detect prior installation, and provide an uninstall command.
  7. Add automated tests using installation paths containing spaces, single quotes, double quotes, command substitutions, semicolons, and newline characters.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description presents the package as a pure Python cognitive engine with no notable side effects, while installation/setup behavior reportedly modifies shell startup files and creates persistent aliases. That hidden persistence behavior can mislead users into executing setup with broader trust than warranted, creating a supply-chain and environment-tampering risk, especially because the side effect is not disclosed in the skill metadata.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description presents the package as a pure Python cognitive engine with no notable side effects, while installation/setup behavior reportedly modifies shell startup files and creates persistent aliases. That hidden persistence behavior can mislead users into executing setup with broader trust than warranted, creating a supply-chain and environment-tampering risk, especially because the side effect is not disclosed in the skill metadata.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module title and descriptive text are presented entirely in Chinese, and the file contains no natural-language indication that language selection is optional or limited to a China-specific deployment. Under the policy, forcing a specific language or locale without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The guide tells users to execute local setup scripts (bash scripts/setup.sh / setup.bat) directly, but provides no description of what those scripts change, what privileges they require, or any recommendation to inspect them first. This increases supply-chain and social-engineering risk because users may run repository-provided code on their systems without understanding its behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The setup script appends an alias to the user's shell startup file automatically, without an explicit confirmation prompt. Modifying persistent shell configuration is security-sensitive because it changes future command behavior and can create lasting trust in code execution paths; if the directory contents are later altered, the alias will continue invoking Python from that location.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The header says this file is metadata-only and describes a 'Pure Python engine', yet the module is itself JavaScript/Node.js code that exposes operational fields like run/test commands and Python usage examples. This is a documentation-level contradiction about what the file is and does, even though the runtime behavior remains low risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

该 markdown 文件的标题和全部说明内容均以中文固定呈现,未见提供用户语言选择、双语支持或明确说明该文档仅适用于特定中文使用场景。根据规则,强制特定语言而无用户选择可构成自然语言层面的语言/地区策略问题。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

A language/locale policy issue exists when a skill or its instructions force a specific language without user opt-in. This usage guide appears entirely in Chinese and does not provide an alternative language option or explain that the skill is intended only for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module docstring at L01 is written in Chinese, and the surrounding natural-language comments and user-facing strings in the file are also Chinese-only. Under the policy rule, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.