Back to skill

Security audit

Baby Guide

Security checks for vulnerabilities and agentic risk

Overview

This baby-care skill is not obviously malicious, but it needs review because it includes high-stakes pediatric medical guidance and an unrelated helper that silently stores command history locally.

Review carefully before installing. The main baby-care references may be useful for general information, but do not rely on this skill for pediatric diagnosis, medication decisions, emergency triage, vaccine timing, allergies, or feeding problems without a qualified clinician. Also be aware that the bundled design helper can write command arguments to a local history file under the baby-guide data directory.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:4
Finding

Undocumented Persistent Logging of Caller-Supplied Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:4-7, 35-84
Vulnerability Type: Undocumented plaintext logging to a caller-configurable path
Risk Level: Medium

Vulnerable Code

bash
VERSION="2.0.0"
DATA_DIR="${BABY_GUIDE_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/baby-guide}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

cmd_palette() {
    echo "  Primary: #2563EB | Secondary: #7C3AED | Accent: #F59E0B"
    _log "palette" "${1:-}"
}

cmd_font() {
    echo "  Heading: Inter/Poppins | Body: Open Sans/Lato"
    _log "font" "${1:-}"
}

cmd_layout() {
    echo "  Grid: 12-col | Spacing: 8px base | Max-width: 1200px"
    _log "layout" "${1:-}"
}

cmd_icon() {
    echo "  Libraries: Heroicons | Lucide | Phosphor | Tabler"
    _log "icon" "${1:-}"
}

cmd_spacing() {
    echo "  xs:4 sm:8 md:16 lg:24 xl:32 2xl:48"
    _log "spacing" "${1:-}"
}

cmd_breakpoint() {
    echo "  sm:640 md:768 lg:1024 xl:1280 2xl:1536"
    _log "breakpoint" "${1:-}"
}

cmd_contrast() {
    echo "  Check: webaim.org/resources/contrastchecker"
    _log "contrast" "${1:-}"
}

cmd_shadow() {
    echo "  sm: 0 1px 2px | md: 0 4px 6px | lg: 0 10px 15px"
    _log "shadow" "${1:-}"
}

cmd_mockup() {
    echo "  Tool: Figma | Sketch | Adobe XD"
    _log "mockup" "${1:-}"
}

cmd_checklist() {
    echo "  [ ] Consistent spacing | [ ] Color contrast | [ ] Mobile responsive"
    _log "checklist" "${1:-}"
}

Technical Analysis

The script creates a persistent data directory on every invocation and appends command arguments to history.log. This behavior is not disclosed in the documented baby-care functionality, and the script itself provides unrelated UI design commands.

Raw arguments are written in plaintext without filtering, retention controls, restrictive permissi ...[truncated 2452 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove scripts/script.sh from the package because its design-reference behavior is unrelated to the documented baby-care skill.
  2. If the script is intentional, document its purpose, filesystem effects, log destination, logged fields, and retention policy.
  3. Disable logging by default and require explicit user opt-in.
  4. Do not record raw caller-supplied arguments. Log only a fixed command identifier when operational telemetry is genuinely required.
  5. Validate and canonicalize BABY_GUIDE_DIR; reject unexpected, relative, or untrusted destinations.
  6. Create the data directory with restrictive permissions, such as mode 0700, and create logs with mode 0600.
  7. Refuse to write when the destination is a symbolic link or is not a regular file. Use safe file-opening semantics that prevent symbolic-link following where supported.
  8. Define a bounded retention policy and provide a command that allows users to inspect and delete stored history.
  9. Add tests confirming that ordinary execution does not modify the filesystem unless logging has been explicitly enabled.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance says to use the skill for broad baby-care topics such as development, feeding, education, and vaccines, without clear limits on when the assistant should defer to professional medical advice. In a parenting context, this can cause the agent to over-invoke the skill for health-related questions and present generalized guidance where individualized medical judgment is needed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

All help text, prompts, and guidance are presented exclusively in Chinese, with no option for the user to choose another language or locale. The policy allows locale constraints only when user choice is offered or the regional limitation is clearly documented and justified, which is not present here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script provides detailed pediatric home-treatment and medication guidance, including dosing conditions by age, symptom triage, and emergency handling steps, before clearly establishing that it is not medical advice. In this context, users may rely on the tool during stressful childcare situations and delay professional care, misapply medications, or follow unsafe instructions, especially because some guidance is clinically specific and presented authoritatively.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The descriptive and operational guidance is primarily written in Chinese, and the commands and examples are framed around Chinese-language use without offering a language choice. This can create a locale/language policy issue if the skill implicitly assumes Chinese output or interaction for all users.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script presents itself as a simple design reference tool, but every functional command silently records usage data to a local history file. While this is only local logging, undisclosed collection of user activity can expose sensitive project names or workflow details passed as arguments and creates a privacy issue inconsistent with the tool’s stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The _log function writes command names and arguments to a history file without any user-facing notice or consent. Even though the log stays local, arguments may contain sensitive information, and silent persistence increases the risk of unintended disclosure to other local users, backups, or support artifacts.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents all user-facing guidance in Chinese, including the title and numbered tips, but does not indicate that the skill is intended only for Chinese-speaking users or provide any language/locale opt-in. This can violate language/locale policy where users are expected to retain language choice unless the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.