Back to skill

Security audit

Bookmark Keeper

Security checks for vulnerabilities and agentic risk

Overview

This is a local command-line logger for bookmarks and productivity notes; its broader logging behavior is disclosed, but users should treat its plaintext stored data and exports carefully.

Install only if you are comfortable with the skill keeping bookmarks, plans, reminders, reviews, and similar notes as plaintext files under ~/.local/share/bookmark-keeper. Avoid storing secrets or highly sensitive personal data, and be careful opening CSV exports in spreadsheets because exported values are not safely encoded.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:64
Finding

Unescaped User Input Allows JSON Export Injection

Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" ``` ### Technical Analysis The application inserts log data directly into a JSON document using string formatting. The `val` field originates from user-controlled command arguments and is not JSON-escaped before serialization. Shell quoting prevents shell command injection at this location, but it does not provide JSON encoding. Characters such as double quotes, backslashes, carriage returns, newlines, and control characters can therefore invalidate the generated document or modify its logical structure. For example, a value containing closing quotes and additional JSON syntax can introduce fabricated fields or records into the export. Any downstream program that treats the exported document as trusted structured data may process attacker-created content. ### Attack Path 1. An attacker convinces a user to save a crafted bookmark or other entry containing JSON syntax, such as embedded quotes and object delimiters. 2. The application writes the value to one of its local log files. 3. The user runs `bookmark-keeper export json`. 4. `_export` interpolates the crafted value into `export.json` without JSON escaping. 5. The resulting file is malformed or contains attacker-controlled JSON structure. 6. A downstream parser, importer, or automation process may reject the export or process fabricated data. ### Impact Assessment The direct impact is limited to data generated under the current user's account. The vulnerability can corrupt exported data, create misleading records, and affect downstream systems that import the JSON. The script itself does not grant additional ope ...[truncated 152 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:78
Finding

CSV Formula Injection and Malformed CSV Export

Content
View full analysis
"$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ``` ### Technical Analysis The `val` field contains user-controlled bookmark or productivity data and is written directly into a CSV file. The implementation does not quote fields or escape embedded commas, double quotes, carriage returns, and newlines as required for reliable CSV serialization. More importantly, spreadsheet applications may interpret cells beginning with characters such as `=`, `+`, `-`, or `@` as formulas. A malicious entry can therefore become an active spreadsheet formula when the exported file is opened. Depending on the spreadsheet application and its security settings, a formula may trigger external resource requests, expose data through attacker-controlled URLs, or invoke other spreadsheet-supported functionality. The script does not execute the formula itself; exploitation occurs in the downstream spreadsheet application. ### Attack Path 1. An attacker supplies or recommends a bookmark value beginning with spreadsheet formula syntax, for example an expression that references an attacker-controlled URL. 2. The user stores that value through `bookmark-keeper add` or another entry command. 3. The user runs `bookmark-keeper export csv`. 4. The value is written verbatim as a CSV cell. 5. The user opens the generated CSV file in spreadsheet software. 6. The spreadsheet interprets the attacker-controlled cell as a formula. 7. Depending on the spreadsheet engine and security configuration, the formula may cause an external request, disclose spreadsheet data, or perform another formula-supported action. Separ ...[truncated 745 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description claims a web bookmark tool focused on saving, organizing, and searching bookmarks with tags and categories. The code does not implement bookmark-specific behavior: it does not capture URLs specially, manage bookmark metadata, organize by categories in a bookmark model, or provide bookmark review workflows. Instead, it is a general-purpose local logging CLI with multiple productivity-related commands that append arbitrary user input to separate .log files, plus search/export/stats/status functions over those logs. While it does include a search command and a tag command, those operate on generic text logs rather than a bookmark collection. Therefore the actual primary purpose materially differs from the declared purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata and help text present this as a bookmark organizer, but the implemented commands are a generic activity logger (plan, streak, remind, prioritize, etc.). This mismatch is dangerous because users and higher-level agents may trust the declared scope and provide inputs they would not otherwise disclose, enabling deceptive collection and persistence of unrelated personal data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description limits the skill to saving, organizing, and searching web bookmarks with tags and categories. However, the skill documentation describes broader capabilities including plans, task tracking, reminders, prioritization, reports, streaks, timelines, and weekly reviews, which go well beyond bookmark management into general personal productivity logging.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline branding and comments market the script as a bookmark tool even though the storage model and command set implement a generic productivity toolkit. Deceptive labeling undermines informed consent and can cause users or orchestrating systems to approve execution under false assumptions about behavior and data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script silently creates a persistent data directory and appends user-submitted content to local log files without clear notice or consent. This is dangerous because users may provide sensitive research notes, URLs, or personal planning data assuming ephemeral processing, while the tool retains it indefinitely on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The export function aggregates all stored logs into json, csv, or txt files on disk without warning that it may concentrate sensitive content into a single easily copied artifact. Consolidated exports increase exposure risk if the workstation is shared, backed up, synced, or later exfiltrated by other software.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The advertised search capability is only a raw grep over all local log files rather than a bookmark-specific search over structured bookmark records. This is risky because it broadens the search surface to all persisted user content and can reveal unrelated sensitive entries while falsely implying a scoped bookmark search.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The numerous productivity, planning, and habit-tracking commands are unjustified for a bookmark manager and materially expand the type of user data this skill collects and stores. This unnecessary capability expansion increases privacy risk and creates an opportunity for covert data harvesting under an innocuous bookmark-related label.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.