Back to skill

Security audit

Brand Namer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its brand-naming purpose, but one script has an input-handling flaw that could let a malicious count argument run local commands.

Review before installing. Do not pass untrusted or generated text as the generate count argument until the script validates it as a bounded integer. Treat domain checks as public network lookups, and avoid checking confidential pre-launch names unless that disclosure is acceptable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:143
Finding

Command Injection Through Unvalidated Bash Arithmetic Input

Content
View full analysis
Remediation
View remediation
&2 return 1 fi if (( count < 1 || count > 100 )); then echo "Count must be between 1 and 100." >&2 return 1 fi # Continue only after successful validation. } ``` Additional hardening measures: 1. Enforce an upper bound to prevent excessive CPU use and output generation. 2. Reject signs, whitespace, arithmetic operators, variable names, brackets, and command-substitution syntax rather than attempting to sanitize them. 3. Apply validation immediately after argument parsing and before every arithmetic use. 4. Add regression tests that reject values such as: - `abc` - `1+1` - `-1` - `999999999` - `x[$(command)0]` 5. Preserve `set -euo pipefail`, but do not treat it as an input-validation mechanism; it does not prevent arithmetic injection. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill exposes shell-executed functionality (scripts/script.sh commands and DNS lookups via dig) but does not declare any tool scope such as permissions or allowed-tools. This can cause an agent runtime to grant broader-than-necessary shell access or execute the skill without clear policy constraints, increasing the chance of unintended command execution or misuse if user-controlled inputs are later passed to the script.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The check command sends the user-supplied brand/domain candidate to external sites via HTTPS requests without any disclosure, consent, or warning. Brand ideas can be commercially sensitive before launch, so this creates a privacy and competitive-intelligence leak even though the mechanism is simple and likely intended for convenience.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The check command sends user-supplied brand names to external DNS resolvers via dig, which discloses potentially sensitive or pre-launch names to network infrastructure outside the local system. In this skill's context, that matters because startup/product naming is often confidential, and the script presents the feature as a simple availability check without a clear upfront warning that it performs outbound network queries.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The file title and all instructional content are written in Chinese and include China-specific naming guidance such as Chinese trademark lookup, but there is no indication that the skill is intentionally limited to Chinese-speaking users or that users may choose another language. This can violate a language/locale policy when a skill implicitly forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The help text and command implementation explicitly provide a cn mode for Chinese brand name ideas, introducing a specific language output mode without indicating user locale choice or opt-in policy. This can violate a language/locale policy when a skill imposes or defaults to a specific language without documented user consent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script defines VERSION as 3.0.3, but the embedded help banner claims 'brand-namer v2.0.0'. This documentation contradicts the code's actual reported version behavior and could mislead users about what release they are running.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes brainstorming, domain availability checks, and name analysis, which align with generation and evaluation features. However, the code creates a persistent data directory and history log, introducing local stateful storage behavior not mentioned in the description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Beyond generating names and checking/analyzing them, the script supports saving names, listing a persistent shortlist, and exporting that data in multiple formats. These are substantial user-facing capabilities rather than incidental implementation details, so they should be reflected in the manifest if intended.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.