Back to skill

Security audit

Calctool

Security checks for vulnerabilities and agentic risk

Overview

CalcTool is advertised as a calculator, but the artifacts show it mainly stores, searches, and displays user-entered text in persistent local logs.

Review this skill carefully before installing. It is not a normal calculator: anything entered into its commands may be saved locally in plaintext and later searched or displayed. Avoid using it for financial details, account-like numbers, confidential reports, credentials, or private business data unless the logging behavior is exactly what you want and local file permissions are hardened.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:6
Finding

Plaintext Log Files Are Created Without Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:6-9, with user-input write operations repeated at scripts/script.sh:139-310
Vulnerability Type: Insecure local storage and insufficient file permissions
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${HOME}/.local/share/calctool"
mkdir -p "$DATA_DIR"

_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

A representative user-input write operation is:

bash
local input="$*"
local ts=$(date '+%Y-%m-%d %H:%M')
echo "$ts|$input" >> "$DATA_DIR/run.log"
echo "  [Calctool] run: $input"
_log "run" "$input"

Equivalent plaintext writes appear in the check, convert, analyze, generate, preview, batch, compare, export, config, status, and report command branches.

Technical Analysis

The script creates its data directory and log files without setting a restrictive umask or explicitly enforcing owner-only permissions. Consequently, permissions depend on the invoking environment's current umask. Under common defaults, the directory may be created as mode 0755 and log files as mode 0644, allowing other local users to traverse the directory and read recorded content.

The logged values are supplied directly by users and may include financial calculations, configuration details, operational status information, reports, or other sensitive data. The same value is also copied into history.log, increasing the number of locations containing the information. The files are persistent and no retention, redaction, or automatic deletion mechanism is implemented.

The script currently also uses local outside functions in the command-dispatch branches, which causes standard Bash executions of those branches to fail before their intended writes. This is a correctness defect that limits immediate reachability of the vulnerable write paths in the present version. Nevertheless, the storage impl ...[truncated 1411 chars]

Remediation
View remediation

Remediation Suggestions

  1. Set a restrictive file-creation mask before creating any storage:

    bash
    umask 077
    
  2. Create and verify the data directory with owner-only permissions:

    bash
    mkdir -p "$DATA_DIR"
    chmod 700 "$DATA_DIR"
    
  3. Explicitly create log files with mode 0600 before appending data:

    bash
    install -m 600 /dev/null "$DATA_DIR/history.log"
    

    Existing files should be checked and corrected with chmod 600.

  4. Avoid logging sensitive values by default. Provide an explicit opt-in for persistent logging and redact credentials, tokens, account identifiers, and confidential financial data.

  5. Add retention controls, including commands to securely remove old records and documentation explaining where data is stored and how long it remains.

  6. Correct the top-level local declarations by moving command logic into functions or replacing those declarations with normal assignments. Apply and test the permission hardening before making the currently failing write paths operational.

  7. Add automated tests that execute the tool under a permissive parent umask and verify that the resulting directory is mode 0700 and every data file is mode 0600.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest presents this as a calculator, but the documented behavior is a generic persistent logging and data-management tool that stores arbitrary user input, supports search over prior entries, and exports accumulated data. That mismatch is dangerous because users or orchestrators may invoke it expecting ephemeral math operations while unintentionally creating a searchable local archive of potentially sensitive prompts, calculations, financial values, or other pasted content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation defines commands that primarily log arbitrary inputs instead of performing calculations, contradicting the declared calculator purpose. This creates a deceptive interface where users may submit sensitive data under the assumption of a simple utility, while the skill instead builds durable records and audit trails unrelated to the expected task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The help text and command surface advertise a broad utility and data-handling workflow rather than a calculator, directly contradicting the declared skill purpose. This kind of capability mismatch is dangerous because it can mislead users and host agents into sending arbitrary sensitive inputs to a tool that is actually designed to store and process activity logs instead of performing calculations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The main command handlers do not compute anything; they persist arbitrary user input into per-command log files and history instead. In a skill presented as a calculator, this creates a deceptive data-capture mechanism that can collect formulas, financial data, or other sensitive text a user believes is being processed ephemerally.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The opening documentation reframes the tool as a traceability and data-entry management utility, which directly conflicts with the calculator manifest. In skill ecosystems, that contradiction makes routing and trust decisions less reliable and can cause a benign-looking tool to be selected for workflows involving sensitive values that then get retained.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The phraseology is overly broad and action-oriented beyond calculation, which can trigger unintended invocation in agentic environments for generic run/check/analyze/manage tasks. That matters because invocation of this skill results in local persistence of arbitrary inputs, so accidental selection becomes a privacy and data-retention issue rather than a harmless misfire.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Although the document later mentions logging, the primary description does not adequately foreground that user inputs are timestamped and persistently stored. Users encountering a calculator skill reasonably expect transient processing, so insufficient up-front disclosure undermines informed consent and can lead to sensitive data being recorded unexpectedly.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instructions normalize comprehensive logging and later review/export of user inputs, establishing a built-in retention and disclosure pathway. In the context of a purported calculator, that is especially risky because users may paste formulas, budgets, account-like numbers, or business metrics without expecting long-term storage and easy retrieval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad logging, config, status, reporting, and history-search capabilities exceed what is needed for a calculator and expand the data-handling surface unnecessarily. Those features enable retention, indexing, and later retrieval of user-provided content, increasing privacy and misuse risks if sensitive information is ever entered.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Directing every action and command input into per-command logs plus a unified history file creates centralized persistence of all submitted content. That design broadens exposure because any later local access, backup process, or support review could reveal aggregated sensitive information far beyond a single command invocation.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill clearly establishes session persistence by encouraging report creation and later review through stats and search across logged data. Persistent state is not inherently unsafe, but in this context it is risky because the state consists of arbitrary user-provided content retained under a misleading calculator identity.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
2. **Batch processing and comparison** — Log batch operations with `batch` and side-by-side comparisons with `compare`
3. **Generating and previewing outputs** — Use `generate` to log generated results and `preview` to log draft outputs before finalizing
4. **Configuration and status tracking** — Record configuration changes with `config` and system states with `status` for audit trails
5. **Reporting and data export** — Create `report` entries for periodic summaries and use `stats` or `search` to review all logged data

## Examples

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Search, recent-history viewing, and export over all logged data make accumulated user inputs easy to retrieve and disclose in bulk. This increases the harm of any mistaken entry of sensitive content because the tool explicitly supports enumeration and extraction of the stored corpus.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline documentation describes a generic utility toolkit, not a calculator, reinforcing that the implementation's true purpose differs from the declared skill context. This discrepancy makes the skill more dangerous because deceptive presentation reduces the likelihood that users or reviewers will recognize unnecessary logging and export behavior before providing input.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The tool is architected to retain arbitrary inputs across commands and later reveal or export them in plaintext, creating a local surveillance and exfiltration channel. In the context of a purported calculator, this is especially risky because users may reasonably submit confidential financial or operational data that can then be searched, viewed, or exported without additional safeguards.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Search, recent-history, status, and multi-format export functions provide secondary data-discovery and exfiltration features that are unnecessary for a basic calculator. These capabilities materially increase risk because once user input is captured, the tool can enumerate, display, and package it in plain formats for later retrieval.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

User-provided input is written verbatim to local log files without notice, consent, retention controls, or redaction. Because users may enter financial calculations, account figures, or other sensitive content into a calculator, silent persistence creates a privacy and data-exposure risk even without remote exfiltration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.