T09 · Insecure Skill Coding Practices
- Location
scripts/daily_journal.sh:80- Finding
Arbitrary Python Code Execution Through JOURNAL_DIR Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This local journal skill is mostly purpose-aligned, but it needs Review because it stores sensitive personal entries with weak protections and contains a path-handling flaw that can become code execution if the environment is manipulated.
Install only if you are comfortable with a shell-based local journal that writes private content to disk. Before use, restrict ~/.journal permissions, avoid setting JOURNAL_DIR from untrusted input, and treat exports as sensitive files that may reveal your full journal history.
scripts/daily_journal.sh:80Arbitrary Python Code Execution Through JOURNAL_DIR Injection
scripts/daily_journal.sh:6Sensitive Journal Records Are Created Without Restrictive Permissions
scripts/daily_journal.sh:143Unescaped Journal Content Produces Active HTML Exports
" && cat "$f" && echo "
` element does not cause browsers to treat it as plain text. HTML tags in the journal remain markup, and a sequence such as `
` can terminate the intended element and introduce active script content. The vulnerable content is stored before execution, so this is a stored HTML injection issue. Content may be attacker-controlled if it is supplied through an automated Agent workflow, copied from an untrusted source, passed to the `write` command by another program, or inserted into a journal file by another local process. ### Attack Path 1. Attacker-controlled text containing HTML or script markup is saved in a `.md` journal entry. 2. The user invokes `daily_journal.sh export html` and redirects the output to an HTML file. 3. The exporter concatenates the journal text into the document without HTML escaping. 4. The user opens the exported document in a web browser or an HTML-capable viewer. 5. The browser interprets the injected markup and may execute embedded JavaScript. ### Impact Assessment An attacker can alter the rendered export, display deceptive content, create links or forms, load external resources, and execute JavaScript within the exported document's browser origin. The exact reach depends on how the file is opened and on browser security restrictions for local files. The flaw does not directly provi ...[truncated 198 chars]
{}The manifest does not declare a tool scope or permissions boundary, yet the skill is described as storing and retrieving local journal data, which implies file access. Without explicit scoping, an agent may invoke the skill with broader-than-expected file read capability or without clear user-visible constraints, increasing the chance of unintended access to local data. Because this skill handles personal journal content, the sensitivity of accessible files makes the omission more concerning.
The description says the skill should be used when the agent 'need[s] Daily Journal capabilities,' which is a broad activation condition rather than a narrowly defined trigger. Overly general routing language can cause the agent to invoke the skill in contexts involving personal notes, memory, or writing where the user did not specifically intend journal access, potentially exposing sensitive local data or causing unintended writes. In a privacy-sensitive journaling skill, unnecessary invocation is especially risky.
This shell script stores potentially sensitive personal reflections in files under ~/.journal and also writes mood and gratitude logs, but it does not include any user-facing warning or explanatory comment about local persistence of private data. The success messages only confirm completion and do not disclose the privacy impact of creating a personal journal archive on disk.
The export command outputs all journal entries in md, html, or json formats, which can expose a user's complete personal history if redirected, shared, or logged. The code performs this potentially privacy-impacting action without any confirmation prompt or warning message about the sensitivity of the exported data.
No suspicious patterns detected.