Back to skill

Security audit

Daily Journal

Security checks for vulnerabilities and agentic risk

Overview

This local journal skill is mostly purpose-aligned, but it needs Review because it stores sensitive personal entries with weak protections and contains a path-handling flaw that can become code execution if the environment is manipulated.

Install only if you are comfortable with a shell-based local journal that writes private content to disk. Before use, restrict ~/.journal permissions, avoid setting JOURNAL_DIR from untrusted input, and treat exports as sensitive files that may reveal your full journal history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/daily_journal.sh:80
Finding

Arbitrary Python Code Execution Through JOURNAL_DIR Injection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/daily_journal.sh:6
Finding

Sensitive Journal Records Are Created Without Restrictive Permissions

Content
View full analysis
> "$f" echo "✍️ Added to ${today}" else cat > "$f" << ENTRY # Journal — $today ($(date +%A)) ## $(date +%H:%M) Write your thoughts here... ENTRY ``` Mood and gratitude records are handled in the same manner: ```bash echo "${today}|${score}|${emoji}|${note}" >> "$JOURNAL_DIR/moods.csv" ``` ```bash echo "${today}|${text}" >> "$JOURNAL_DIR/gratitude.csv" ``` ### Technical Analysis The script does not set `umask 077`, explicitly assign mode `700` to the journal directory, or assign mode `600` to journal and CSV files. Consequently, effective permissions depend on the invoking environment. Under a common `umask` of `022`, newly created directories are typically mode `755`, while files are typically mode `644`. On a multi-user system, this can allow other local users to traverse the journal directory and read its contents. The data is especially sensitive because it includes personal journal entries, mood records, gratitude notes, and potentially confidential information voluntarily entered by the user. Local storage alone does not ensure confidentiality when filesystem permissions are permissive. ### Attack Path 1. The Skill runs under an account whose `umask` permits group or world access, such as ...[truncated 934 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/daily_journal.sh:143
Finding

Unescaped Journal Content Produces Active HTML Exports

Content
View full analysis

Journal

"; for f in "$JOURNAL_DIR"/*.md; do [ -f "$f" ] && echo "
text
" && cat "$f" && echo "

"; done; echo "";; ``` ### Technical Analysis The HTML exporter copies journal content directly into an HTML document using `cat`, without encoding HTML-sensitive characters such as `&`, `<`, and `>`. Placing content inside a `
text
` element does not cause browsers to treat it as plain text. HTML tags in the journal remain markup, and a sequence such as `
text
` can terminate the intended element and introduce active script content.

The vulnerable content is stored before execution, so this is a stored HTML injection issue. Content may be attacker-controlled if it is supplied through an automated Agent workflow, copied from an untrusted source, passed to the `write` command by another program, or inserted into a journal file by another local process.

### Attack Path

1. Attacker-controlled text containing HTML or script markup is saved in a `.md` journal entry.
2. The user invokes `daily_journal.sh export html` and redirects the output to an HTML file.
3. The exporter concatenates the journal text into the document without HTML escaping.
4. The user opens the exported document in a web browser or an HTML-capable viewer.
5. The browser interprets the injected markup and may execute embedded JavaScript.

### Impact Assessment

An attacker can alter the rendered export, display deceptive content, create links or forms, load external resources, and execute JavaScript within the exported document's browser origin.

The exact reach depends on how the file is opened and on browser security restrictions for local files. The flaw does not directly provi
...[truncated 198 chars]
Remediation
View remediation
Journal

Journal

""") for path in sorted(glob.glob(os.path.join(directory, "*.md"))): with open(path, encoding="utf-8") as handle: content = handle.read() print("
text
{}

".format(html.escape(content))) print("") PYEOF ``` The remediation should: 1. Escape text with a context-appropriate HTML encoder. 2. Declare UTF-8 explicitly. 3. Add a restrictive Content Security Policy to reduce the effect of future encoding mistakes. 4. Avoid enabling Markdown raw-HTML features unless output is processed through a well-maintained sanitizer. 5. Add tests containing closing `pre` tags, script elements, event attributes, ampersands, and angle brackets. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
78% confidence
Finding

The manifest does not declare a tool scope or permissions boundary, yet the skill is described as storing and retrieving local journal data, which implies file access. Without explicit scoping, an agent may invoke the skill with broader-than-expected file read capability or without clear user-visible constraints, increasing the chance of unintended access to local data. Because this skill handles personal journal content, the sensitivity of accessible files makes the omission more concerning.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The description says the skill should be used when the agent 'need[s] Daily Journal capabilities,' which is a broad activation condition rather than a narrowly defined trigger. Overly general routing language can cause the agent to invoke the skill in contexts involving personal notes, memory, or writing where the user did not specifically intend journal access, potentially exposing sensitive local data or causing unintended writes. In a privacy-sensitive journaling skill, unnecessary invocation is especially risky.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script stores potentially sensitive personal reflections in files under ~/.journal and also writes mood and gratitude logs, but it does not include any user-facing warning or explanatory comment about local persistence of private data. The success messages only confirm completion and do not disclose the privacy impact of creating a personal journal archive on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The export command outputs all journal entries in md, html, or json formats, which can expose a user's complete personal history if redirected, shared, or logged. The code performs this potentially privacy-impacting action without any confirmation prompt or warning message about the sensitivity of the exported data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.