Back to skill

Security audit

Diet

Security checks for vulnerabilities and agentic risk

Overview

This diet-tracking skill is coherent and disclosed, storing user-entered nutrition and water logs locally without signs of hidden network access or malicious behavior.

Install only if you are comfortable with meal, macro, calorie, and water-intake records being stored locally in ~/.diet. Because the script does not set restrictive permissions itself, privacy-conscious users should ensure their system umask or the ~/.diet directory and JSON files are owner-only readable.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:14
Finding

Sensitive Nutrition Records Created Without Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 14-21
Vulnerability Type: Sensitive local data stored with permissions controlled only by the caller's umask
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${HOME}/.diet"
MEALS_FILE="${DATA_DIR}/meals.json"
WATER_FILE="${DATA_DIR}/water.json"

ensure_data_dir() {
  mkdir -p "${DATA_DIR}"
  [[ -f "${MEALS_FILE}" ]] || echo '[]' > "${MEALS_FILE}"
  [[ -f "${WATER_FILE}" ]] || echo '[]' > "${WATER_FILE}"
}

The files are subsequently rewritten without enforcing their permissions:

python
with open(meals_file, 'w') as f:
    json.dump(data, f, ensure_ascii=False, indent=2)
python
with open(water_file, 'w') as f:
    json.dump(data, f, ensure_ascii=False, indent=2)

Technical Analysis

The Skill stores meal history, food descriptions, calorie and macronutrient measurements, and water intake under ~/.diet/. This information may constitute sensitive health-related data.

The storage directory and JSON files are created without a restrictive umask or explicit permission modes. Their permissions therefore depend entirely on the invoking process's environment. With a common 022 umask, the directory can be created as mode 0755 and the JSON files as mode 0644. Where the user's home-directory permissions permit traversal, other local users could read these records.

Reopening the files with Python's open(..., 'w') does not correct permissions that were assigned when the files were created. The implementation also does not repair preexisting files or directories that have overly broad permissions.

Attack Path

  1. A user invokes log, water, or another command that calls ensure_data_dir.
  2. The script creates ~/.diet, meals.json, and water.json using permissions derived from the user's current umask.
  3. Under a permissive umask, the files become readable by users outside the o ...[truncated 793 chars]
Remediation
View remediation

Remediation Suggestions

  1. Set a restrictive umask before creating or updating the data:

    bash
    umask 077
    
  2. Explicitly protect the storage directory:

    bash
    mkdir -p -m 700 "${DATA_DIR}"
    chmod 700 "${DATA_DIR}"
    
  3. Create and repair the data files with owner-only permissions:

    bash
    [[ -f "${MEALS_FILE}" ]] || printf '%s\n' '[]' > "${MEALS_FILE}"
    [[ -f "${WATER_FILE}" ]] || printf '%s\n' '[]' > "${WATER_FILE}"
    chmod 600 "${MEALS_FILE}" "${WATER_FILE}"
    
  4. Validate that the data paths are regular files owned by the current user before reading or overwriting them.

  5. Use atomic writes through temporary files created inside the protected directory, set each temporary file to mode 0600, and rename it into place. This will also reduce the risk of data corruption during interrupted writes.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes code-backed operations that read environment state and read/write local files, but it does not declare any explicit tool scope or permissions boundary in the manifest. That creates an authorization ambiguity where an agent/runtime may grant broader capabilities than a user expects, increasing the risk of unintended data access or persistence in the user's home directory.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest says the skill is for tracking food and nutrition, logging meals, checking calories, tracking macros, or generating diet reports. The code also creates a separate water log and exposes water logging and water-inclusive reports, which is behavior beyond the described meal/calorie/macro scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.