Back to skill

Security audit

File Finder

Security checks for vulnerabilities and agentic risk

Overview

This file-finder skill is a real filesystem utility, but it contains unsafe argument handling that can execute injected Python code and it under-describes its broader analysis features.

Do not install this version until the embedded Python blocks are changed to pass arguments safely and the manifest is updated to disclose the full filesystem analysis behavior and intended directory scope. There is no evidence of a backdoor or persistence, but a crafted path argument could run code with the same access as the agent or user invoking the skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/file_finder.sh:38
Finding

Arbitrary Python Code Execution Through the large Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/file_finder.sh:81
Finding

Arbitrary Python Code Execution Through the dup Command

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/file_finder.sh:135
Finding

Arbitrary Python Code Execution Through the summary Command

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The manifest presents the skill as a simple fd-style file finder, but the detected behavior includes substantially broader filesystem inspection and analysis capabilities such as hashing, size analysis, recency reporting, and tree/statistical summaries. This mismatch can mislead users and policy systems about what the skill actually does, increasing the risk of unintended data exposure and overbroad file enumeration.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
79% confidence
Finding

The skill declares runtime and exposes filesystem-oriented behavior, but it does not define any explicit tool scope such as permissions or allowed-tools. In an agent environment, missing scope boundaries can lead to broader-than-intended file read access and makes it harder to enforce least privilege.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Generic triggers like help, run, info, and status are overly broad and are likely to collide with normal agent workflows or other skills. That can cause accidental invocation of this skill in unintended contexts, which is especially risky for a filesystem-oriented tool that may enumerate or inspect local files.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
84% confidence
Finding

The usage text says 'Run any command,' which signals unconstrained command handling rather than a fixed, narrowly defined interface. In practice, ambiguous command acceptance can expand the reachable behavior surface and undermine enforcement of safe, expected operations.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
## Usage

Run any command: `file-finder <command> [args]`

---
> **Disclaimer**: This skill is an independent, original implementation. It is not affiliated with, endorsed by, or derived from the referenced open-source project. No code was copied. The reference is for context only.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest presents this skill as a fast alternative to 'find', implying file-location functionality. However, the help text and implemented commands add broader analysis capabilities such as duplicate detection, large-file analysis, recency reporting, directory summaries, and tree views, which materially expand the behavior beyond simple file finding.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The top-level comment describes the script as 'File Finder — fast file search', aligning with a narrow search utility. Immediately below, the user-facing help expands the intent to 'fast file search & analysis' and exposes analysis-oriented commands, creating a direct documentation-level divergence about the tool's intended scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.