Back to skill

Security audit

Icon

Security checks for vulnerabilities and agentic risk

Overview

This icon skill is mostly purpose-aligned, but its bundled shell script accepts unsafe inputs that can lead to local command execution or writing files outside the intended output directory.

Install only if you trust the inputs the agent will pass to it and the SVGs it will process. Avoid using untrusted icon names, sizes, colors, prefixes, or source SVG files until the script validates numeric dimensions, constrains filenames to safe basenames, and sanitizes SVG/XML content.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:124
Finding

Arbitrary Command Execution Through Unvalidated Arithmetic Expressions

Content
View full analysis
"$outfile" ;; circle) svg_shape_circle "$size" "$color" > "$outfile" ;; square|check|close|plus|minus) svg_shape_square "$size" "$color" > "$outfile" ;; star|heart|bookmark) svg_shape_star "$size" "$color" > "$outfile" ;; *) svg_shape_placeholder "$size" "$color" "$name" > "$outfile" ;; esac } ``` The resulting value is evaluated in arithmetic contexts such as: ```bash local r=$(( size/2 - 2 )) ``` and: ```bash ``` ### Technical Analysis The `--size` argument is stored without verifying that it contains only a positive decimal integer. The value subsequently reaches multiple Bash arithmetic contexts. Bash arithmetic evaluation can recursively interpret variable contents as arithmetic expressions. Malicious arithmetic syntax, particularly expressions using array subscripts and command substitutions, can therefore cause shell commands embedded in the supplied value to execute during icon generation. Normal shell quoting around `"$size"` when passing it to an icon function does not make its later use in `$((...))` safe. The dangerous interpretation occurs inside the arithmetic evaluation itself. ### Attack Path 1. An ...[truncated 1382 chars]
Remediation
View remediation
= 4 && 10#$value <= 4096 )) || die "Size must be between 4 and 4096" } ``` Call validation immediately after parsing: ```bash validate_size "$size" size=$((10#$size)) ``` Apply equivalent validation independently to every entry accepted through `--sizes`. Reject empty entries, signs, whitespace, arithmetic operators, variable names, brackets, command substitutions, and values outside a reasonable resource limit. Do not rely on quoting alone to protect values later interpreted by Bash arithmetic evaluation. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:124
Finding

Output-Directory Escape Through Unsanitized Icon Names

Content
View full analysis
"$outfile" ;; circle) svg_shape_circle "$size" "$color" > "$outfile" ;; square|check|close|plus|minus) svg_shape_square "$size" "$color" > "$outfile" ;; star|heart|bookmark) svg_shape_star "$size" "$color" > "$outfile" ;; *) svg_shape_placeholder "$size" "$color" "$name" > "$outfile" ;; esac } ``` ### Technical Analysis The attacker-controlled `name` value is concatenated directly into the destination path: ```bash local outfile="${output}/${name}.svg" ``` No restriction prevents `name` from containing slash characters or `..` path components. Although shell quoting prevents word splitting and shell metacharacter expansion, it does not prevent filesystem path traversal. Consequently, a name such as `../../target` resolves outside the requested output directory. Redirection with `>` then creates or truncates the resolved file if the invoking account has permission. The `.svg` suffix restricts the final filename but does not ensure that the file remains inside the selected output directory. ### Attack Path 1. An attacker controls the `--name` argument passed to the `generate` command. 2. The attacker supplies a traversal sequence such as `../../shared/attacker-content`. 3. The s ...[truncated 1096 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:155
Finding

Active SVG Content Injection in Generated Icons and Sprite Sheets

Content
View full analysis
SVG } ``` The sprite command also inserts attacker-influenced IDs and copies source SVG content without sanitization: ```bash { echo '' for svg_file in "${svgs[@]}"; do local basename_noext basename_noext="$(basename "$svg_file" .svg)" local id="${prefix}${basename_noext}" # Extract viewBox from source SVG local viewbox viewbox=$(grep -oP 'viewBox="[^"]*"' "$svg_file" | head -1 || echo 'viewBox="0 0 24 24"') echo " " # Extract inner content (skip opening/closing svg tags) sed -n '//{ //d; p; }' "$svg_file" | sed 's/^/ /' echo " " done echo '' } > "$output" ``` ### Technical Analysis The `--color` value is inserted directly into quoted XML attributes without XML escaping or validation. A malicious value containing a quote can terminate the intended attribute and inject additional attributes or elements. Sprite generation has several related trust-boundary failures: - `--prefix` and source filenames are inserted into the `id` attribute without XML escaping. - The source `viewBox` attribute is extracted textually rather than parsed securely. - The complete inner body of every input SVG is copied into the resulting sprite. - No filtering removes scripts, event-handler attributes, external ref ...[truncated 2018 chars]
Remediation
View remediation
`, `"`, and `'` correctly for the relevant XML context. 3. Restrict sprite IDs and prefixes to a safe pattern such as: ```text ^[A-Za-z_][A-Za-z0-9_.-]*$ ``` 4. Replace regular-expression and line-oriented SVG extraction with a secure XML parser configured to: - Disable external entities and DTD processing - Reject or remove `script` - Reject event-handler attributes such as `onload` - Reject `foreignObject` - Remove external `href` and `xlink:href` references - Reject unsafe `data:` and `javascript:` URLs - Remove external CSS imports and resource references 5. Maintain a strict allowlist of SVG elements and attributes required for icon rendering. 6. Document that untrusted SVG files must not be processed without sanitization. 7. When publishing generated files, use an appropriate Content Security Policy and safe content disposition. Avoid injecting untrusted sprite content directly into HTML. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.