Back to skill

Security audit

Live Stream Script

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly generates livestream sales scripts, but one bundled script quietly saves user-provided prompts to a local history file, so it should be reviewed before installation.

Install only if you are comfortable with the package's unclear command mapping and with one bundled script storing entered topics or prompts in a local history file. Avoid entering confidential campaign plans, customer data, secrets, or unpublished business details unless the logging behavior is removed or clearly controlled.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:29
Finding

Undisclosed Persistent Logging of User-Controlled Input

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 4-6 and 29-81
Vulnerability Type: Plaintext storage of potentially sensitive user input
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${LIVE_STREAM_SCRIPT_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/live-stream-script}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

cmd_draft() {
    echo "  Draft: $1
      Target: ${2:-800} words"
    _log "draft" "${1:-}"
}

cmd_headline() {
    echo "  1. How to $1
      2. $1: Complete Guide
      3. Why $1 Matters"
    _log "headline" "${1:-}"
}

cmd_outline() {
    echo "  1. Intro | 2. Problem | 3. Solution | 4. Examples | 5. CTA"
    _log "outline" "${1:-}"
}

cmd_seo() {
    echo "  Keywords: $1 | Title tag | Meta desc | H1-H3 | Internal links"
    _log "seo" "${1:-}"
}

cmd_schedule() {
    echo "  Mon: Research | Tue: Write | Wed: Edit | Thu: Publish | Fri: Promote"
    _log "schedule" "${1:-}"
}

cmd_hooks() {
    echo "  Question | Statistic | Story | Bold claim | Controversy"
    _log "hooks" "${1:-}"
}

cmd_cta() {
    echo "  Subscribe | Share | Comment | Try it | Learn more"
    _log "cta" "${1:-}"
}

cmd_repurpose() {
    echo "  Blog -> Thread -> Video -> Carousel -> Newsletter"
    _log "repurpose" "${1:-}"
}

cmd_metrics() {
    echo "  Views | Clicks | Shares | Time on page | Conversions"
    _log "metrics" "${1:-}"
}

cmd_ideas() {
    echo "  How-to | Listicle | Case study | Interview | Comparison"
    _log "ideas" "${1:-}"
}

Technical Analysis

The script persistently appends command names and raw user-controlled arguments to history.log. The documented skill behavior describes generation of textual livestream content but does not disclose persistent logging, a retention period, or a deletion mechanism.

...[truncated 1407 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove argument logging unless it is necessary for the declared functionality.
  2. If logging is required, make it explicitly opt-in and document what is recorded, where it is stored, and how long it is retained.
  3. Avoid recording raw user content. Log only non-sensitive event metadata, such as the command name and success status.
  4. Apply restrictive permissions before creating data:
    bash
    umask 077
    mkdir -p -- "$DATA_DIR"
    
  5. Create log files with an explicit owner-only mode and verify that the configured data directory is not shared.
  6. Add log rotation, retention limits, and a command that securely removes stored history.
  7. Validate LIVE_STREAM_SCRIPT_DIR before use if it can be supplied by an untrusted launcher or environment.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/livestream.sh:3
Finding

Unquoted Shell Expansion Causes Argument Splitting and Pathname Disclosure

Content
View full analysis

Vulnerability Details

File Location: scripts/livestream.sh, lines 3 and 29
Vulnerability Type: Unsafe shell argument expansion
Risk Level: Low

Vulnerable Code

bash
CMD="${1:-help}"; shift 2>/dev/null || true; INPUT="$*"

The collected input is subsequently expanded without quotes:

bash
' "$CMD" $INPUT

Technical Analysis

Although INPUT="$*" initially stores the arguments as a single string, the later unquoted $INPUT expansion is subject to shell word splitting and pathname expansion. Consequently, whitespace boundaries are not preserved and wildcard characters such as *, ?, and bracket expressions may expand to filesystem entries in the current working directory.

The expanded values are passed as arguments to the fixed python3 -c program. Shell control operators embedded inside the variable are not reparsed as shell syntax, so the reviewed code does not provide direct shell-command injection. However, pathname expansion can unexpectedly incorporate local filenames into inp, after which commands such as plan print the resulting value.

Attack Path

  1. The script is invoked with a plan topic containing a shell wildcard, such as *.
  2. The wildcard is stored in INPUT.
  3. At the final invocation, unquoted $INPUT undergoes pathname expansion in the caller's current directory.
  4. Matching filenames are passed to Python as separate arguments.
  5. Python joins those arguments and prints them as part of the livestream plan topic.
  6. If output is captured by another service or exposed to another user, local filenames may be unintentionally disclosed.

Impact Assessment

Exploitation can alter generated output and disclose names of files or directories visible from the script's working directory. It does not reveal file contents, execute arbitrary commands, elevate privileges, or establish persistence. The scope is limited by the invoking process's existing ...[truncated 70 chars]

Remediation
View remediation

Remediation Suggestions

Preserve the remaining arguments in a Bash array and pass every element using quoted expansion:

bash
CMD="${1:-help}"
if (($# > 0)); then
    shift
fi
INPUT_ARGS=("$@")

python3 -c '
import sys
cmd = sys.argv[1] if len(sys.argv) > 1 else "help"
inp = " ".join(sys.argv[2:])
# Existing command implementation...
' "$CMD" "${INPUT_ARGS[@]}"

Alternatively, if the Python program should receive the input as exactly one argument, use:

bash
INPUT="$*"
python3 -c '...' "$CMD" "$INPUT"

Add regression tests using spaces, *, ?, bracket expressions, empty input, and filenames beginning with - to verify that user input is preserved literally.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described entirely as a Chinese live-stream script generator and presents its outputs and use cases in Chinese without indicating that users may choose another language. This is a natural-language policy concern because it appears to impose a specific language/locale by default rather than offering a language preference.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This Python skill is explicitly described as a Chinese live-stream script generator, and all generated user-facing content is hard-coded in Chinese. Because the file does not offer any language selection or explain a justified region-specific restriction, it creates a natural-language locale policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

User-provided content is written to a local history log with no visible warning, which can capture sensitive prompts, unpublished content ideas, client names, or proprietary work product. In the context of a content-creation assistant, users are likely to paste drafts or strategic topics, making undisclosed persistence more dangerous than in a tool whose primary purpose is auditing or logging.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The entire skill content is presented only in Chinese, with no indication that other languages are supported or that the user can opt into this locale. Under the stated policy, forcing a specific language without user choice is a natural-language policy violation unless clearly documented as region-specific or optional.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
71% confidence
Finding

The help text suggests only a generic data directory, while the implementation specifically appends command data to history.log. This is not merely omitted detail about storage location; it can mislead users about the nature of persisted data because the code records operational history that the documentation does not describe.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script persistently records command names and user-supplied arguments into a history file even though its visible interface presents simple content-assistance features and does not disclose this behavior. This creates a privacy issue because prompts, topics, or other potentially sensitive user content may be stored on disk without consent and later exposed to other local users, backups, or forensic review.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.