Back to skill

Security audit

Name Generator

Security checks for vulnerabilities and agentic risk

Overview

The main naming tool is low-risk, but the package includes an under-disclosed generic utility that persistently stores and logs user-provided text on disk.

Review before installing. The documented name-generation script does not show network access or dangerous commands, but avoid passing private names, business plans, or other sensitive text to the bundled name-generator/script.sh utility unless you are comfortable with that text being stored locally in plaintext. Prefer using scripts/name.sh directly for the advertised naming functions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:6
Finding

Undocumented Persistent Plaintext Logging of User-Supplied Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:6-9, 32, 35-75
Vulnerability Type: Persistent plaintext storage of potentially sensitive user input
Risk Level: Medium

The secondary utility script persistently stores command arguments without notifying the user, obtaining explicit consent, applying a retention policy, or enforcing restrictive file permissions. This behavior is not documented in SKILL.md.

Vulnerable Code

bash
DATA_DIR="${NAME_GENERATOR_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/name-generator}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
cmd_run() {
    echo "  Running: $1"
    _log "run" "${1:-}"
}

cmd_config() {
    echo "  Config: $DATA_DIR/config.json"
    _log "config" "${1:-}"
}

cmd_status() {
    echo "  Status: ready"
    _log "status" "${1:-}"
}

cmd_init() {
    echo "  Initialized in $DATA_DIR"
    _log "init" "${1:-}"
}

cmd_list() {
    [ -f "$DB" ] && cat "$DB" || echo "  (empty)"
    _log "list" "${1:-}"
}

cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

cmd_remove() {
    echo "  Removed: $1"
    _log "remove" "${1:-}"
}

cmd_search() {
    grep -i "$1" "$DB" 2>/dev/null || echo "  Not found: $1"
    _log "search" "${1:-}"
}

cmd_export() {
    [ -f "$DB" ] && cat "$DB" || echo "No data"
    _log "export" "${1:-}"
}

cmd_info() {
    echo "  Version: $VERSION | Data: $DATA_DIR"
    _log "info" "${1:-}"
}

Technical Analysis

The script creates a persistent directory under the user's data directory as soon as it starts. The _log function appends the first argument supplied to most commands to history.log, while cmd_add writes every supplied argument to data.log.

Neither the directory nor the files ...[truncated 1895 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove scripts/script.sh if it is unused, because its generic persistent-storage behavior is unrelated to the documented name-generation interface.
  2. If persistence is required, document every stored field, storage location, retention period, and deletion procedure in SKILL.md.
  3. Obtain explicit user consent before retaining command arguments.
  4. Do not log raw arguments. Record only non-sensitive operational metadata, or redact and minimize values before writing them.
  5. Set umask 077 before creating the data directory and files.
  6. Create the directory with mode 0700 and data files with mode 0600, then verify that existing files are not more permissive.
  7. Add commands that allow users to inspect and permanently delete stored history.
  8. Define a short retention period and automatically remove expired records.
  9. Avoid using arbitrary user-controlled storage locations without validating ownership, permissions, and symbolic-link behavior.
  10. Add automated tests confirming that sensitive arguments are not logged and that all persistent files receive restrictive permissions.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The natural-language description and usage are predominantly in Chinese and present the skill as a Chinese-language assistant without any opt-in or language selection guidance. This may violate language/locale policy where skills should not force a specific language absent user choice or documented justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger guidance is broad enough that ordinary conversations about naming could invoke the skill even when the user did not clearly request tool use. This can cause unintended activation, irrelevant responses, or unnecessary script execution, though the skill’s functionality is low-risk and limited to name generation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The usage instruction says to use the skill when users ask about naming-related topics, but it does not define clear limits or require explicit consent for tool invocation. This ambiguity increases the chance of over-triggering in general discussion contexts, leading to inappropriate or unnecessary use of the skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user-facing help and invocation descriptions are entirely in Chinese, and the script consistently presents all prompts and outputs in Chinese. This imposes a specific language/locale without any opt-in, fallback, or explanation that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Across all subcommands, usage errors, labels, recommendations, and guidance are emitted only in Chinese. Because the file does not offer a user language choice or clearly state that it is a China-specific naming tool, this constitutes a natural-language locale restriction.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file header and help text identify the tool as 'name-generator', which implies functionality centered on generating names. However, the implemented commands only log activity, append arbitrary entries to a local data file, list/search/export them, and report status; there is no name-generation behavior anywhere in the code.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The comment at L162 says the tool recommends similar-sounding English names based on the first character of the Chinese name. In implementation, L205-L217 extract the surname as the first character and only use that surname to drive initial_map, which is a narrower and different basis than the comment describes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The comment at L602 describes availability constraints ('温柔 only for 女, 大气 only for 男'), which implies validation of incompatible combinations. Instead, L603-L606 silently substitutes a different style (简约 or 温柔) rather than rejecting the input or clearly reporting the change.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The helper writes command history to "$DATA_DIR/history.log", but the script does not disclose this persistent logging behavior in comments, prompts, or the help text. For a code file, silent file writes that record user activity should be surfaced to the user somehow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This line appends user-provided content to the persistent database file "$DB". Although it prints "Added", the overall script help does not explain that entries are stored on disk under the data directory, so the data-modifying behavior lacks clear disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The tips content from L03-L10 is written entirely in Chinese, which imposes a specific language on users without any indication of language selection or opt-in. Under the policy, forcing a language or locale without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.