Back to skill

Security audit

Performance Review

Security checks for vulnerabilities and agentic risk

Overview

The main review generator is local and purpose-aligned, but the package also contains an under-documented utility that can persist sensitive review text and falsely says data was removed.

Review this skill before installing if you may enter real employee feedback, KPI data, promotion details, or other confidential personnel information. The documented review generator appears local, but avoid using scripts/script.sh for sensitive data unless its storage, logging, and deletion behavior are fixed or clearly accepted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Undocumented Plaintext Persistence of Potentially Sensitive Personnel Data

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:5-7, scripts/script.sh:35, and scripts/script.sh:57-59
Vulnerability Type: Plaintext storage and logging of potentially sensitive data
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${PERFORMANCE_REVIEW_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/performance-review}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }
bash
cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

Technical Analysis

The secondary utility creates a persistent data directory and writes user-controlled command arguments to data.log and history.log without explicitly establishing restrictive permissions. The resulting permissions depend on the invoking user's umask and any pre-existing filesystem objects.

Because this project handles performance reviews, promotion assessments, KPIs, and employee feedback, supplied arguments may contain confidential personnel information. Storing that content in plaintext creates an unnecessary local disclosure risk. Storage, retention, and history logging are also not disclosed by the documented SKILL.md interface, which describes a report generator that prints output locally.

The history log duplicates part of the submitted content, increasing the number of locations from which sensitive information must be removed. Retention is unbounded, and the implementation provides no verified data-lifecycle controls.

The related removal implementation at scripts/script.sh:61-64 also does not delete stored data:

bash
cmd_remove() {
    echo "  Removed: $1"
    _log "remove" "${1:-}"
}

It reports that an item was removed while only adding another history entry. Users may therefore incorrectly believe that sensitive information has been erased.

Attack Path

  1. A user or automated agent invokes `scripts/script.sh a ...[truncated 1193 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove scripts/script.sh if it is unused or unrelated to the documented performance-review functionality.
  2. Clearly document all persistent storage, history logging, retention, export, and deletion behavior.
  3. Require explicit user consent before storing performance-review or personnel information.
  4. Create the storage directory and files with restrictive permissions:
bash
umask 077
install -d -m 0700 -- "$DATA_DIR"
touch "$DB" "$DATA_DIR/history.log"
chmod 0600 "$DB" "$DATA_DIR/history.log"
  1. Avoid recording command arguments or review content in history.log. Log only non-sensitive operational events where necessary.
  2. Implement actual, verified record deletion in cmd_remove; only print a success message after confirming that the intended record was removed.
  3. Add configurable retention limits and a command that securely clears both the primary database and associated history records.
  4. Validate the configured storage location and reject unsafe paths or unexpected pre-existing filesystem objects where appropriate.
  5. Consider encryption at rest if retaining confidential personnel data is a required feature, while protecting encryption keys separately from the stored records.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language description is presented in both Chinese and English and prominently begins in Chinese, but nowhere indicates that the user can choose their preferred language or locale. This can violate language/locale policy expectations because the skill appears to impose a language presentation style without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script's help text, usage messages, and generated report templates are entirely in Chinese, effectively forcing a specific language/locale for all users. The file does not provide any opt-in, language selection mechanism, or documentation that this tool is intentionally limited to a Chinese-speaking regional context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script writes command activity to $DATA_DIR/history.log, creating a persistent record of user-supplied arguments. Although some commands print status output, there is no user-facing warning that inputs will be stored on disk, and the help text does not disclose this logging behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

cmd_add appends all provided arguments to $DB, which stores user content on disk. While it echoes that an item was added, the script does not clearly warn in its help or documentation that entered content will be permanently written to a local file under the user's data directory.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The command name and user-facing output indicate deletion behavior, but the implementation only prints a message and writes to the history log. This actively misrepresents the command's effect and can mislead users into believing data was deleted when it was not.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file is natural-language instructional content, and it presents all guidance exclusively in Chinese. Under the policy rule for language or locale constraints, forcing a specific language without user opt-in or documented justification is a policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.