Back to skill

Security audit

Sleepwell

Security checks for vulnerabilities and agentic risk

Overview

This skill needs review because it is branded as a sleep tracker but mainly documents and ships a broad productivity logger that persistently stores, searches, and exports arbitrary user entries, with an additional unsafe shell/Python script issue.

Install only if you are comfortable with a wellness-branded skill acting as a general productivity journal. Avoid storing secrets, regulated health information, credentials, incident details, customer data, or confidential work plans in it. Review and fix the shell argument handling and file permissions before using it with untrusted inputs or on shared systems.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sleep_diary.sh:29
Finding

User-Controlled Arguments Are Interpolated into Executable Python Source

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:6
Finding

Sensitive Health and Activity Records Are Created Without Restrictive Permissions

Content
View full analysis
"$DB" ``` ### Technical Analysis The scripts store sleep history, health-related measurements, reminders, schedules, task information, and exports in persistent files under the user's home directory. They do not set a restrictive `umask`, specify directory modes, or enforce file permissions after creation. The resulting permissions depend entirely on the process's ambient `umask`. Under a common `022` umask, newly created directories are generally mode `0755` and files are generally mode `0644`. On a multi-user system, this can permit other local accounts to traverse the data directories and read stored records. Generated export files and log files inherit the same problem. The health and activity information remains persistently exposed until permissions are corrected. ### Attack Path 1. The Skill runs under a permissive `umask`, such as `022`. 2. `mkdir -p` creates a data directory that may be traversable and readable by other local users. 3. Shell redirection creates databases, logs, and exports with group- or world-readable permissions. 4. Another local account locates the predictable paths under the victim's home directory. 5. That account reads sleep records, routines, reminders, schedules, task history, or exported data. ### Impact Assessment The primary impact is local confidentiality loss. Exposed data may reveal sleep patterns, expected waking and sleeping times, personal routines, work activities, reminders, and ...[truncated 300 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:58
Finding

JSON and CSV Exports Do Not Escape Attacker-Controlled Record Values

Content
View full analysis
"$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "" >> "$out" echo "]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" done ;; ``` ### Technical Analysis The JSON exporter places values directly between quotation marks without escaping JSON metacharacters. A record containing a quotation mark, backslash, control character, or newline can make the result invalid or alter its logical structure. The CSV exporter concatenates fields with commas without applying RFC 4180 quoting. Record values containing commas, quotation marks, or newlines can create additional rows or columns. Furthermore, values beginning with spreadsheet formula prefixes such as `=`, `+`, `-`, or `@` may be interpreted as formulas when the CSV is opened in spreadsheet software. This creates a downstream formula-injection risk when exported data includes attacker-controlled entries. ### Attack Path 1. An attacker causes crafted text to be stored through one of the logging commands. 2. The victim runs `sleepwell export json` ...[truncated 834 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest advertises a sleep-tracking skill, but the documented behavior is a broad productivity logger with task, sprint, report, search, and export functions. This mismatch is dangerous because users may disclose sensitive work or personal information under false assumptions about the skill's purpose and data handling, and security reviewers may under-scope their evaluation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The top-level documentation immediately shifts from sleep tracking to a generic productivity/task-management toolkit, contradicting the manifest. Security-sensitive users could be misled into invoking unrelated logging functions that capture broader personal or organizational history than expected.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill exposes numerous capabilities unrelated to sleep tracking, including reminders, archives, reports, search, recent history, status, and export. Broad hidden scope increases the risk of overcollection, retention, and disclosure of sensitive data, especially because these functions enable aggregation and retrieval across logs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script materially diverges from the declared sleep-tracking purpose and instead exposes a broad generic note-taking/productivity interface. This kind of scope mismatch is dangerous because it can mislead users and host systems into granting trust, permissions, or invocation contexts intended for a narrowly scoped sleep tool, while the implementation stores arbitrary user input across many unrelated categories.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documentation describes persistent local storage and export capabilities but does not declare any explicit tool scope or permissions boundary. This creates a transparency and governance problem: a user or hosting platform may believe the skill is narrowly scoped while it can write files and retain potentially sensitive data on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill stores timestamped entries, searchable history, and export files, but the description does not warn that this may include sensitive personal or work data. Users may unknowingly create a durable local record of health habits, schedules, and operational notes that could later be exposed through local compromise, backups, or accidental sharing of exports.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage guidance instructs users to log tasks, sprint plans, and deployment history despite the skill being branded as a sleep tracker. This context makes the mismatch more dangerous because it normalizes storing sensitive work-operational information in a tool the user may perceive as harmless wellness software.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The inline documentation labels the tool as a productivity tool, directly contradicting the manifest's sleep-tracking description. While not directly exploitable on its own, this inconsistency is a trust and review risk because it signals the skill may have been repurposed or mislabeled, reducing transparency and making policy evasion or accidental overtrust more likely.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help output presents the program as a productivity toolkit and advertises many non-sleep commands, confirming that runtime behavior does not match the declared skill purpose. In a skill ecosystem, misleading help and command discovery increase the chance of unauthorized or unexpected use beyond the approved domain, especially when users rely on the manifest to assess safety and scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell script creates a persistent directory under the user's home folder and initializes a JSON database file, which affects local user data storage. While later commands print confirmations, these setup writes occur automatically on startup without any visible warning, prompt, or explanatory comment about creating and storing sleep records on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script appends bedtime and wakeup entries to times.csv, which persists potentially sensitive health-related routine data. Although the commands echo the entered time afterward, there is no warning in the help text or comments that these values are stored on disk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.