T09 · Insecure Skill Coding Practices
- Location
scripts/sleep_diary.sh:29- Finding
User-Controlled Arguments Are Interpolated into Executable Python Source
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill needs review because it is branded as a sleep tracker but mainly documents and ships a broad productivity logger that persistently stores, searches, and exports arbitrary user entries, with an additional unsafe shell/Python script issue.
Install only if you are comfortable with a wellness-branded skill acting as a general productivity journal. Avoid storing secrets, regulated health information, credentials, incident details, customer data, or confidential work plans in it. Review and fix the shell argument handling and file permissions before using it with untrusted inputs or on shared systems.
scripts/sleep_diary.sh:29User-Controlled Arguments Are Interpolated into Executable Python Source
scripts/script.sh:6Sensitive Health and Activity Records Are Created Without Restrictive Permissions
scripts/script.sh:58JSON and CSV Exports Do Not Escape Attacker-Controlled Record Values
The manifest advertises a sleep-tracking skill, but the documented behavior is a broad productivity logger with task, sprint, report, search, and export functions. This mismatch is dangerous because users may disclose sensitive work or personal information under false assumptions about the skill's purpose and data handling, and security reviewers may under-scope their evaluation.
The top-level documentation immediately shifts from sleep tracking to a generic productivity/task-management toolkit, contradicting the manifest. Security-sensitive users could be misled into invoking unrelated logging functions that capture broader personal or organizational history than expected.
The skill exposes numerous capabilities unrelated to sleep tracking, including reminders, archives, reports, search, recent history, status, and export. Broad hidden scope increases the risk of overcollection, retention, and disclosure of sensitive data, especially because these functions enable aggregation and retrieval across logs.
The script materially diverges from the declared sleep-tracking purpose and instead exposes a broad generic note-taking/productivity interface. This kind of scope mismatch is dangerous because it can mislead users and host systems into granting trust, permissions, or invocation contexts intended for a narrowly scoped sleep tool, while the implementation stores arbitrary user input across many unrelated categories.
The skill documentation describes persistent local storage and export capabilities but does not declare any explicit tool scope or permissions boundary. This creates a transparency and governance problem: a user or hosting platform may believe the skill is narrowly scoped while it can write files and retain potentially sensitive data on disk.
The skill stores timestamped entries, searchable history, and export files, but the description does not warn that this may include sensitive personal or work data. Users may unknowingly create a durable local record of health habits, schedules, and operational notes that could later be exposed through local compromise, backups, or accidental sharing of exports.
The usage guidance instructs users to log tasks, sprint plans, and deployment history despite the skill being branded as a sleep tracker. This context makes the mismatch more dangerous because it normalizes storing sensitive work-operational information in a tool the user may perceive as harmless wellness software.
The inline documentation labels the tool as a productivity tool, directly contradicting the manifest's sleep-tracking description. While not directly exploitable on its own, this inconsistency is a trust and review risk because it signals the skill may have been repurposed or mislabeled, reducing transparency and making policy evasion or accidental overtrust more likely.
The help output presents the program as a productivity toolkit and advertises many non-sleep commands, confirming that runtime behavior does not match the declared skill purpose. In a skill ecosystem, misleading help and command discovery increase the chance of unauthorized or unexpected use beyond the approved domain, especially when users rely on the manifest to assess safety and scope.
This shell script creates a persistent directory under the user's home folder and initializes a JSON database file, which affects local user data storage. While later commands print confirmations, these setup writes occur automatically on startup without any visible warning, prompt, or explanatory comment about creating and storing sleep records on disk.
The script appends bedtime and wakeup entries to times.csv, which persists potentially sensitive health-related routine data. Although the commands echo the entered time afterward, there is no warning in the help text or comments that these values are stored on disk.
No suspicious patterns detected.