Back to skill

Security audit

Student

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its student-assistant purpose, but its note command can write outside the promised notes folder when given a crafted subject name.

Review before installing. Use this only for non-sensitive coursework files, and avoid passing subjects that contain slashes, dot-dot path components, or symlinked folders until the note path handling is fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:34
Finding

Path Traversal Allows Note Files to Be Written Outside the Intended Storage Directory

Content
View full analysis
\"\"" echo " Example: script.sh note biology \"Mitosis has 4 phases: prophase, metaphase, anaphase, telophase\"" exit 1 fi ensure_data_dir local subject_dir="${NOTES_DIR}/${subject}" mkdir -p "${subject_dir}" local ts ts="$(timestamp)" local filename="${subject_dir}/$(today).md" # Append to the day's note file { echo "" echo "## ${ts}" echo "" echo "${content}" echo "" } >> "${filename}" ``` ### Technical Analysis The `note` command treats the user-controlled `subject` argument as a trusted directory name. It concatenates that value directly with `${NOTES_DIR}` and passes the resulting path to `mkdir -p`: ```bash local subject_dir="${NOTES_DIR}/${subject}" mkdir -p "${subject_dir}" ``` The implementation does not reject path separators, `..` components, or paths that traverse symbolic links. Consequently, a subject such as `../../escaped` resolves outside the documented `~/.student/notes/` storage boundary. After creating the directory, the command constructs a date-based Markdown filename under the traversed path and appends attacker-controlled note content to it. Shell quoting prevents command injection, but it does not prevent filesystem path traversal. Pre-existing symbolic links beneath the notes directory may also redirect the write to another location because the implementation neither rejects symlinks nor verifies the canonical destination before opening the file. ### Attack Path 1. An attacker or untrusted caller invokes the Skill with a traversal sequence as the subject: ```bash bash ...[truncated 1522 chars]
Remediation
View remediation
&2 exit 1 fi ``` 2. **Explicitly reject path syntax.** Reject `/`, `\`, standalone `.` or `..` components, control characters, and newline characters. 3. **Verify the canonical destination.** Resolve both the notes root and destination with a reliable canonicalization mechanism, then ensure the destination remains beneath the canonical notes root before creating or writing files. 4. **Defend against symbolic-link traversal.** Reject pre-existing symlink components or open files using an implementation that supports no-follow semantics. Canonical-path validation alone should not be relied upon where another process can change path components between validation and use. 5. **Apply restrictive permissions.** Create the data directory with user-only permissions where appropriate: ```bash umask 077 mkdir -p -- "${NOTES_DIR}" ``` 6. **Use `--` for path-taking commands.** Although this does not prevent traversal, it prevents option interpretation for paths beginning with a hyphen: ```bash mkdir -p -- "${subject_dir}" ``` 7. **Add regression tests** covering `../`, nested traversal, slashes, symbolic links, control characters, and valid subject identifiers. Tests should verify that every resulting note path remains under `~/.student/notes/`. ]]>
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
bash scripts/script.sh note <subject> "<content>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
bash scripts/script.sh note <subject> "<content>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
bash scripts/script.sh note <subject> "<content>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
bash scripts/script.sh note <subject> "<content>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
bash scripts/script.sh note <subject> "<content>"

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
bash scripts/script.sh note <subject> "<content>"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises commands that read arbitrary local files via summarize <file_path>, but it does not declare any explicit tool scope or permission boundaries. That omission can allow the agent framework to invoke file-reading behavior without clear user-visible constraints, increasing the chance of overbroad access to sensitive local files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description 'Help with coursework' is broad enough to trigger in many academic contexts, which can cause the skill to activate when the user did not specifically request it. Over-broad activation increases the chance that file-reading or note-writing features are used in unintended contexts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

Generates a formatted citation string in APA or MLA style.

outline — Create an essay outline

bash
bash scripts/script.sh outline "<topic>" <num_sections>

Static analysis

No suspicious patterns detected.