Back to skill

Security audit

Persona Spawn

Security checks for vulnerabilities and agentic risk

Overview

This skill’s persona-spawning purpose is coherent, but it imports mutable remote prompt content and can include broad local files in subagent prompts, so users should review it before installing.

Install only if you are comfortable with persona files from the referenced GitHub marketplace influencing spawned subagents. Review imported personas before use, avoid --all unless you trust the source, keep context_files limited to non-secret documents, and do not point context_files at credentials, private keys, agent state, or unrelated personal files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T01 · Skill Instruction Hijacking

Error
Location
scripts/build-persona-prompt.py:17
Finding

Authoritative persona directive enables subagent instruction hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
scripts/import-persona.sh:54
Finding

Mutable remote persona archive is imported without integrity verification

Content
View full analysis
&2 rm -rf "$TMPDIR" return 1 fi mkdir -p "$DEST_ROOT" cp -r "$SRC_DIR"/* "$DEST_ROOT"/ ``` The single-persona path has the same mutable-source problem at `scripts/import-persona.sh:34-48`, where files are fetched from `raw.githubusercontent.com/decentraliser/personas/main`. ### Technical Analysis The importer downloads content from the mutable `main` branch of a third-party repository. It performs no commit pinning, checksum comparison, signature verification, trusted-manifest validation, or content review before extraction and installation. The downloaded archive is not directly executed as a native executable or shell script. Nevertheless, its `SOUL.md` and `IDENTITY.md` files are subsequently inserted into subagent prompts and influence agent behavior. Their integrity is therefore security-sensitive. The `--all` path also copies all entries under the upstream `personas` directory into the local destination without restricting expected names or file types. TLS protects the connection in transit but does not protect against repository compromise, malicious upstream changes, account takeover, or an unreviewed change to the mutable branch. ### Attack Path 1. An attacker compromises the upstream repository or obtains permission to modify its `main` branch. 2. The attacker adds malicious persona instructions or unexpected files to the reposit ...[truncated 996 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/build-persona-prompt.py:42
Finding

Context configuration permits unrestricted local file ingestion

Content
View full analysis
list[tuple[Path, str]]: config_path = personas_dir / "config.json" if not config_path.exists(): return [] try: config = json.loads(config_path.read_text(encoding="utf-8")) except (OSError, json.JSONDecodeError) as exc: raise SystemExit(f"Failed to parse {config_path}: {exc}") from exc context_files = normalize_context_files(config.get("context_files")) loaded: list[tuple[Path, str]] = [] for rel in context_files: candidate = Path(rel) resolved = (config_path.parent / candidate).resolve() if not candidate.is_absolute() else candidate.resolve() if not resolved.exists(): raise SystemExit(f"Shared context file not found: {resolved}") loaded.append((resolved, read_text(resolved))) return loaded ``` ### Technical Analysis The `context_files` setting accepts absolute paths as well as relative paths containing `..`. The code resolves those paths but never verifies that the result remains within the workspace or another approved directory. It also does not reject symlinks, non-regular files, sensitive file classes, or excessively large files. Reading selected organization documents is part of the Skill's declared functionality. Allowing arbitrary files anywhere readable by the process exceeds the minimum filesystem access required for that function. The loaded contents are inserted into the assembled prompt, which exposes them to the spawned subagent and potentially to the model provider handling that prompt. ### Attack Path 1. An attacker or compromised process gains the ability to modify `/personas/config.json`. 2. The attacker adds an absolute path or traversing relative path, such as a cr ...[truncated 862 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/import-persona.sh:30
Finding

Unvalidated persona handle permits destination path traversal

Content
View full analysis
/dev/null || echo "000") if [[ "$HTTP_CODE" != "200" ]]; then echo "Error: persona '$HANDLE' not found in marketplace (HTTP $HTTP_CODE)" >&2 return 1 fi mkdir -p "$DEST" echo "Importing $HANDLE..." curl -sf "$BASE/persona.json" > "$DEST/persona.json" && echo " ✓ persona.json" curl -sf "$BASE/SOUL.md" > "$DEST/SOUL.md" && echo " ✓ SOUL.md" curl -sf "$BASE/IDENTITY.md" > "$DEST/IDENTITY.md" 2>/dev/null && echo " ✓ IDENTITY.md" || echo " - IDENTITY.md (not found, optional)" curl -sf "$BASE/avatar.png" > "$DEST/avatar.png" 2>/dev/null && echo " ✓ avatar.png" || true } ``` ### Technical Analysis `HANDLE` is incorporated directly into both a URL path and the local destination path. No syntax validation or canonical containment check is performed. A value containing `../` can cause `DEST_ROOT/$HANDLE` to resolve outside the intended persona directory. The preliminary HTTP request reduces exploitability because the normalized upstream path must produce a valid `persona.json`. It does not establish local path safety, however. If that precondition is satisfied, shell redirections create or truncate fixed file names in the escaped destination before `curl` writes their content. ### Attack Path 1. An attacker influences the handle supplied to `import-persona.sh`. 2. The attacker supplies a handle containing traversal components whose normalized remote URL resolves to an upstream location containing `persona.json`. 3. The HTTP existence che ...[truncated 763 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/ensure-personas.py:29
Finding

Bootstrap operation recursively deletes existing persona directories

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill advertises persona selection and context injection, but the described implementation does not clearly guarantee that those delegation semantics occur; instead it focuses on local indexing and metadata generation. This can undermine governance and review controls because operators may authorize a seemingly harmless persona feature that actually performs broader environment changes.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill directs the agent to read and write workspace files and execute shell commands, but it does not declare any explicit tool scope or permissions boundary. That makes the operational capability broader and less auditable than the metadata suggests, increasing the chance of unintended file modification or command execution when the skill is invoked.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation guidance is broad enough to trigger on ordinary requests about style, voice, or roleplay, which can cause unnecessary subagent spawning, prompt injection of persona files, or execution of setup steps when the user only wanted a conversational tone change. In a skill that reads local files, writes configs, and shells out to scripts, over-broad activation increases accidental exposure and misuse risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/ensure-personas.py (reported line 41)May include surrounding context.

python
shutil.copytree(child, dest)
            else:
                shutil.copy2(child, dest)
        subprocess.run([sys.executable, str(rebuild), str(personas_dir)], check=True, stdout=subprocess.DEVNULL)
        print(f"Bootstrapped starter personas into {personas_dir}", file=sys.stderr)

    if not config_path.exists():

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/import-persona.sh (reported line 57)May include surrounding context.

sh
TMPDIR="$(mktemp -d)"

  echo "Downloading persona archive..."
  curl -Lsf "https://github.com/decentraliser/personas/archive/refs/heads/main.tar.gz" -o "$TMPDIR/personas.tar.gz"
  tar xzf "$TMPDIR/personas.tar.gz" -C "$TMPDIR"

  local SRC_DIR="$TMPDIR/personas-main/personas"

Static analysis

No suspicious patterns detected.