Back to skill

Security audit

File Inbox

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent local file inbox skill, but it needs review because it can move files by default and stores unsanitized file metadata in a persistent index that agents are told to read.

Review this skill before installing. Use it only in workspaces where moving files into an inbox is expected, prefer --copy when preserving originals matters, and treat inbox/INDEX.md as untrusted data if filenames, sender names, tags, or notes may come from other people.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/register_file.py:134
Finding

Persistent Markdown Injection in the Inbox Index

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/register_file.py:184
Finding

Directory Paths Are Accepted by a File-Only Registration Operation

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description presents a general bidirectional file management system used to save user files, generate/send files, and find/list/search previously exchanged files. The supplied code chunk does not implement those core behaviors. Instead, it is a narrow reporting script that inspects an existing inbox directory, parses metadata and an index markdown table, measures directory sizes, and prints summary statistics such as totals, file types, tags, and recent activity. While this is related to the same inbox resource, its primary purpose is analytics/status display, not file management or retrieval. Therefore the description materially overstates and mischaracterizes what this code chunk actually does.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script performs a move operation by default, which removes the file from its original location and is a user-data-affecting action. Although the usage text mentions 'move' as the default, there is no runtime confirmation prompt or explicit warning immediately before the operation in code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.