Back to skill

Security audit

Clipboard Tool

Security checks for vulnerabilities and agentic risk

Overview

This clipboard utility is mostly purpose-aligned, but it needs Review because it can copy file contents and prints copied text into terminal or agent logs.

Review before installing. Use this only with non-sensitive clipboard content unless the stdout preview is removed or disabled; do not use it to copy passwords, tokens, keys, or private files in logged agent sessions. The subprocess usage itself appears tied to normal clipboard operation, and no persistence or remote execution was found.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/clipboard.py:53
Finding

Sensitive Clipboard Content Exposed in Standard Output

Content
View full analysis

Vulnerability Details

File Location: scripts/clipboard.py, line 53
Vulnerability Type: Sensitive data exposure through application output
Risk Level: Medium

Vulnerable Code

python
print(f"Copied to clipboard: {text[:50]}{'...' if len(text) > 50 else ''}")

Technical Analysis

Every successful copy operation prints the first 50 characters of the copied value to standard output. The value may originate from the --copy argument or from a file supplied through --file.

Clipboard data commonly contains passwords, access tokens, private keys, personal information, and other secrets. Although the disclosure is limited to 50 characters, that may expose an entire credential or enough sensitive material to compromise it. Standard output may be retained in terminal scrollback, shell-session recordings, CI logs, automation logs, or AI-agent transcripts. This can preserve sensitive content after the clipboard itself has been overwritten or cleared.

Attack Path

  1. A user invokes the tool with sensitive content, for example through --copy or --file.
  2. The tool successfully sends that content to the platform clipboard utility.
  3. Line 53 prints up to the first 50 characters of the content to standard output.
  4. A local observer, log collector, CI operator, session-recording system, or party with access to an agent transcript obtains the disclosed content.
  5. If the preview contains a complete password, token, or other credential, it can be reused against the corresponding resource.

Impact Assessment

The issue does not directly grant additional operating-system privileges. Its scope is the first 50 characters of each value copied with the tool. Depending on the exposed data, the secondary impact could include unauthorized access to accounts, APIs, repositories, or other resources available to the disclosed credential. Exposure persists wherever standard output is logged or recorded.

Remediation
View remediation

Remediation Suggestions

Replace the content-bearing message with a content-free confirmation:

python
print("Copied to clipboard")

If previews are considered necessary, require an explicit opt-in flag, disable previews by default, clearly warn users that content may be logged, and direct diagnostic output only to an appropriately protected destination. Avoid logging clipboard data or file contents at any verbosity level intended for routine use. Add tests verifying that copied values—including representative secrets—never appear in standard output or standard error.

Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill exposes shell-capable usage patterns for a CLI utility but does not declare any tool scope such as explicit permissions or allowed tools. This creates an authorization and review gap: consumers may not realize the skill expects shell/file capabilities, increasing the chance of unintended command execution or broader-than-necessary access.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/clipboard.py (reported line 18)May include surrounding context.

python
if system == 'Linux':
        # Try different clipboard tools
        for cmd in ['xclip', 'xsel', 'wl-paste']:
            if subprocess.call(['which', cmd], stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL) == 0:
                if cmd == 'xclip':
                    return (f'{cmd} -selection clipboard', f'{cmd} -selection clipboard -o')
                elif cmd == 'xsel':

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/clipboard.py (reported line 47)May include surrounding context.

python
try:
        if platform.system() == 'Windows':
            # Windows clip command
            process = subprocess.Popen(copy_cmd, stdin=subprocess.PIPE)
            process.communicate(input=text.encode('utf-8'))
        else:
            # Unix-like systems

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/clipboard.py (reported line 51)May include surrounding context.

python
try:
        if platform.system() == 'Windows':
            # Windows clip command
            process = subprocess.Popen(copy_cmd, stdin=subprocess.PIPE)
            process.communicate(input=text.encode('utf-8'))
        else:
            # Unix-like systems

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/clipboard.py (reported line 72)May include surrounding context.

python
try:
        if platform.system() == 'Windows':
            # Windows PowerShell
            result = subprocess.run(
                ['powershell', '-Command', paste_cmd],
                capture_output=True, text=True, check=True
            )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/clipboard.py (reported line 78)May include surrounding context.

python
)
            return result.stdout
        else:
            result = subprocess.run(
                paste_cmd.split(),
                capture_output=True, text=True, check=True
            )

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is described as performing clipboard operations, but it also reads arbitrary local files and copies their contents to the clipboard. In agent/tooling contexts this broadens data access beyond the declared capability, increasing the risk of unintended sensitive file exfiltration through clipboard output or logs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

In addition to copy, paste, and clear, the CLI supports --upper and --lower transformations. Those are ancillary text-processing capabilities that are not reflected in the stated clipboard-only description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.