Back to skill

Security audit

Hexdump Tool

Security checks for vulnerabilities and agentic risk

Overview

This is a small local hexdump utility with minor large-file memory risk and lightly under-described conversion options, but no evidence of deception, exfiltration, persistence, or privileged behavior.

Install only if you are comfortable with a local utility that reads files or stdin you ask it to inspect. Avoid running it on very large or untrusted streams until it is changed to process input incrementally, and the publisher should update the description to mention the encode/decode options.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/hexdump.py:54
Finding

Unbounded Input Buffering Enables Memory Exhaustion

Content
View full analysis

Vulnerability Details

File Location: scripts/hexdump.py, lines 54–64
Vulnerability Type: Uncontrolled resource consumption
Risk Level: Medium

Vulnerable Code:

python
elif args.file:
    try:
        with open(args.file, 'rb') as f:
            data = f.read()
        hexdump(data, args.offset, args.length)
    except FileNotFoundError:
        print(f"Error: File not found: {args.file}", file=sys.stderr)
        sys.exit(1)
else:
    # Read from stdin
    data = sys.stdin.buffer.read()
    hexdump(data)

Technical Analysis

Both file and standard-input processing use unbounded read() operations, causing the entire input to be buffered in memory before processing begins. For file input, the --length option does not mitigate this behavior because it is passed to hexdump() only after the complete file has been read. The slicing performed inside hexdump() therefore limits displayed output but not memory consumption.

Standard input is likewise read until end-of-file without a size constraint. A very large file or attacker-controlled stream can consequently consume all available process memory. No command execution, elevated privileges, network access, persistence, or data exfiltration is involved.

Attack Path

  1. An attacker supplies or identifies a file large enough to exceed the memory available to the process or host, or provides an extremely large stream through standard input.
  2. A user or automated agent invokes the tool against that input, potentially using --length under the incorrect assumption that it constrains the amount read.
  3. f.read() or sys.stdin.buffer.read() buffers the entire input.
  4. Memory usage grows until the process becomes unresponsive, is terminated by the operating system, or causes broader host resource pressure.

Impact Assessment

Exploitation requires the ability to influence the input file or stdin stream processed by the ...[truncated 374 chars]

Remediation
View remediation

Remediation Suggestions

Process input incrementally rather than buffering it in full:

  1. Read files and stdin in fixed-size chunks, such as 4–64 KiB.
  2. If --length is specified, track the remaining byte count and never read more than that limit.
  3. Preserve offsets between chunks so output addresses remain correct.
  4. Reject negative --length values and consider enforcing a configurable maximum when the tool is used by an automated agent.
  5. Apply operating-system or container memory and execution-time limits as defense in depth.
  6. Handle MemoryError, broken pipes, and relevant OSError exceptions gracefully.

For bounded file reads, use an approach such as f.read(args.length) when a valid length is provided. For unrestricted output and stdin, iterate over fixed-size chunks and emit each chunk before reading the next one.

Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The main declared purpose is a hexdump/display tool, and the core code does perform that function by reading binary data from a file or stdin and printing offsets, hex bytes, and ASCII representations. However, the code also exposes additional user-facing capabilities unrelated to simply displaying file contents: it can encode strings to hex and decode hex strings back to text via command-line options. These are undeclared capabilities, so the description does not fully represent the actual behavior.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a tool for displaying file contents in hexadecimal and ASCII format for binary inspection. However, the code also provides standalone string-to-hex and hex-to-string conversion modes, which go beyond merely displaying file contents as a hexdump.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.