Back to skill

Security audit

Time Tool

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small command timer whose command execution behavior is disclosed and aligned with its purpose.

Install this only if you want a helper that can run and time commands you provide. Treat timed commands with the same caution as running them directly in a shell, especially commands that change files, use credentials, or access the network.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes shell command execution (time-tool <command> [args...]) but does not declare any tool scope such as permissions or allowed-tools. This creates an authorization gap where a broadly capable shell may be used without explicit restriction, increasing the risk of arbitrary command execution or misuse in environments that rely on manifest-declared boundaries.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/time.py (reported line 5)May include surrounding context.

python
import time, subprocess, sys
if len(sys.argv) < 2: print("Usage: time.py <cmd>"); sys.exit(1)
start = time.time()
subprocess.run(sys.argv[1:])
print(f"Time: {time.time()-start:.2f}s")

Static analysis

No suspicious patterns detected.