T09 · Insecure Skill Coding Practices
- Location
scripts/inbox.js:212- Finding
Unescaped User-Controlled Content in Markdown Rendering
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a local operator inbox with disclosed local storage and no network behavior, but users should treat stored and rendered messages as potentially sensitive.
Install only if you want agents to keep a local inbox of operational notes. Keep the workspace private, avoid storing secrets or credentials in messages, and be cautious rendering untrusted content to Slack or Discord because formatting and mentions may not be escaped.
scripts/inbox.js:212Unescaped User-Controlled Content in Markdown Rendering
scripts/inbox.js:27Predictable Temporary File Allows Symlink-Based File Overwrite
scripts/inbox.js:19Potentially Sensitive Inbox Data Uses Umask-Dependent Permissions
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger guidance says the operator asking to see their inbox or saying 'inbox', 'messages', or 'check inbox' should cause the skill to run. Terms like 'messages' are overly generic and can be invoked accidentally during ordinary conversation, causing unintended data disclosure or stateful actions in the wrong context.
No suspicious patterns detected.