Back to skill

Security audit

Code Tester

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plausible code tester, but one bundled path resolver can execute shell syntax from a project path and also searches outside the workspace.

Review before installing. The core idea is ordinary build/test automation, but the resolver should remove eval, constrain project lookup to the workspace or explicit user-approved paths, and use private per-run temporary log files. Treat a successful result as build/test validation only, not proof that the application actually ran correctly.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/resolve_project.sh:11
Finding

Arbitrary Command Execution Through Unsafe Path Expansion

Content
View full analysis
/tmp/resolve-project-proof)' ``` 2. The prefix check accepts the argument because it begins with `./`. 3. `eval` reparses the resulting command: ```bash echo ./$(id > /tmp/resolve-project-proof) ``` 4. The command substitution executes `id` with the privileges of the Skill process. 5. The directory validation may subsequently fail, but the injected command has already run. An attacker could replace the demonstration command with any command available to the executing account. ### Impact Assessment Successful exploitation provides arbitrary command execution with the same operating-system privileges as the process invoking the Skill. If the Skill runs under the documented root-oriented environment, the impact may include access to root-readable dat ...[truncated 276 chars]
Remediation
View remediation
/dev/null); then echo "Error: Invalid path" >&2 exit 1 fi if [ ! -d "$EXPANDED" ]; then echo "Error: Directory not found: $EXPANDED" >&2 exit 1 fi ``` Additional hardening measures: - Treat the argument exclusively as data and never evaluate it as shell source. - Use `realpath --` or `readlink -f --` to canonicalize paths. - Add the `--` end-of-options delimiter when passing user-controlled paths to commands that support it. - If projects must remain inside an approved workspace, verify that the canonical path is beneath that workspace. - Add regression tests with inputs containing `$(...)`, backticks, semicolons, pipes, redirections, spaces, and newline characters. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/test.sh:46
Finding

Predictable Shared Temporary Log Files Permit Symlink Attacks and Cross-Run Data Exposure

Content
View full analysis
&1 | tee /tmp/code-tester-tests.log cargo build 2>&1 | tee /tmp/code-tester-build.log go test ./... 2>&1 | tee /tmp/code-tester-tests.log go build 2>&1 | tee /tmp/code-tester-build.log mvn test 2>&1 | tee /tmp/code-tester-tests.log mvn compile 2>&1 | tee /tmp/code-tester-build.log ./gradlew test 2>&1 | tee /tmp/code-tester-tests.log ./gradlew build -x test 2>&1 | tee /tmp/code-tester-build.log ``` ### Technical Analysis The script writes test and build output to fixed names in the globally shared `/tmp` directory. It does not securely create the files, verify their ownership or type, assign restrictive permissions, or isolate concurrent executions. Where operating-system symlink protections allow it, an attacker able to write to `/tmp` can create one of these paths as a symbolic link before the Skill runs. `tee` then opens and truncates the linked destination using the Skill process's privileges. Even when symlink-following protections block that attack, fixed shared filenames still create security and reliability concerns: - Concurrent invocations overwrite or intermix one another's logs. - Existing files controlled by another account can cause failures or unexpected writes. - Log files may be created with permissions derived from a permissive process `umask`. - Compiler and test output can contain source paths, environment details, tokens printed by tests, internal endpoints, or other sensitive diagnostics. ### Attack Path A local attacker can attempt the following sequence: 1. Create a symbolic link at a predictable log path: ```bash ln -s /path/to/writable-target /tmp/code-tester-build.log ``` 2. Wait for a more privileged user or autom ...[truncated 1140 chars]
Remediation
View remediation
&2 exit 1 } trap 'rm -rf -- "$LOG_DIR"' EXIT HUP INT TERM TEST_LOG="$LOG_DIR/tests.log" BUILD_LOG="$LOG_DIR/build.log" ``` Use the generated paths in every pipeline: ```bash cargo test 2>&1 | tee "$TEST_LOG" cargo build 2>&1 | tee "$BUILD_LOG" ``` Additional hardening measures: - Apply `umask 077` before creating logs so only the executing account can read them. - Avoid placing sensitive persistent logs in `/tmp`; move retained results to an access-controlled application directory. - If logs must survive execution, copy them from the private temporary directory to a uniquely named destination after validating destination ownership. - Never reuse fixed filenames across concurrent invocations. - Preserve the existing cleanup trap if new signal handling is added. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill metadata and description claim it verifies that the application 'runs without errors' and communicates results back, but the documented behavior only runs tests/build steps via a shell script and reports a format for responses. This mismatch can mislead downstream agents into trusting that runtime validation occurred when it did not, creating unsafe assumptions about deployment readiness or code safety.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill metadata and description claim it verifies that the application 'runs without errors' and communicates results back, but the documented behavior only runs tests/build steps via a shell script and reports a format for responses. This mismatch can mislead downstream agents into trusting that runtime validation occurred when it did not, creating unsafe assumptions about deployment readiness or code safety.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Using eval on user-controlled input enables shell command execution during path expansion, not just pathname resolution. A crafted input such as shell substitution or metacharacters could execute arbitrary commands as the script user, which is especially dangerous here because this helper is meant only to locate code projects, not interpret shell syntax.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The resolver searches under /root outside the declared workspace scope, allowing a caller to enumerate or resolve directories unrelated to the project-testing task. In this skill context, that expands access from intended workspace projects to potentially sensitive home-directory content, which is an unnecessary privilege increase and can expose paths or enable downstream commands to operate on unintended directories.

Content

No source excerpt is available for this finding.