Back to skill

Security audit

Design Swarm

Security checks for vulnerabilities and agentic risk

Overview

This design workflow skill is not malicious, but it asks for and instructs persistent local actions in ways that are under-scoped and should be reviewed before installation.

Review this skill before installing. It appears intended to manage smart-home design deliverables, but it can create persistent local task files containing customer/project details, declares network access without a clear need, and uses an unsafe customer-name path pattern. Install only if you are comfortable with those behaviors and can constrain or correct the write scope, retention, and input sanitization.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:7
Finding

Excessive and Inconsistent Skill Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:88
Finding

Path Traversal Through Unsanitized Customer Name

Content
View full analysis
~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF' ``` The same constructed path is subsequently used for additional file operations: ```bash touch ~/.workbuddy/tasks/"$TASK_NAME"/research-findings.md cat > ~/.workbuddy/tasks/"$TASK_NAME"/progress-log.md << 'EOF' ``` ### Technical Analysis The externally derived `CUSTOMER` value is incorporated directly into a filesystem path without validation or canonicalization. Shell quoting prevents ordinary command substitution and metacharacter-based shell injection, but it does not neutralize path separators, `..` components, absolute-path-like structures embedded after a separator, or symlink traversal. A value containing directory traversal components can cause the normalized task path to resolve outside `~/.workbuddy/tasks`. The subsequent `mkdir`, `cat >`, and `touch` operations then create or overwrite files in the redirected directory. The fixed `design-` prefix and date suffix constrain the exact destination name, but they do not guarantee that the resolved destination remains beneath the intended task root. Existing symlinks or a race involving writable path components can further redirect the operations. ### Attack Path 1. An attacker supplies or influences the customer name used as `CUSTOMER`. 2. The attacker includes path separators and traversal components, such as a value structurally similar to `client/../../../tmp/target`. 3. The skill constructs `TASK_NAME` without rejecting those components. 4. `mkdir -p` resolves the resulting path and may create a task directory outside `~/.workbuddy/tasks`. 5. The `cat >` and `touch` commands write `task-plan.md`, `research-findings.md`, and `progress-log.md` in tha ...[truncated 822 chars]
Remediation
View remediation
&2 exit 1 ;; esac TASK_ROOT="$HOME/.workbuddy/tasks" TASK_NAME="design-${CUSTOMER}-$(date +%Y%m%d)" TASK_DIR="$TASK_ROOT/$TASK_NAME" mkdir -m 700 -- "$TASK_DIR" ``` 9. For stronger protection, implement path construction and canonical containment checks in a language with robust path APIs rather than relying only on shell string handling. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Scope Creep

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill declares only file-read permission, but its instructions explicitly create directories and write multiple files under ~/.workbuddy/tasks. This is a real permission/behavior mismatch that can mislead the runtime or reviewer about the skill’s capabilities and enable unauthorized local state creation, including persistent task artifacts containing customer or project data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The description and operational content are presented in Chinese, but the file does not state that the skill is region-specific or give users a language choice. Per policy, forcing a specific language without opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The when_to_use description broadly says to use the skill whenever a full design workflow is needed and includes generic trigger words, but it does not clearly define exclusions or confirmation requirements. This ambiguity can lead to accidental invocation of a skill that has network access and instructions for local persistence, making unintended execution more dangerous in context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains broad, common design phrases such as rendering, design drawings, floorplans, and icons, which can cause the skill to activate in contexts where the user did not intend to invoke it. Over-broad activation increases the chance that a network-enabled skill with operational instructions is engaged on unrelated requests, expanding the attack surface and risking unintended data handling.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicated finding points to the same session-persistence behavior: the skill writes multiple workflow files into a durable user directory. In the context of a design workflow that may process customer floorplans, device inventories, and delivery progress, persistence meaningfully raises the risk of leaking sensitive project metadata across sessions or to other tools.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

bash
TASK_NAME="design-${CUSTOMER}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 设计交付

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

This duplicated finding points to the same session-persistence behavior: the skill writes multiple workflow files into a durable user directory. In the context of a design workflow that may process customer floorplans, device inventories, and delivery progress, persistence meaningfully raises the risk of leaking sensitive project metadata across sessions or to other tools.

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

bash
TASK_NAME="design-${CUSTOMER}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 设计交付

Static analysis

No suspicious patterns detected.