Back to skill

Security audit

Quote Swarm

Security checks for vulnerabilities and agentic risk

Overview

This smart-home quotation skill is mostly purpose-aligned, but it under-declares persistent file writes and uses broad triggers plus unsafe path construction that need review.

Review this skill before installing. It should either request narrowly scoped write permission or remove the automatic file-creation steps, sanitize customer names before using them in paths, narrow its activation triggers, and document where customer documents and generated records are stored and when they are cleaned up.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:86
Finding

User-Controlled Path Traversal in Task Initialization

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 86–88 and 128–129
Vulnerability Type: Path traversal caused by an unsanitized customer identifier
Risk Level: Medium

bash
TASK_NAME="quote-${CUSTOMER}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
...
touch ~/.workbuddy/tasks/"$TASK_NAME"/research-findings.md
cat > ~/.workbuddy/tasks/"$TASK_NAME"/progress-log.md << 'EOF'

Technical Analysis

The CUSTOMER value is incorporated directly into TASK_NAME, which is then used as part of several filesystem paths. Although quoting the variable prevents shell word splitting and direct shell-command injection, it does not neutralize path separators or traversal components such as ../.

If an untrusted party controls the customer name, a value containing traversal sequences can cause the resulting path to resolve outside the intended ~/.workbuddy/tasks/ directory. The commands then create directories and write fixed-name files at the attacker-selected resolved location.

Attack Path

  1. An attacker supplies a customer name containing path traversal components, such as multiple ../ segments.
  2. The agent assigns that unvalidated value to CUSTOMER.
  3. The documented initialization block constructs TASK_NAME from the malicious value.
  4. mkdir, cat, and touch resolve the traversal components when operating on the generated paths.
  5. The operations escape the expected task directory and create or overwrite task-plan.md, progress-log.md, and research-findings.md in another directory writable by the executing user.

Exploitation requires the agent to run the documented shell block with an attacker-controlled customer name.

Impact Assessment

The attacker does not gain additional operating-system privileges. File operations execute with the permissions of the user running the Skill.

Within that use ...[truncated 547 chars]

Remediation
View remediation

Remediation Suggestions

  1. Convert the customer name to a strict filesystem-safe identifier before constructing TASK_NAME. Allow only a narrow character set such as ASCII letters, digits, underscores, and hyphens.
  2. Reject empty values, . and .., path separators, control characters, shell metacharacters, and names exceeding a reasonable length.
  3. Construct the destination from a fixed base directory and verify its canonical path remains beneath that base before performing any write.
  4. Create the task directory securely and fail if it already exists to reduce accidental or malicious overwrites.
  5. Avoid writing through symbolic links. Validate directory ownership and permissions, and use no-clobber or exclusive file-creation behavior where supported.
  6. Keep display names separate from filesystem identifiers so the original customer name never needs to be used as a path component.

Example hardening approach:

bash
SAFE_CUSTOMER=$(printf '%s' "$CUSTOMER" | tr -cd 'A-Za-z0-9_-')
[ -n "$SAFE_CUSTOMER" ] || {
  echo "Invalid customer identifier" >&2
  exit 1
}

BASE_DIR="$HOME/.workbuddy/tasks"
TASK_NAME="quote-${SAFE_CUSTOMER}-$(date +%Y%m%d)"
TASK_DIR="$BASE_DIR/$TASK_NAME"

mkdir -p -- "$BASE_DIR"
mkdir -- "$TASK_DIR" || exit 1

Canonical containment and symbolic-link checks should additionally be applied before creating the output files.

Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Scope Creep

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill declares only file-read and network-access permissions, but the documented workflow explicitly creates directories and writes multiple files under ~/.workbuddy/tasks. This is a permission/behavior mismatch that can mislead operators and downstream enforcement, and it enables persistent state creation outside the declared capability boundary.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The when_to_use field includes broad phrases like '出方案' and '全链路报价,' which are generic enough to match ordinary conversation. Over-broad activation criteria increase the risk of unintended invocation, causing the skill to process local files or network resources in contexts the user did not intend.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The stated safety boundary says the agent should 'only change quantities,' but the skill also instructs creation of task-tracking documents and multiple deliverable artifacts. This contradiction weakens operator trust and can cause the agent to exceed its intended scope, especially when handling customer data and generated outputs.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger list contains many ambiguous phrases such as '报价', '出方案', and '户型解析' without constraints. In a skill with file-read and network-access, accidental activation is more dangerous because it may initiate document parsing, remote requests, or multi-step workflows on unrelated tasks.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

This duplicate persistence pattern reflects the same behavior: automatic creation of long-lived local records for the task. Even if intended for convenience, undocumented retention of operational and customer information broadens exposure if other tools, users, or later sessions can read those files.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
TASK_NAME="quote-${CUSTOMER}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 报价方案

Session Persistence

Medium
Category
Rogue Agent
Confidence
98% confidence
Finding

This duplicate persistence pattern reflects the same behavior: automatic creation of long-lived local records for the task. Even if intended for convenience, undocumented retention of operational and customer information broadens exposure if other tools, users, or later sessions can read those files.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

bash
TASK_NAME="quote-${CUSTOMER}-$(date +%Y%m%d)"
mkdir -p ~/.workbuddy/tasks/"$TASK_NAME"
cat > ~/.workbuddy/tasks/"$TASK_NAME"/task-plan.md << 'EOF'
# 任务计划 - 报价方案

Static analysis

No suspicious patterns detected.