Back to skill

Security audit

Decision Recorder

Security checks for vulnerabilities and agentic risk

Overview

This decision logger is mostly purpose-aligned, but a path-handling bug could let its view, update, or delete functions affect JSON files outside its own storage folder.

Review before installing. The skill does not show hidden remote code, exfiltration, install hooks, or deceptive instructions, but it should validate decision IDs and enforce directory containment before view/update/delete are safe. Avoid recording secrets or highly sensitive planning details unless local file permissions are hardened, and prefer a fixed version that stores files with owner-only permissions and has clear retention/deletion behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/index.js:126
Finding

Path Traversal Enables Arbitrary JSON File Read, Deletion, and Overwrite

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/index.js:26
Finding

Decision Records Are Created Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

The skill is designed to persist user-provided decision records across sessions in local storage, and those records may contain sensitive technical, product, team, or personal planning rationale. Session persistence is a genuine privacy/security concern here because retained records can expose confidential context, strategic decisions, or personal information if stored without clear consent, retention guidance, or access protections.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Core capabilities

- Detect decision-oriented text
- Create structured decision records
- Search and filter past decisions
- Review decision details
- Analyze decision patterns

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly supports deleting stored decision records but does not warn users that invoking the delete command can permanently remove locally stored data under ~/.decision-recorder/. This is a real safety/usability weakness because an agent could surface or invoke destructive functionality without making the irreversible consequence clear, increasing the risk of unintended data loss.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code presents help text entirely in Chinese and formats dates with a hard-coded 'zh-CN' locale, which imposes a specific language/locale on all users. The file does not offer any opt-in, configuration, or documented justification for this locale restriction.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill persists potentially sensitive decision content to a fixed local directory in the user's home folder without any notice, consent flow, or visibility at the point of collection. Because decision records may contain product plans, internal rationale, credentials accidentally pasted by users, or personal notes, silent local persistence creates a privacy and data-handling risk, especially in an agent context where users may not expect durable storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The delete function irreversibly removes a decision record as soon as it is called, with no confirmation, soft-delete, or recovery mechanism. In an agent-driven workflow, mistaken invocation, prompt confusion, or misuse by another component can lead to loss of potentially important historical rationale and auditability.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The package description is written entirely in Chinese, which indicates a fixed language choice in user-facing metadata without offering any language or locale option. Under the policy, forced language presentation without user opt-in can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The file embeds Chinese-language naming, messages, and keyword triggers together with English equivalents, but does not indicate any user-selectable language or locale preference. Because the skill behavior is partially tied to fixed language choices, this may violate a policy requiring language/locale opt-in rather than implicit enforcement.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.