Back to skill

Security audit

Release Guard

Security checks for vulnerabilities and agentic risk

Overview

Release Guard is a narrow local release-checking skill, with a real but limited temporary-file safety issue in its helper script.

Install only if you are comfortable running a local shell checker over skill folders you choose. Do not run it as root, avoid using it in hostile shared machines, and prefer a patched version that uses mktemp-based private temporary files before relying on it in sensitive environments.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/release-check.sh:43
Finding

Predictable Temporary Files Allow Symlink-Based File Clobbering

Content
View full analysis
/tmp/release-guard-shell-eval.$$ 2>/dev/null; then warn "Potential dynamic shell evaluation found; review these lines:" sed -n '1,20p' /tmp/release-guard-shell-eval.$$ else pass "No dynamic shell evaluation found outside release-check.sh." fi rm -f /tmp/release-guard-shell-eval.$$ if grep -RInE '(api[_-]?key|secret|token|password)[[:space:]]*[:=]' "$skill_dir" \ --exclude-dir=.git --exclude-dir=node_modules >/tmp/release-guard-secret.$$ 2>/dev/null; then warn "Secret-like assignment text found; manually verify it is not a real credential:" sed -n '1,20p' /tmp/release-guard-secret.$$ else ``` ### Technical Analysis The script constructs temporary paths in the shared `/tmp` directory using only the shell process ID (`$$`). Process IDs are observable or predictable by other local users. The files are then opened using ordinary shell output redirection without atomic exclusive creation, ownership validation, or protection against symbolic links. If an attacker creates one of these paths as a symbolic link before the corresponding redirection occurs, the shell follows the link and opens its target with truncation enabled. The target is consequently truncated and then populated with the output produced by `grep`. The later `rm -f` operation removes the attacker-created symbolic link rather than reversing modifications made to its target. This behavior also conflicts with the documented claim that the skill does not modify files. ### Attack Path 1. A local attacker observes or predicts the process ID of a user running `release-check.sh`. 2. The attacker creates a symbolic link wit ...[truncated 1386 chars]
Remediation
View remediation
&2 exit 1 } trap 'rm -rf -- "$tmp_dir"' EXIT HUP INT TERM shell_eval_output="$tmp_dir/shell-eval" secret_output="$tmp_dir/secrets" ``` Use `$shell_eval_output` and `$secret_output` for the two redirections. Quote every reference to these paths: ```bash grep ... >"$shell_eval_output" sed -n '1,20p' "$shell_eval_output" grep ... >"$secret_output" sed -n '1,20p' "$secret_output" ``` Additional hardening measures include: - Do not create predictable files directly under a shared temporary directory. - Fail safely if `mktemp` cannot create the private directory. - Retain `umask 077` so temporary scan results are not readable by other users. - Register cleanup immediately after successful directory creation so files are removed on normal exit and common signals. - Avoid running the release checker with elevated privileges because its checks do not require them. ]]>
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
- `SKILL.md` exists.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/release-check.sh (reported line 53)May include surrounding context.

sh
else
  pass "No dynamic shell evaluation found outside release-check.sh."
fi
rm -f /tmp/release-guard-shell-eval.$$

if grep -RInE '(api[_-]?key|secret|token|password)[[:space:]]*[:=]' "$skill_dir" \
  --exclude-dir=.git --exclude-dir=node_modules >/tmp/release-guard-secret.$$ 2>/dev/null; then

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/release-check.sh (reported line 62)May include surrounding context.

sh
else
  pass "No simple secret-like assignments found."
fi
rm -f /tmp/release-guard-secret.$$

if [ "$status" -eq 0 ]; then
  say "FINAL: PASS with any WARN items requiring manual review."

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The checklist states that 'Documentation is mostly English,' which is a natural-language policy constraint. The file does not present this as optional, nor does it justify the locale restriction as region-specific or compliance-driven.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The checklist explicitly requires that SKILL.md be 'English-first,' which imposes a language policy in natural language. This is a locale/language constraint without any indication of user choice, opt-in, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.