Back to skill

Security audit

Self Improving Life

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly purpose-aligned, but its included script automatically saves sensitive life-assessment details to a local file without clear consent or private-file safeguards.

Review before installing if you might run the quick assessment script. The guidance itself is ordinary self-reflection content, but the script saves personal answers locally by default; run it only in a private directory, check/delete generated reports as needed, and avoid entering details you do not want retained.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/quick-life-assessment.sh:107
Finding

Insecure Storage and Predictable File Creation for Sensitive Assessment Data

Content
View full analysis
"life-assessment-$timestamp.md" << EOF # 生活评估报告 **评估时间**: $(date) ## 领域评分 - 健康: $health_avg/10 - 整体满意度: $health_score/10 - 睡眠质量: $sleep_score/10 - 运动频率: $exercise_freq 次/周 - 关系: $relationship_avg/10 - 亲密关系: $relationship_score/10 - 社交频率: $social_freq/10 - 家庭联系: $family_score/10 - 工作: $work_avg/10 - 投入度: $work_engagement/10 - 成长感: $career_growth/10 - 平衡度: $work_balance/10 ## 改进重点 最需要关注的领域: $lowest_domain ($lowest_score/10) ## 建议行动 $(case $lowest_domain in "健康") echo "1. 确保7-8小时睡眠\n2. 每周运动3-5次\n3. 均衡饮食,充足饮水" ;; "关系") echo "1. 安排定期社交活动\n2. 主动联系朋友家人\n3. 参加兴趣小组或社区" ;; "工作") echo "1. 设定明确工作边界\n2. 规划职业发展路径\n3. 平衡工作与个人时间" ;; esac) ## 后续步骤 1. 使用完整的生活轮模板进行详细评估 2. 设定具体改进目标 3. 每月重新评估进展 4. 调整策略以获得更好平衡 EOF ``` ### Technical Analysis The script unconditionally writes health, relationship, and work assessment data to the current working directory. It neither obtains explicit consent immediately before storage nor ensures that the selected directory is private. The output file inherits permissions from the caller's process-wide `umask`; on systems using a permissive default, other local users may be able to read the report. The filename is derived solely from a timestamp with one-second precision: ```bash life-assessment-YYYYMMDD_HHMMSS.md ``` The file is then opened using ordinary truncating shell redirection. This operation follows symbolic links and overwrites an existing target. If the script is run in a directory writable by another user, an attacker can predict candidate filenames and pre-create symbolic links pointing to files the victim is permitted to overwrite. The documentation recognizes that the assessment can contain sensitive healt ...[truncated 1464 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill declares broad life-optimization coverage and also instructs the system to append sensitive reflections to local markdown files, while the top-level description does not clearly disclose persistent storage as a core behavior. This can mislead users into sharing health, relationship, and financial information without informed consent about retention, and the mismatch reduces trust in what the skill actually does.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file is a markdown skill description, so natural-language policy checks apply. Lines L025-L027 introduce a full scenario and output in Chinese, but the skill does not say it is China-specific or that language will be chosen based on user preference, which can amount to forcing a locale/language without opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script collects sensitive self-assessment data about health, relationships, and work, then automatically writes it to a timestamped markdown file without clearly warning the user beforehand. In a local multi-user environment, shared workspace, synced folder, or backed-up directory, this can expose personal information beyond the user's immediate session and violates data minimization expectations for a 'quick assessment' helper.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script writes a personal life-assessment report to disk without prior warning or confirmation, which is risky because the data includes intimate lifestyle and relationship details. This is especially problematic in the skill context because users are likely to disclose honest, sensitive information during self-improvement exercises and may not expect durable local storage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script's user-facing text is primarily in Chinese but includes English terms such as "wellness," and it does not provide any language or locale selection. This can violate language/locale policy when a skill implicitly forces one presentation style without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The script asks for three health inputs, including exercise frequency, and presents them as part of the health assessment, but the computed health_avg only uses overall satisfaction and sleep quality. Because the later 'identify lowest domain' logic relies on that average, the documented intent of assessing the domain contradicts the actual scoring logic for health.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.