Back to skill

Security audit

Skills Orchestrator

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed local template/report generator, but it needs review because one script can overwrite arbitrary writable files and the generated advice promotes public-by-default publishing.

Install only if you are comfortable with local shell scripts that generate template reports. Avoid passing arbitrary --output paths, treat all metrics as mock data, and revise any public-by-default publishing recommendations to require explicit user opt-in and privacy review.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/design-loop.sh:45
Finding

Unrestricted Output Path Allows Arbitrary File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/design-loop.sh, lines 45-46, 62, and 70
Vulnerability Type: Unvalidated file path and destructive file overwrite
Risk Level: Medium

Vulnerable Code

bash
--output)
    OUTPUT_FILE="$2"
    shift 2
    ;;
bash
DESIGN_FILE="${OUTPUT_FILE:-$DATA_DIR/LOOP-DESIGN-${SKILL_NAME}-$(date +%Y%m%d).md}"
bash
cat > "$DESIGN_FILE" << EOF

Technical Analysis

The script accepts the --output argument and uses its value directly as the destination of a truncating shell redirection. It does not:

  • Restrict output to the intended data directory.
  • Reject absolute paths or .. path traversal.
  • Detect symbolic links.
  • Check whether the destination already exists.
  • Require explicit authorization before overwriting an existing file.

Quoting "$DESIGN_FILE" prevents shell word splitting and ordinary command injection, but it does not make the destination path safe. The > operator opens the selected file with truncation, replacing its contents before writing the generated Markdown.

Consequently, a caller can select any file writable by the account executing the Skill. This behavior exceeds the expected function of creating a growth-loop report in the project data directory.

Attack Path

  1. An attacker controls or influences the --output argument provided to the Skill.

  2. The Agent invokes the script with a sensitive writable destination, for example:

    bash
    ./scripts/design-loop.sh \
      --type viral \
      --skill demo \
      --output ../../some-writable-configuration-file
    
  3. The script assigns the supplied path to OUTPUT_FILE without validation.

  4. DESIGN_FILE resolves directly to the attacker-selected path.

  5. cat > "$DESIGN_FILE" truncates the existing destination.

  6. The generated Markdown replaces the destination's previous contents.

A symbolic-link destination could similarly redirect the write to another file accessible to the executing accoun ...[truncated 718 chars]

Remediation
View remediation

Remediation Suggestions

  1. Confine generated files to a dedicated directory

    • Resolve the canonical output directory.
    • Treat user input as a filename rather than an unrestricted path.
    • Verify that the resolved destination remains beneath the approved directory.
  2. Reject dangerous path forms

    • Reject absolute paths.
    • Reject path components equal to ...
    • Apply a conservative filename allowlist, such as letters, digits, periods, underscores, and hyphens.
    • Require the expected .md extension.
  3. Prevent symbolic-link attacks

    • Reject an existing destination if it is a symbolic link.
    • Ensure parent path components are trusted and not attacker-controlled.
    • Prefer secure file-opening mechanisms that support no-follow semantics where available.
  4. Avoid implicit overwrite

    • Refuse to replace an existing file by default.
    • Add a separate --force option if overwrite behavior is genuinely required.
    • Consider enabling shell no-clobber behavior with set -o noclobber and handling failures explicitly.
  5. Harden argument handling

    • Confirm that options requiring values have a following argument before reading $2.
    • Use set -euo pipefail to catch unset arguments and pipeline failures.

A safer design would derive the output path from a validated basename:

bash
case "$OUTPUT_FILE" in
    "" )
        OUTPUT_NAME="LOOP-DESIGN-${SKILL_NAME}-$(date +%Y%m%d).md"
        ;;
    /*|*".."*|*/* )
        echo "Error: --output must be a filename within the data directory" >&2
        exit 1
        ;;
    * )
        OUTPUT_NAME="$OUTPUT_FILE"
        ;;
esac

if [[ ! "$OUTPUT_NAME" =~ ^[A-Za-z0-9._-]+\.md$ ]]; then
    echo "Error: Invalid output filename" >&2
    exit 1
fi

DESIGN_FILE="$DATA_DIR/$OUTPUT_NAME"

if [[ -e "$DESIGN_FILE" || -L "$DESIGN_FILE" ]]; then
    echo "Error: Output already exists" >&2
    exit 1
fi
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description promises portfolio growth-loop orchestration, but the documented behavior is mainly local script execution, simulated metrics generation, and file-writing/reporting. This mismatch is dangerous because users or autonomous agents may trust the skill with strategic or operational tasks it does not actually perform, while still allowing shell/file actions that can modify local state under misleading pretenses.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises shell-based commands in its interface but does not declare any explicit tool scope such as permissions or allowed-tools. That creates an authorization ambiguity where an agent or reviewer may not realize shell execution is expected, increasing the risk of unintended command execution or over-broad tool access if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger examples include broad natural-language phrases such as asking how to increase engagement or what's blocking growth. Overly generic triggers can cause unintended invocation in unrelated contexts, which matters more here because the skill exposes shell-oriented commands and could steer workflows toward script execution or misleading simulated analytics.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document defines the trigger as "Need or habit" and context as "Daily workflow," which are extremely broad conditions that overlap with ordinary user behavior. It does not specify concrete invocation phrases, boundaries, or negative examples to clarify when the skill should or should not activate.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script presents itself as an analysis tool but generates a fully static markdown report with hard-coded metrics, issues, and recommendations regardless of inputs. This is dangerous because users may make product, growth, or operational decisions based on fabricated results, and the deception is amplified by realistic formatting and dynamic timestamps/file names that make the output appear genuine.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The behavior does not match the skill's stated orchestration purpose; instead of connecting usage, feedback, improvement, and adoption signals, it emits a canned report with no orchestration or analysis. In this context, the mismatch is risky because it can create false confidence that a portfolio-level growth system is functioning, when in reality no meaningful evaluation or coordination is happening.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The validator explicitly permits feedback as a valid loop type, but the subsequent case statement has no feedback) branch. As a result, the script presents feedback as supported while failing to generate any corresponding design, creating a direct contradiction between the script's behavior contract and implementation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The generated content explicitly recommends making outputs public by default with opt-out behavior. In the context of a growth-orchestration skill, that guidance encourages product designs that can disclose user-generated or user-supplied content without explicit consent, increasing privacy, confidentiality, and compliance risk.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This plain-language instruction promotes exposing user outputs publicly unless the user opts out, which is dangerous because outputs may contain prompts, personal data, proprietary content, or sensitive business information. The skill context makes this more dangerous because it frames the behavior as a growth best practice, increasing the chance it will be adopted broadly without adequate privacy review.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation checklist directs builders to make outputs public by default, operationalizing broad disclosure rather than merely describing it. Because this skill is intended to influence product strategy across a portfolio, the unsafe default could propagate into multiple downstream systems and normalize insecure publication practices.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The implementation steps combine public-by-default exposure with search-engine submission and SEO optimization, creating a direct path to large-scale dissemination of potentially sensitive user content. Once indexed, accidental disclosure becomes harder to remediate because cached and mirrored copies may persist even after takedown.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script presents itself as tracking growth metrics, but it fabricates values using random number generation and writes them to a metrics file as if they were real telemetry. This is dangerous because downstream users, dashboards, or automation may treat the output as authentic operational data, leading to false reporting, bad business decisions, or concealment of real performance issues.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The header usage comment says the script accepts only viral|content|network|engagement, but the validation logic also accepts feedback. This is an active contradiction between the file's inline documentation and actual behavior, which can mislead users about supported functionality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This shell script performs file creation/overwrite via shell redirection into "$DESIGN_FILE", which is a safety-relevant file write operation. While it prints the destination after completion, it does not warn beforehand that running the script will create or overwrite a markdown file, and there is no confirmation prompt or explanatory comment about overwrite behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.