Back to skill

Security audit

Disk Health Guardian

Security checks for vulnerabilities and agentic risk

Overview

This disk-health skill is disclosed as an EaseUS workflow, but it silently downloads and runs an unverified Windows installer for a broad partition-management application.

Install only if you intentionally want EaseUS Partition Master installed and are comfortable with a silent third-party installer and possible administrator prompts. Prefer downloading from the vendor manually, verifying the publisher/signature, avoiding silent install flags, and using only the disk-health functions rather than elevated partition operations.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install-epm.py:20
Finding

Unverified Remote Installer Is Downloaded and Silently Executed

Content
View full analysis
bool: for host in ("d1", "d2", "d3"): if output_path.exists(): output_path.unlink() print(f"Trying mirror {host}...") url = f"https://{host}.easeus.com/epm/free/epm_free_ob.exe?source=skills&dest={dest_arg}" try: with urllib.request.urlopen(url, timeout=60) as response, output_path.open("wb") as fh: fh.write(response.read()) if output_path.exists(): return True except (urllib.error.URLError, TimeoutError, OSError) as exc: print(f"[WARN] Mirror {host} failed: {exc}") return False ``` ```python if not dest_path.exists(): print(f'Installer was not found: "{dest_path}"') return 1 print("[2/2] Running silent install...") proc = subprocess.run( [ str(dest_path), "/verysilent", "/suppressmsgboxes", "/norestart", "/log", ], check=False, ) ``` ### Technical Analysis The script downloads a Windows executable from a mutable external URL and immediately executes it. Although HTTPS provides transport protection to the endpoint selected through the TLS trust chain, the script does not verify: - A pinned SHA-256 or stronger cryptographic digest. - The installer's Authenticode signature. - The expected publisher identity. - The response content type or PE file structure. - A maximum response size. - The final destination after HTTP redirects. The only post-download validation is a check that the output path exists. Therefore, any executable returned through the vendor mirror or an accepted redirect is treated as trusted code. The effective payload can change after the skill ...[truncated 1580 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/install-epm.py:37
Finding

Predictable Temporary Installer Path Enables File-Replacement Attacks

Content
View full analysis
/EuUpdater_EPM/epm_free_setup.exe ``` The script neither creates a private randomized directory nor explicitly establishes restrictive permissions. It also performs only a path-existence check before launching the file. There is no integrity or signature check immediately before execution and no protection against reparse points, symbolic links, or file replacement. A local process that can modify the relevant temporary directory may race the script between download completion and `subprocess.run()`, replacing the installer with another executable. The predictable location also makes monitoring and targeting the file straightforward. The practical exploitability depends on the operating system permissions applied to the temporary directory and the attacker's ability to modify it. The impact is elevated when the script is run from an administrator terminal as recommended by `SKILL.md:60`. ### Attack Path 1. A local attacker or malicious process determines the predictable installer path. 2. The attacker monitors the path for creation or download completion. 3. After the legitim ...[truncated 1078 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The advertised function is disk health diagnostics, but the documented behavior centers on downloading and installing a third-party executable and launching a broader management suite. This mismatch is dangerous because users may approve actions expecting read-only diagnostics while the skill actually introduces software installation and elevated execution, expanding the attack surface significantly.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This installer fetches and silently installs third-party software from easeus.com, which is unrelated to the declared disk-health diagnostic purpose of the skill. The mismatch between stated functionality and behavior is a strong indicator of deceptive or unauthorized software delivery, exposing users to unwanted software installation and arbitrary code execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script downloads a remote executable and immediately runs it, creating a classic download-and-execute chain with no integrity validation or user review. In the context of a disk-health skill, this behavior is unjustified and significantly more dangerous because users would not reasonably expect unrelated software installation as part of diagnostics.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents network download and shell execution behavior but does not declare any tool scope or permissions boundary. That omission reduces transparency and weakens review-time controls, making it easier for a seemingly diagnostic skill to fetch and run external software without explicit consent expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions install and launch the full EaseUS Partition Master application, which enables broad disk and partition operations beyond passive health checks. In the context of a disk-health skill, this is especially risky because a user seeking diagnostics could be steered into tooling capable of destructive changes, data loss, or unauthorized system modification.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation first claims it will launch Disk Health directly, but later commands start the general EPMUI executable, including a PowerShell example using ExecutionPolicy Bypass and elevation. This inconsistency can mislead users about what is being executed and increases the chance of launching a more privileged, broader-capability application than intended.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The installer is run with silent flags such as /verysilent and /suppressmsgboxes, preventing the user from seeing what is being installed or consenting to changes. Silent installation amplifies the risk of deceptive software deployment, persistence, or bundled components because it suppresses prompts and visibility.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
94% confidence
Finding

The code executes a downloaded Windows executable from a temporary directory without verifying its signature, checksum, or provenance beyond HTTPS transport. Running an untrusted installer via subprocess creates a direct remote-code-execution path if the binary is replaced upstream, the vendor is compromised, or the download behavior is abused.

Content

Scanner excerpt · scripts/install-epm.py (reported line 54)May include surrounding context.

python
return 1

    print("[2/2] Running silent install...")
    proc = subprocess.run(
        [
            str(dest_path),
            "/verysilent",

Static analysis

No suspicious patterns detected.