Back to skill

Security audit

Reboot Checker

Security checks for vulnerabilities and agentic risk

Overview

This skill is a simple reboot monitor that writes local state files, with a real but purpose-aligned file-safety caveat around custom state paths.

Install only if you are comfortable with a local script writing reboot state and history files in the user's home directory. Run it as an unprivileged user, avoid running it as root from cron, and do not pass custom --state, STATE_FILE, or HISTORY_FILE values from untrusted sources or shared writable directories.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/check-reboot.sh:4
Finding

Unrestricted State Paths and Symbolic-Link Following Permit File Deletion or Clobbering

Content
View full analysis
"$STATE_FILE" echo "$CURRENT_BOOT | first_recorded" >> "$HISTORY_FILE" ``` ```bash echo "$CURRENT_BOOT_TS" > "$STATE_FILE" echo "$CURRENT_BOOT | reboot_detected" >> "$HISTORY_FILE" ``` ### Technical Analysis The script accepts an unrestricted state-file path through the `STATE_FILE` environment variable or the `--state` option. It subsequently passes that path to `rm -f` during reset and uses shell redirection to overwrite it during initialization or reboot detection. The history-file path is similarly controllable through `HISTORY_FILE` and is opened in append mode. Neither path is validated for ownership, file type, symbolic-link status, or containment within a trusted directory. Shell redirection and `rm` follow or operate on the supplied filesystem path without these safeguards. Consequently: - `--reset` can delete any file that the executing account is permitted to remove. - State updates can truncate and replace the contents of an existing target. - State or history files pre-created as symbolic links can redirect writes to another file. - If the script runs from cron or another privileged context while an attacker can influence its environment, arguments, home directory, or configured state directory, the operation occurs with that context's filesystem privileges. The script also does not set a restrictive `umask`, use atomic file replacement, or protect state updates against concurrent invocations. ### Attack Path A symbolic-l ...[truncated 2286 chars]
Remediation
View remediation
Vulnerability Patterns
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

View boot history

bash {baseDir}/scripts/check-reboot.sh --history

Reset state (mark current boot as known)

bash {baseDir}/scripts/check-reboot.sh --reset

text

Memory Manipulation

High
Category
Memory Poisoning
Confidence
80% confidence
Finding

Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

View boot history

bash {baseDir}/scripts/check-reboot.sh --history

Reset state (mark current boot as known)

bash {baseDir}/scripts/check-reboot.sh --reset

text

Static analysis

No suspicious patterns detected.