Back to skill

Security audit

Nooks: Places worth revisiting

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent personal place-notes helper, but it deserves Review because it recommends mutable self-updates, recurring checks, plaintext API-key storage, and external lookups involving personal location interests.

Review before installing. Use it only if you are comfortable storing personal place history in workspace files and sending place queries to web services when enrichment is used. Do not enable the cron/heartbeat reminder unless you want recurring access to those notes. If using Google Places, restrict the API key, keep nooksconfig.yml out of git, and prefer pinned or reviewed updates instead of replacing the skill from a mutable main-branch URL.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Warning
Location
README.md:33
Finding

Unpinned Remote Skill Installation and Update Channels

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:87
Finding

Plaintext API Key Storage with an Unsupported Git-Exclusion Assurance

Content
View full analysis
`nooksconfig.yml` is excluded from git by default — your key stays local. ``` `SKILL.md:71-75`: ```markdown - Otherwise if `google_places_api_key` is set in `mind/nooks/nooksconfig.yml`, call Places API Text Search yourself (IDs only, free): ``` POST https://places.googleapis.com/v1/places:searchText Headers: X-Goog-Api-Key: , X-Goog-FieldMask: places.id Body: { "textQuery": ", " } ``` ``` `SKILL.md:160-169`: ```markdown 5. Add a billing account (card required by Google, but ID-only searches are free) 6. Save the key to `mind/nooks/nooksconfig.yml` (at the root of your nooks folder): ```yaml google_places_api_key: YOUR_KEY_HERE ``` Once configured, Maps links are fetched automatically when saving a place — no manual copy-paste needed. ``` ### Technical Analysis The Skill instructs users to store a live Google Places API key in plaintext inside a workspace configuration file. Plaintext credentials may be exposed through source-control commits, workspace synchronization, backups, support archives, broad filesystem permissions, or other tools with workspace access. The README claims that `nooksconfig.yml` is excluded from Git by default. However, the audited project contains only `README.md` and `SKILL.md`; it does not contain a `.gitignore` implementing that exclusion. The assurance may therefore lead users to believe the credential is protected when no repository-level exclusion is actually supplied. Sending the ke ...[truncated 1450 chars]
Remediation
View remediation

T06 · System Persistence

Note
Location
SKILL.md:137
Finding

Unnecessary Recurring Execution Through Heartbeat or Cron

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Self-Modification

High
Category
Rogue Agent
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to fetch a remote SKILL.md from GitHub and replace the current file, which is a self-modification pathway. This is dangerous because it allows remote content to alter future agent behavior, potentially introducing malicious instructions or silently broadening permissions if the upstream source is compromised or changed.

Content

Scanner excerpt · SKILL.md (reported line 176)May include surrounding context.

Updating

To update this skill to the latest version, fetch the new SKILL.md from GitHub and replace this file:

text
https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 35)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

bash
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 36)May include surrounding context.

bash
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

bash
mkdir -p ~/.claude/skills/nooks
curl -o ~/.claude/skills/nooks/SKILL.md https://raw.githubusercontent.com/haah-ing/nooks-skill/main/SKILL.md

Other agents

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The invocation cues are broad enough to match ordinary conversation about places, eating, meeting, or working in a city. That increases the chance the agent activates this skill unexpectedly and performs note-taking or lookups without the user clearly intending to use the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create directories and files on first use with no requirement to notify the user before modifying the workspace. Silent file creation and updates can violate user expectations, create persistence unexpectedly, and make it harder to audit what data the agent stored.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill expands from local note management into external web search, Google Places API calls, and image fetching without requiring an explicit user opt-in at the moment of use. This can cause unintended disclosure of user interests, locations, or place names to third-party services and increases the skill's attack surface beyond its stated local-storage purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill directs external searches, API calls, and image lookups but does not require a user-facing privacy warning when those actions occur. Because place names, neighborhoods, and preferences can reveal sensitive personal context, sending them to third parties without notice creates a privacy risk.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The core behavior encourages activation on passing mentions of places and observations, which can cause the agent to infer consent to create or update records from casual conversation. In a personal-memory skill, this is risky because it may capture sensitive habits, meetings, or location preferences without clear user approval.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The heartbeat/cron guidance introduces recurring autonomous behavior unrelated to the core task of saving and retrieving place notes. Periodic unsolicited checks can lead to surprise background activity, repeated file scanning, and increased opportunities for privacy-invasive prompts or workflow disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README says the skill "searches the web first" to pre-fill place information, which implies sending the user's requested place/query to external services. It describes the feature as convenience functionality but does not clearly warn that user-provided place information may be transmitted to third-party services during save operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explains that the agent will "automatically fetch" Maps links using the Google Places API, but the warning focuses on API-key storage rather than disclosure that user-entered place queries are shared with Google. For a skill storing personal place history, this external transmission has privacy implications that should be explicitly disclosed.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The saving instructions explicitly say not to ask the human to install a key or paste a share link when a maps link is unavailable. Later, the document includes a full setup flow for configuring a Google Places API key, which contradicts that earlier directive at the documentation level.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.