Back to skill

Security audit

Tvs Cc Migrator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Claude Code migration skill, but it gives restore manifests and backup paths enough authority to overwrite local configuration or run commands if a backup is tampered with.

Install only if you are comfortable giving the skill access to your Claude Code configuration and reviewing every backup item. Use the sensitive-field redaction option, keep backups private, restore only from backups you created or trust, and do not approve reinstall commands or overwrite restores unless the exact paths and commands make sense.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/backup.mjs:604
Finding

Command Injection Through the User-Controlled Backup Output Path

Content
View full analysis
a.startsWith('--exclude=')) const excludeIds = excludeArg ? excludeArg.replace('--exclude=', '').split(',') : [] const outputDir = args.find(a => !a.startsWith('--')) || join(homedir(), 'Desktop', `cc-backup-${DATE}`) backup(outputDir, excludeIds) } ``` The user-controlled value subsequently reaches shell commands during archive creation: ```js if (platform() === 'win32') { const zipName = `${dirName}.zip` execSync( `powershell -Command "Compress-Archive -Path '${outputDir}' -DestinationPath '${join(parentDir, zipName)}'"`, { stdio: 'pipe' } ) info(`Backup archive: ${join(parentDir, zipName)}`) } else { const archiveName = `${dirName}.tar.gz` execSync(`tar -czf "${join(parentDir, archiveName)}" -C "${parentDir}" "${dirName}"`, { stdio: 'pipe' }) info(`Backup archive: ${join(parentDir, archiveName)}`) } ``` ### Technical Analysis The first positional command-line argument is accepted as `outputDir` without restrictions. Components derived from this value are interpolated into command strings passed to `execSync`. Unlike direct process execution with an argument array, `execSync` parses the assembled string through a command shell. Quotation marks alone are not a sufficient defense: a malicious path containing shell-specific quotation characters, substitutions, separators, or other metacharacters can terminate the intended argument and introduce an additional command. Both supported archive branches are affected: - On Unix-like systems, `outputDir`, `parentDir`, and `dirName` influence the `tar` command string. - On Windows, `outputDir` and the archive destination are embedded inside a PowerShell co ...[truncated 1521 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
RESTORE_GUIDE.md:19
Finding

Untrusted Restore Manifest Can Direct Arbitrary File Operations and Command Execution

Content
View full analysis
placeholder. Resolve it according to the current platform. ``` ### Technical Analysis The restore guide treats `manifest.json` as authoritative but does not require the restoring agent to establish the integrity or provenance of the backup package. For `direct_copy` entries, the manifest controls both `source` and `target`. The instructions do not require the agent to: - Reject absolute source or target paths. - Reject parent-directory traversal components. - Canonicalize paths before accessing them. - Verify that a source remains inside the extracted backup directory. - Verify that a target remains inside the intended Claude configuration directory. - Reject symbolic-link traversal. - Validate the manifest against a strict schema. Consequently, a malicious manifest could direct the restoring agent to read files outside the backup or overwrite files outside `~/.claude`. For `reinstall` entries, the guide explicitly tells the agent to execute strings from `r ...[truncated 2435 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The restore flow supports direct overwrite of configuration files and directories under ~/.claude but does not present a strong up-front safety warning about destructive changes to existing local data. In a migration context this can cause loss of local configuration, silent replacement of trusted settings, or restoration of unsafe files from an untrusted backup with insufficient user awareness.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide explicitly instructs the agent to read reinstall_commands, ask the user, and then execute them on the user's machine. Because those commands are sourced from the backup package's manifest.json, a tampered or malicious backup can smuggle arbitrary command execution into a trusted migration workflow, and the user prompt alone is a weak safeguard if commands are not independently validated and fully disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide tells Claude to execute installation commands after confirmation, but it does not clearly warn at the outset that shell/package-manager commands may run on the host system. In a restore skill, that omission increases the chance that users treat the process as mere file copying while actually authorizing code execution from backup-supplied metadata.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill description uses broad trigger phrases like '备份配置、迁移 Claude Code、导出设置、恢复配置、换电脑等场景时使用此 skill', which can overlap with normal conversation and cause the skill to activate in contexts where the user did not explicitly request backup or restore actions. Because this skill operates on sensitive local configuration under ~/.claude and may expose or package secrets, accidental invocation increases the chance of unintended scanning, disclosure prompts, or risky file operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The scan logic dynamically enumerates and later legitimizes unknown top-level files and directories under ~/.claude beyond the explicitly documented categories. In a migration tool, this broadens collection scope and can silently include unintended local data, making over-collection and later exfiltration or accidental disclosure more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script copies settings.json to disk by default even when it detects sensitive env fields such as tokens, secrets, keys, or passwords. Although it supports excluding sensitive fields, it does not require explicit consent or provide a prominent warning before persisting secrets into the backup, which can lead to credential exposure if the archive is shared or stored insecurely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Backup mode copies arbitrary non-hidden root entries from ~/.claude rather than only documented configuration classes. This can capture unrelated or sensitive files placed in that directory and persist them into the backup archive without strong user awareness, increasing the blast radius of any later leak or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest records source hostname and username without an explicit disclosure or necessity check. While lower severity than credential backup, this still leaks identifying environment metadata that can aid profiling, social engineering, or unnecessary exposure when backups are shared across systems or teams.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The stated purpose is backing up and restoring Claude Code configuration, which primarily requires local file reads/writes. This script additionally executes external system commands (tar or PowerShell Compress-Archive) to package the backup, introducing subprocess execution capability that is not mentioned in the skill description.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/backup.mjs:602