T09 · Insecure Skill Coding Practices
- Location
templates.md:17- Finding
Shell Command Injection Through an Unquoted HTTP Monitor Target
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This monitoring skill is mostly coherent, but it asks agents to run recurring user-defined commands and uses unsafe command templates without enough guardrails.
Review this skill before installing. It is not clearly malicious, but only use it where monitor definitions are trusted, avoid or tightly approve custom command checks, validate URLs and webhook destinations, and assume alert payloads may expose service names, outages, timestamps, and failure details to configured third-party services.
templates.md:17Shell Command Injection Through an Unquoted HTTP Monitor Target
alerts.md:71Curl Option Injection Through a User-Provided Webhook URL
The template explicitly supports a custom check where the user supplies an arbitrary command and the agent runs it. That expands the skill from monitoring into general command execution, creating a high-risk path for destructive local actions, privilege misuse, or lateral movement if the agent has host or SSH access.
The referenced Pushover API endpoint confirms that this skill relies on an external network destination for alert delivery. In context, this is less indicative of malicious behavior than hidden exfiltration, but it still creates a data exposure surface because internal incident information leaves the local environment.
curl -s -X POST https://api.pushover.net/1/messages.json \
-d "token=$PUSHOVER_TOKEN" \
-d "user=$PUSHOVER_USER" \
-d "message=$MESSAGE"
The referenced Pushover API endpoint confirms that this skill relies on an external network destination for alert delivery. In context, this is less indicative of malicious behavior than hidden exfiltration, but it still creates a data exposure surface because internal incident information leaves the local environment.
curl -s -X POST https://api.pushover.net/1/messages.json \
-d "token=$PUSHOVER_TOKEN" \
-d "user=$PUSHOVER_USER" \
-d "message=$MESSAGE"
The webhook channel sends alert contents to a user-supplied external URL, but the skill text does not warn users that monitor names, status history, timestamps, outage details, and possibly error messages will be disclosed to a third party. In a monitoring skill, this is a real privacy and data-governance issue because users may configure alerts for internal services and unintentionally exfiltrate operational metadata outside their environment.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "api-health",
"description": "Check API returns 200",
"checks": [
{"type": "http", "target": "https://api.example.com/health", "expect": 200}
],
"interval": "5m",
"requires": []
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
"name": "api-health",
"description": "Check API returns 200",
"checks": [
{"type": "http", "target": "https://api.example.com/health", "expect": 200}
],
"interval": "5m",
"requires": []
The documentation normalizes running user-provided commands without any visible warning about code execution risk, shell injection, data destruction, or privilege boundaries. In a skill whose purpose is monitoring, presenting arbitrary command execution as a routine template makes unsafe use more likely and reduces informed consent for users and operators.
No suspicious patterns detected.