Back to skill

Security audit

CardDAV Contacts

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward CardDAV contact-sync guide, with normal but important risks around contact deletion, sync conflicts, and password-file handling.

Before installing or following this skill, confirm you are comfortable syncing contacts through vdirsyncer and khard. Protect any app-password file with strict permissions or use a keyring, review conflict_resolution before first sync, and verify contact matches before running delete or move commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:73
Finding

Plaintext App Password Retrieval Without Required File-Permission Controls

Content
View full analysis
Remediation
View remediation
~/.config/vdirsyncer/google_app_password chmod 0600 ~/.config/vdirsyncer/google_app_password ``` 2. Prefer a vdirsyncer-supported integration with an operating-system keyring or secret manager so the password is not maintained as an ordinary plaintext file. 3. If command-based retrieval remains necessary, use a trusted absolute executable path rather than relying on `PATH` resolution: ```ini password.fetch = ["command", "/bin/cat", "~/.config/vdirsyncer/google_app_password"] ``` 4. Ensure the credential file is excluded from source control, logs, shared archives, and unencrypted backups. 5. Use an app-specific credential with the minimum server-side scope available. Do not reuse the user's primary account password. 6. Document immediate credential revocation and rotation if the file is exposed, copied, or created with unsafe permissions. ]]>
Vulnerability Patterns
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

Management

bash
khard new                        # Create new contact (interactive editor)
khard edit "john"                # Edit contact (interactive editor)
khard remove "john"              # Delete contact
khard move "john" -a work        # Move to another address book

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown instructs users to run khard remove "john" but provides no warning that this deletes contact data, nor any note about confirming the target or syncing implications. Because this operation can remove user data, the skill description should disclose the risk clearly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The example sets conflict_resolution = "a wins", which can silently overwrite local changes during sync if the remote side differs. In a contact-sync skill, this is operationally dangerous because users may lose contact edits or deletions without understanding that conflicts are being resolved one-way.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.