Back to skill

Security audit

Random Thought

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent purpose, but it repeatedly reads workspace files on a schedule and has real scoping and script-safety problems users should review before installing.

Install only in a workspace where you are comfortable with an agent repeatedly reading random files and storing derived reflections. Avoid cron until you have verified the effective scan scope, keep secrets and private notes outside the workspace, do not rely on the documented excludePatterns until fixed, and treat external posting/output destinations as potentially exposing file-derived content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/corpus-pick.sh:21
Finding

Arbitrary Python Code Execution Through Unsafe String Interpolation

Content
View full analysis
/dev/null || echo "$default" else echo "$default" fi } ``` ```bash FILTERED=$(python3 -c " import sys cutoff = int('$CUTOFF') history_path = '$HISTORY_PATH' # Load recently visited files recent = set() with open(history_path) as f: for line in f: parts = line.strip().split('\t', 1) if len(parts) == 2: try: ts = int(parts[0]) if ts >= cutoff: recent.add(parts[1]) except ValueError: continue # Filter candidates for line in sys.stdin: path = line.strip() if path and path not in recent: print(path) " <<< "$CANDIDATES" 2>/dev/null) || true ``` The same construction is used in `freshness-gate.sh`: ```bash DAYS=$(python3 -c "import json; c=json.load(open('$CONFIG')); print(c.get('freshness',{}).get('days',7))" 2>/dev/null || echo "7") HISTORY_FILE=$(python3 -c "import json; c=json.load(open('$CONFIG')); print(c.get('freshness',{}).get('historyFile','.random-thought-history'))" 2>/dev/null || echo ".random-thought-history") ``` ```bash FOUND=$(python3 -c " cutoff = int('$CUTOFF') target = '$ABS_FILE' with open('$HISTORY_FILE') as f: for line in f: parts = line.strip().split('\t', 1) if len(parts) == 2: ts, path = int(parts[0]), parts[1] if ts >= cutoff and path == target: p ...[truncated 2185 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/corpus-pick.sh:33
Finding

Documented Corpus Exclusions and Scan Boundaries Are Silently Ignored

Content
View full analysis
/dev/null) || true ``` ### Technical Analysis The implementation does not consume `corpus.watch ...[truncated 1820 chars]
Remediation
View remediation

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:89
Finding

Workspace Files Are Loaded as Agent Context Without Prompt-Injection Isolation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
" >&2 exit 2 fi ABS_FILE=$(cd "$(dirname "$FILE")" 2>/dev/null && echo "$(pwd)/$(basename "$FILE")" || echo "$FILE") echo "$(date +%s) $ABS_FILE" >> "$HISTORY_FILE" echo "Recorded: $ABS_FILE" ;; ``` The `prune` action rewrites it: ```bash prune) if [ ! -f "$HISTORY_FILE" ]; then echo "No history file to prune." exit 0 fi BEFORE=$(wc -l < "$HISTORY_FILE" | tr -d ' ') python3 -c " cutoff = int('$CUTOFF') lines = [] with open('$HISTORY_FILE') as f: for line in f: par ...[truncated 2236 chars]:37
Finding

Unrestricted History Paths Permit Writes Outside the Intended Workspace

Content
View full analysis
> "$HISTORY_PATH" fi ``` In `freshness-gate.sh`, the configured path is used directly: ```bash HISTORY_FILE=$(python3 -c "import json; c=json.load(open('$CONFIG')); print(c.get('freshness',{}).get('historyFile','.random-thought-history'))" 2>/dev/null || echo ".random-thought-history") ``` The `record` action appends to the target: ```bash record) if [ -z "$FILE" ]; then echo "Usage: freshness-gate.sh record " >&2 exit 2 fi ABS_FILE=$(cd "$(dirname "$FILE")" 2>/dev/null && echo "$(pwd)/$(basename "$FILE")" || echo "$FILE") echo "$(date +%s) $ABS_FILE" >> "$HISTORY_FILE" echo "Recorded: $ABS_FILE" ;; ``` The `prune` action rewrites it: ```bash prune) if [ ! -f "$HISTORY_FILE" ]; then echo "No history file to prune." exit 0 fi BEFORE=$(wc -l < "$HISTORY_FILE" | tr -d ' ') python3 -c " cutoff = int('$CUTOFF') lines = [] with open('$HISTORY_FILE') as f: for line in f: parts = line.strip().split('\t', 1) if len(parts) == 2 and int(parts[0]) >= cutoff: lines.append(line) with open('$HISTORY_FILE', 'w') as f: f.writelines(lines) print(f'Kept {len(lines)} entries') " 2>/dev/null ``` ### Technical Analysis The `freshness.historyFile` value is neither canonicalized nor restricted to the workspace. In `corpus-pick.sh`, traversal sequences such as `../../target` can escape the ...[truncated 1682 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a multi-stage introspection system that generates reflective writing and periodic curated digests. The supplied code only implements a narrow helper: random corpus file selection with exclusion rules and a freshness gate backed by a history file. While this aligns with one supporting sub-step ('picks a random file from a configurable corpus'), it does not implement the core advertised behavior of producing reflections, synthesizing digests, or building self-awareness about workspace patterns. Therefore the code chunk materially under-delivers relative to the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a two-stage autonomous introspection/reflection system that produces written reflections and curated digests. The supplied code does none of that. It is a support script for maintaining a recency history file, with actions to check, record, prune, and summarize file visits. While this could plausibly support a larger 'random thought' system, the code chunk itself has a materially different primary purpose and lacks the core declared behaviors of reflection generation, random corpus selection, and synthesis. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The exclusion list includes some sensitive file patterns, but it is incomplete and relies on optional configuration, while the default corpus scans the entire workspace. That means credentials or secrets stored under unexcluded names, alternate extensions, nested config files, cloud credential directories, or plaintext notes can still be selected, read, and then echoed into reflections or digests, creating a real credential exposure path.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
"excludePatterns": [
      "node_modules", ".git", ".next", "dist", "build",
      "venv", "__pycache__", "*.png", "*.jpg", "*.gif",
      "*.mp3", "*.ogg", "*.pdf", "*.zip", "*.env",
      "*.pem", "*.key", "package-lock.json", "*.lock"
    ],
    "minFileSize": "100c",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 96)May include surrounding context.

md
-not -name "*.mp3" -not -name "*.ogg" -not -name "*.m4a" -not -name "*.wav" \
  -not -name "*.mp4" -not -name "*.mov" -not -name "*.avi" \
  -not -name "*.pdf" -not -name "*.zip" -not -name "*.tar" -not -name "*.gz" \
  -not -name "*.env" -not -name "*.pem" -not -name "*.key" \
  -not -name "package-lock.json" -not -name "yarn.lock" -not -name "pnpm-lock.yaml" \
  -not -name "*.lock" \
  -not -name ".random-thought-history" \

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corpus-pick.sh (reported line 55)May include surrounding context.

sh
-not -name "*.mp3" -not -name "*.ogg" -not -name "*.m4a" -not -name "*.wav" \
  -not -name "*.mp4" -not -name "*.mov" -not -name "*.avi" \
  -not -name "*.pdf" -not -name "*.zip" -not -name "*.tar" -not -name "*.gz" \
  -not -name "*.env" -not -name "*.pem" -not -name "*.key" \
  -not -name "package-lock.json" -not -name "yarn.lock" -not -name "pnpm-lock.yaml" \
  -not -name "*.lock" \
  -not -name ".random-thought-history" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README promotes a tool that autonomously reads arbitrary workspace files and generates written reflections, but it does not prominently warn that sensitive content may be ingested and reproduced in outputs. In a workspace context, that can expose secrets, proprietary code, personal notes, or client data through generated observations or digests, especially when users assume the tool is low-risk automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The cron setup encourages unattended, repeated execution without clearly warning that each scheduled run will access workspace content and write persistent outputs automatically. That increases the risk of unnoticed collection, retention, and propagation of sensitive material over time, particularly in shared machines, synced folders, or multi-project workspaces.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly describes reading arbitrary workspace files and producing persistent outputs, yet it declares no tool scope or permission boundaries. In an agent environment, missing permission declarations can cause over-broad file read/write capability and make it harder for users or platforms to enforce least privilege.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill's overview omits a clear warning that it may inspect arbitrary workspace files and persist reflections or digests derived from them. Because the skill is designed for autonomous and scheduled operation, inadequate disclosure increases the risk of users enabling continuous processing of sensitive local content without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manual and cron setup instructions encourage scheduled execution but do not warn that recurring runs will continuously inspect files and create stored artifacts. In practice, this can lead to ongoing collection and retention of sensitive project data, especially in mixed workspaces containing secrets, notes, or proprietary code.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.