T09 · Insecure Skill Coding Practices
- Location
SKILL.md:34- Finding
Unsafe Shell Interpolation Guidance Enables Command Injection
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
Needs review: this is a local PII redaction skill, but its own example leaves a full card number visible and the implementation lacks safeguards when redaction fails.
Install only if you are comfortable reviewing redaction results yourself before sharing them. Do not treat the output as guaranteed sanitized for payment data or regulated PII, avoid --show-entities unless you truly need original-value mappings, and consider pinning and verifying the model before setup.
SKILL.md:34Unsafe Shell Interpolation Guidance Enables Command Injection
scripts/redact.py:74Prompt-Delimiter Injection Can Bypass PII Redaction
examples/sample_output.json:2Documented Redaction Output Retains a Full Payment Card Number
scripts/setup.sh:5Model Artifact Is Downloaded from a Mutable Source Without Integrity Verification
The supposedly redacted text still contains a full credit card number (4111 1111 1111 1234), which is a direct failure of redaction for extremely sensitive financial data. In the context of a PII-redaction skill, this is more dangerous because users will reasonably trust the output as safe to store, transmit, or review, potentially causing PCI exposure and financial fraud risk.
The skill uses shell and network-capable operations (bash scripts/setup.sh, curl, model download, and a local server) but does not declare an explicit tool scope such as permissions or allowed-tools. This creates an avoidable trust gap: an agent may invoke broader capabilities than intended during setup or execution, increasing the chance of unintended command execution or network access in a privacy-sensitive skill handling raw PII.
The sample output includes raw sensitive values in the entities[].value fields, which undermines the claim that PII is redacted locally and can normalize unsafe handling of highly sensitive data in logs, docs, or downstream integrations. Because this skill is specifically about PII redaction, exposing original values in example output is especially dangerous: developers may copy this schema and accidentally retain or emit the very data that should be removed.
The skill promises that text never leaves the machine, but it sends all input text to an HTTP service at localhost:8712. Even though this is loopback traffic, the data leaves the calling process boundary and is exposed to whatever is listening on that port, so the privacy guarantee in the skill description is materially overstated. In a PII-redaction skill, this mismatch is more dangerous because users are specifically encouraged to submit highly sensitive data under a strong local-processing claim.
The manifest explicitly says the skill works locally and that text never leaves the machine, which conveys a strongly local-only posture. This setup script performs an external network fetch to download the model from Hugging Face, so the skill is not fully local in operation even if inference later runs locally.
The quick-start instruction says 'set up the PII redactor' and notes that it downloads the model and starts a local server, but it does not clearly warn the user that this performs a network download and installs about 5 GB of model data locally. For a markdown skill description, user-facing warnings should disclose behaviors that affect the user's system or resources.
The top-level documentation states that the script prints the redacted JSON to stdout, but the implementation only prints full JSON when --show-entities is supplied. By default, it parses the model response and prints only the redacted_text field, so the docstring actively misdescribes observable behavior.
This code starts llama-server in the background and persists its PID to a file, which changes the user's local runtime state beyond the script's immediate execution. Although there is a status message, it does not clearly warn that a persistent background service will continue running after setup completes.
No suspicious patterns detected.