Back to skill

Security audit

Text Search

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward local text-search helper, with one low-risk grep argument-handling issue users should be aware of.

Install only if you are comfortable with a local grep-based search tool reading files in directories you ask it to search. Avoid using untrusted search patterns that begin with '-' unless the script is updated to pass '--' before the pattern.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Note
Location
run.sh:23
Finding

User-Controlled grep Option Injection

Content
View full analysis

Vulnerability Details

File Location: run.sh, line 23
Vulnerability Type: Argument/option injection into grep
Risk Level: Low

Vulnerable Code

bash
grep -rn "$PATTERN" "$DIR_PATH" 2>/dev/null || echo "No matches found."

Technical Analysis

The user-controlled PATTERN is quoted, which prevents shell word splitting and shell metacharacter injection. However, quoting does not prevent grep from interpreting a value beginning with - as a command-line option.

Because the command does not place the -- option terminator before "$PATTERN", an attacker can supply valid grep options instead of ordinary search text. This can alter search behavior and may cause grep to read an attacker-selected auxiliary file through options that accept filenames, such as --exclude-from=FILE.

Additionally, 2>/dev/null suppresses diagnostic output, while || echo "No matches found." treats both the normal no-match status and execution errors identically. This can conceal injected-option failures and complicate detection.

This is argument injection into grep, not shell command injection. The audited code does not use eval, invoke a shell with attacker-generated command text, or provide a demonstrated path to arbitrary command execution.

Attack Path

  1. An attacker supplies a search pattern beginning with a valid grep option.
  2. The Agent or user invokes run.sh with that value as the first argument.
  3. Line 23 passes the value to grep before any -- option terminator.
  4. grep interprets the value as an option rather than strictly as a search pattern.
  5. The attacker changes search semantics, causes unintended auxiliary-file reads where supported by the selected option, or triggers resource-intensive behavior.
  6. Errors may remain hidden because standard error is discarded and all nonzero statuses produce the misleading message No matches found.

Impact Assessment

Exploit ...[truncated 370 chars]

Remediation
View remediation

Remediation Suggestions

Terminate option parsing before passing user-controlled positional arguments:

bash
grep -rn -- "$PATTERN" "$DIR_PATH"

Handle grep exit statuses separately so that a normal no-match result is not confused with an operational failure:

bash
if grep -rn -- "$PATTERN" "$DIR_PATH"; then
  :
else
  status=$?
  if [ "$status" -eq 1 ]; then
    echo "No matches found."
  else
    echo "ERROR: grep failed." >&2
    exit "$status"
  fi
fi

Do not suppress all standard-error output by default. If concise output is required, capture diagnostics and return a clear error for exit code 2. Consider explicitly documenting that the input is a regular expression; if literal text searching is intended, add -F:

bash
grep -rnF -- "$PATTERN" "$DIR_PATH"
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.