Back to skill

Security audit

Ai Companion Diet

Security checks for vulnerabilities and agentic risk

Overview

This diet-tracking skill is purpose-aligned overall, but it stores sensitive health data and contains unsafe input handling that can execute local code when crafted meal, step, or weight values are supplied.

Review before installing. Use only in a trusted local environment, avoid entering adversarial or copied meal/weight/step values, and prefer a fixed version that validates numeric inputs, passes data to Python as arguments instead of generated code, and clearly documents privacy, deletion, and file-permission behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
modules/recorder.sh:171
Finding

Arbitrary Python Code Execution Through Unvalidated Numeric Arguments

Content
View full analysis
"$weight_history" fi python3 << EOF import json with open("$weight_history", 'r', encoding='utf-8') as f: history = json.load(f) # Remove an existing record from the same day history = [h for h in history if h['date'] != '$today'] history.append({'date': '$today', 'weight': $weight}) with open("$weight_history", 'w', encoding='utf-8') as f: json.dump(history, f, ensure_ascii=False, indent=2) EOF ``` ### Technical Analysis The `record_steps` and `record_weight` functions accept command-line arguments without validating their format. These values are expanded directly into unquoted Python heredocs and consequently become part of executable Python source code. For example, `$steps` is not passed to Python as a string or integer argument. Instead, it is substituted into this statement: ```python data['steps'] = ATTACKER_CONTROLLED_TEXT ``` An attacker can provide text containing a valid initial expression, a semicolon, additional Python statements, and a comment marker. Python then interprets the supplied statements as program code rather than record data. Quoting the argument when invoking the Bash scrip ...[truncated 1458 chars]
Remediation
View remediation
&2 return 1 } ``` - Validate weight as a decimal number and enforce medically reasonable minimum and maximum values. - Pass values as command-line arguments or environment variables instead of inserting them into Python source. - Use a quoted heredoc delimiter to disable shell interpolation: ```bash python3 - "$daily_file" "$steps" <<'PY' import json import sys path = sys.argv[1] try: steps = int(sys.argv[2]) except ValueError: raise SystemExit("Invalid step count") with open(path, "r", encoding="utf-8") as f: data = json.load(f) data["steps"] = steps with open(path, "w", encoding="utf-8") as f: json.dump(data, f, ensure_ascii=False, indent=2) PY ``` - Apply the same typed-argument pattern to both weight-update heredocs. - Return an error before modifying files if validation fails. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
modules/recorder.sh:105
Finding

Python Code Injection Through Meal Descriptions and Weights

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
modules/calculator.sh:7
Finding

Expression Injection Through Unvalidated Values Passed to bc

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

声明描述的是一个较完整的减肥陪伴技能,而代码片段只是底层计算模块,主要提供代谢、热量、步数、BMI等公式计算。虽然其中“热量差=目标步数”的核心理念与部分代码一致,但大量被明确宣称的用户功能在代码中完全没有体现。没有发现明显的额外越权或危险未声明能力;问题主要在于声明显著高于实际实现范围,因此描述不能准确代表该代码块的实际行为。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明描述的是一个较完整的减肥陪伴系统,包含提醒、记录、分析、预测和对话优化等多项能力。但该代码块实际只覆盖“提醒模块”相关行为:基于当前时间触发三餐、步数、睡前总结和饮水提醒,提供鼓励消息,并从本地日记录中读取步数数据进行简单比较。代码没有显示实现饮食打卡、断食管理、加餐记录、平台期解释、体重趋势预测或多轮对话等关键宣称能力。因此,代码行为只对应声明中的一部分,声明对该代码块的能力表述明显更宽,存在描述与实际行为不一致。未发现额外越权资源访问或无关危险能力,但功能范围存在显著不匹配。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation is presented entirely in Chinese, which effectively imposes a language choice on users without any opt-in, alternative language option, or stated region-specific justification. Under the policy, language constraints should either be optional for the user or clearly documented as necessary for a specific locale or compliance context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill documents file read/write behavior through persistent storage files but does not declare any tool scope, permissions, or allowed-tools boundaries. This creates an authorization and transparency gap: a host may grant broader filesystem access than users expect, and reviewers cannot verify that access is limited to the minimum necessary for health data handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill collects and stores sensitive health data including age, sex, height, weight history, goals, and activity level, but the documentation provides no privacy notice, retention policy, access controls, or handling safeguards. In a health-focused context this is more dangerous because the data is highly personal and could expose medical inferences, habits, and long-term body metrics if accessed improperly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell skill’s comments and all user-facing output strings are written in Chinese, and there is no indication that the user can opt into another language or that the skill is intentionally limited to a Chinese-speaking context. That creates a natural-language locale policy issue under the rule for forced language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This shell skill contains all user-facing comments and reminder messages in Chinese, including the outputs shown to users. The policy only permits forcing a specific language when the skill offers user opt-in or clearly documents a justified regional constraint, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script collects and stores sensitive health data including gender, age, height, weight, target weight, and activity level in local JSON files without any privacy notice, consent flow, retention policy, or file-permission hardening. In a diet/health companion context, this data is especially sensitive because it can reveal health status and habits, and local plaintext storage increases exposure to other local users, backups, logs, or malware.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

This shell skill uses Chinese for user-facing comments and category labels such as BMI classifications without indicating that the user can choose another language. The policy explicitly calls for flagging language or locale constraints when a skill forces a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.