Back to skill

Security audit

GEDCOM Explorer

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its generated HTML can execute GEDCOM-supplied HTML or JavaScript and stores private family data in a shareable file without a clear warning.

Install only if you will process GEDCOM files you trust and keep the generated HTML private. Treat the output as a sensitive export of the full family tree, including hidden or non-visible records, and avoid uploading, emailing, or hosting it unless you intend to publish that data. Do not open generated files from unknown GEDCOM sources until the renderer escapes data safely.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/build_explorer.py:420
Finding

Stored HTML and JavaScript Injection in Generated Family Tree Dashboard

Content
View full analysis
{TITLE} ``` ```html
Remediation
View remediation
', '\\u003e') .replace('\u2028', '\\u2028') .replace('\u2029', '\\u2029') ) ``` Apply this function to people, family, and statistics data. 2. **Prefer non-executable JSON containers.** Store serialized data in ` ``` ```javascript const PEOPLE = JSON.parse( document.getElementById('people-data').textContent ); ``` 3. **Eliminate `innerHTML` for untrusted data.** Construct elements through DOM APIs and assign GEDCOM values using `textContent`: ```javascript const place = document.createElement('div'); place.className = 'person-place'; place.textContent = '📍 ' + p.birthPlace; ``` Apply this change to people cards, timeline entries, alerts, charts, tree nodes, spotlight cards, fun facts, and the person modal. 4. **Escape display metadata by output context.** HTML-escape `TITLE` and `SUBTITLE` before placing them in ``, headings, paragraphs, or attributes. Do not rely on one generic escaping method for HTML text, JavaScript strings, and HTML attributes. 5. **Remove string-based inline event handlers.** Replace generated `onclick` attributes with `addEventListener`. Keep identifiers in JavaScript variables or validated `data-*` attributes rather than interpolating them into executable source. 6. **Add a restrictive Content Security Policy as defense in depth.** Remove inline scripts and hand ...[truncated 920 chars]
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description is mostly aligned with the broad GEDCOM-to-HTML family dashboard behavior, but it omits a substantial president-centric specialization present throughout the code. The script detects presidents from OCCU fields, derives party affiliation, surfaces presidential stats/charts, labels alerts as 'presidential history,' claims presidents in fun facts, and only populates tree roots with presidents. Those are not minor implementation details; they materially shape the generated app's behavior and focus. So this is a description-behavior mismatch, even though the genealogy dashboard functionality itself is genuinely implemented.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
python3 scripts/build_explorer.py <input.ged> [output.html] [--title "Title"] [--subtitle "Subtitle"]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
python3 scripts/build_explorer.py <input.ged> [output.html] [--title "Title"] [--subtitle "Subtitle"]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
python3 scripts/build_explorer.py <input.ged> [output.html] [--title "Title"] [--subtitle "Subtitle"]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
python3 scripts/build_explorer.py <input.ged> [output.html] [--title "Title"] [--subtitle "Subtitle"]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
python3 scripts/build_explorer.py <input.ged> [output.html] [--title "Title"] [--subtitle "Subtitle"]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill advertises executable workflow steps that read a user-supplied GEDCOM file and write a generated HTML file, but it declares no explicit tool scope or permissions boundary. In an agent environment, this ambiguity can cause the agent to access local files or create outputs without clear user-visible authorization, increasing the risk of unintended file access or data handling beyond what the user expects.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly states that all parsed genealogy data is embedded as inline JSON in a single HTML file, but it does not warn users that sharing or hosting that file exposes the full contents of the GEDCOM. GEDCOM files often contain sensitive family-history and living-person information, so a self-contained export can easily leak private data if emailed, synced, published, or served locally without understanding the exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code writes a complete interactive dashboard containing names, birth/death details, places, relatives, and other family-history data to an HTML file. Although the script logs that it is generating output, it does not warn the user that potentially sensitive personal or family data will be persisted in a shareable local artifact.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML template sets lang="en" and the interface labels, headings, and messages throughout the generated page are fixed in English. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.