Back to skill

Security audit

erebos

Security checks for vulnerabilities and agentic risk

Overview

This skill appears non-malicious but unreliable: it asks for command execution while its theming script does not implement the advertised accessibility, preview, or export features and one documented option can hang.

Review this package carefully before installing. It does not appear to steal data or persist on the system, but it should not be trusted to produce accessible themes or build artifacts, and its preview command should be fixed before use in automation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/theme-gen.sh:6
Finding

Preview Option Causes an Infinite Loop and Unbounded Output

Content
View full analysis

Vulnerability Details

File Location: scripts/theme-gen.sh, lines 6-24
Vulnerability Type: Denial of service caused by incorrect argument parsing
Risk Level: Medium

Vulnerable Code

bash
# Parse arguments: --palette, --preview, --export
while [[ $# -gt 0 ]]; do
  case $1 in
    --palette)
      shift
      echo "[erebos] Palette mode: $*"
      ;;
    --preview)
      echo "[erebos] Preview mode"
      ;;
    --export)
      echo "[erebos] Export mode"
      shift
      ;;
    *)
      shift
      ;;
  esac
done

Technical Analysis

The argument-processing loop continues while at least one positional argument remains. Most branches consume an argument using shift, but the --preview branch does not.

When --preview is the first positional argument, $# remains greater than zero and $1 remains --preview after every iteration. The same branch is therefore executed indefinitely, repeatedly printing the preview message.

The issue does not grant additional privileges or permit arbitrary command execution. It is nevertheless an availability vulnerability because it can consume CPU time and produce unbounded output. If stdout is redirected to a file or retained by a logging service, it can also consume storage.

Attack Path

  1. An attacker or untrusted automation causes the skill to invoke:
    bash
    ./scripts/theme-gen.sh --preview
    
  2. The loop recognizes --preview.
  3. The branch prints [erebos] Preview mode without consuming the argument.
  4. The loop condition remains true and the same branch executes continuously.
  5. The process remains active until externally terminated, potentially consuming CPU, log capacity, pipeline time, and storage.

Impact Assessment

No elevated privileges, data access, persistence, or code execution can be obtained through this flaw. The affected scope is the process running the script and any sur ...[truncated 171 chars]

Remediation
View remediation

Remediation Suggestions

Consume the --preview argument before leaving its branch:

bash
--preview)
  echo "[erebos] Preview mode"
  shift
  ;;

A safer parser design is to guarantee that every iteration either consumes at least one argument or exits with an error. Additional hardening should include:

  1. Reject unknown options rather than silently consuming them.
  2. Validate the required values for options such as --palette, --export, and --format.
  3. Use set -euo pipefail where compatible.
  4. Add tests that execute every supported option under a timeout and verify successful termination.
  5. Apply process runtime and output-size limits when invoking the script from an Agent or automated service.

other

Note
Location
scripts/theme-gen.sh:3
Finding

Documented Security and Accessibility Functions Are Not Implemented

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17-27 and 31-39; README.md, lines 7-17; scripts/theme-gen.sh, lines 3-24
Vulnerability Type: Misrepresented functionality and false accessibility assurance
Risk Level: Low

Documented Claims

SKILL.md states:

markdown
Erebos provides dark theming for web applications. It generates WCAG-compliant palettes, manages CSS variables and design tokens, and enables runtime theme switching without page reload.

Use Erebos when you need dark mode support, accessible color palettes, or a theming system for your web app.

## How Erebos Works

Erebos builds theme tokens from a base palette. It computes contrast ratios and validates accessibility before output. The engine supports:

- **Palette generation** — Produce dark backgrounds with sufficient contrast
- **Preview mode** — Visualize themes in browser or terminal
- **Export** — Output CSS variables, JSON tokens, or design-system formats

The documented commands include:

bash
# Generate palette from seed colors
./scripts/theme-gen.sh --palette "#1a1a2e" "#16213e"

# Preview in browser (opens local HTML)
./scripts/theme-gen.sh --preview

# Export tokens to stdout or file
./scripts/theme-gen.sh --export --format css

Actual Implementation

bash
#!/usr/bin/env bash
set -e

echo "Copyright Netsnek e.U. 2026"

# Parse arguments: --palette, --preview, --export
while [[ $# -gt 0 ]]; do
  case $1 in
    --palette)
      shift
      echo "[erebos] Palette mode: $*"
      ;;
    --preview)
      echo "[erebos] Preview mode"
      ;;
    --export)
      echo "[erebos] Export mode"
      shift
      ;;
    *)
      shift
      ;;
  esac
done

Technical Analysis

The executable does not generate a palette, calculate contrast ratios, validate WCAG compliance, emit CSS or JSON tokens, create a preview, open a browser, write outpu ...[truncated 1567 chars]

Remediation
View remediation

Remediation Suggestions

Either implement the advertised capabilities or revise the documentation and package metadata so that they accurately describe the script as a placeholder.

If the features are retained, the implementation should:

  1. Parse color values using strict syntax and argument-count validation.
  2. Calculate relative luminance and contrast ratios according to the applicable WCAG formula.
  3. Reject or clearly flag color combinations that do not satisfy the documented conformance threshold.
  4. Implement deterministic CSS and JSON serialization for export mode.
  5. Make preview behavior explicit and avoid launching external programs without clear user confirmation.
  6. Return nonzero exit codes when validation, generation, preview, or export fails.
  7. Keep diagnostics on stderr and generated artifacts on stdout so automated consumers can distinguish them.
  8. Add tests that verify contrast calculations, output schemas, file creation, failure handling, and documentation examples.
  9. Avoid claiming WCAG compliance unless the implementation has been tested against the specific criteria and conformance level being advertised.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest grants the skill executable capability and references a shell script even though the declared purpose is UI theming and palette generation, which does not inherently require command execution at runtime. This unnecessarily expands the attack surface: if the skill or its dependencies are compromised, the host could be induced to run arbitrary shell commands under the skill's authority.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.