Back to skill

Security audit

Log Analyzer

Security checks for vulnerabilities and agentic risk

Overview

This is a local log-analysis skill with some quality and terminal-output risks, but no evidence of hidden behavior, exfiltration, persistence, or destructive actions.

Install only if you are comfortable running a local shell script over logs you explicitly choose. Treat production/system logs as sensitive, redact before sharing output, avoid elevated access unless authorized, and be careful analyzing logs from untrusted sources because crafted terminal control characters may affect what your terminal displays.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/log-analyzer.sh:97
Finding

Terminal Control-Sequence Injection Through Untrusted Log and Pattern Output

Content
View full analysis
/dev/null \ | tr '[:upper:]' '[:lower:]' \ | sed 's/^[[:space:]]*//;s/[[:space:]]*$//' \ | sort | uniq -c | sort -rn \ | head -20 \ | awk '{printf "%-5s %-10s %s\n", NR, $1, substr($0, index($0,$2))}' ``` The pattern is printed again in the main summary: ```bash echo -e "${BOLD}Log Analyzer${NC} — Pattern: \"$ERROR_PATTERN\" | Window: ${TIME_WINDOW}h\n" ``` ### Technical Analysis The script handles log files and custom regular-expression patterns as untrusted input, but emits values derived from those inputs directly to an interactive terminal. No filtering or visible encoding of control characters is performed. There are two related injection mechanisms: 1. A custom pattern supplied through `-p` is interpolated into strings passed to `echo -e`. Because `echo -e` interprets backslash escapes, specially constructed pattern text can introduce terminal control characters when displayed. 2. Matched log text is passed through `awk printf` unchanged. Literal ANSI, OSC, or other terminal control sequences embedded in a malicious log record are therefore written directly to the operator's terminal. Depending on terminal capabilities and configuration ...[truncated 1832 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code substantially matches the core declared purpose of analyzing logs for error patterns, IP frequency, time-based summaries, and spike detection. It accepts files or stdin and works on common syslog-like input. However, there is a meaningful description/behavior gap: the declared description explicitly includes alert generation, but the script only prints analysis results and anomaly lines to stdout; it does not generate alerts, send notifications, emit structured alert output, or trigger any downstream action. Additionally, the advertised time-window parameter is displayed but not used to filter entries, and some comments/help mention RFC 5424 support that the implemented sed parsing does not actually handle. These are material enough to count as a mismatch, though there are no suspicious undeclared capabilities beyond local log reading and analysis.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description says to use the skill whenever a user needs log file analysis, error pattern detection, anomaly identification, top error messages, frequency aggregation, or time-based log analysis. This is a wide set of common troubleshooting intents and does not give explicit constraints or negative examples, making the trigger scope overly broad for a manifest-style description.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The examples encourage analysis of system logs like /var/log/syslog and journalctl output without prominently warning that these logs may contain sensitive operational data, credentials, tokens, internal hostnames, or personal data. In an agent setting, broad encouragement to inspect system logs can lead to unnecessary exposure of sensitive information and accidental over-collection, especially when users or agents run the examples on production systems.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
- For large log files (>100MB), consider reducing the time window with `-t` or pre-filtering with grep
- Time-based analysis expects standard syslog date formats (RFC 3164 or RFC 5424); custom formats may need adjustment
- IP detection uses a standard IPv4 regex — IPv6 is not currently supported
- Works without root for user-owned log files; system logs may require sudo

Static analysis

No suspicious patterns detected.