Back to skill

Security audit

Programming Assistant

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent programming helper, but its project setup script can write outside the intended directory or overwrite files if given unsafe paths.

Review this skill before installing. It is not evidence of theft or deception, but only use its project setup behavior with trusted, explicit target directories and safe project names; avoid running the bundled shell script on untrusted input or in directories where overwriting README.md or .gitignore would matter.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/init_project.sh:5
Finding

Unrestricted Project Path Permits Directory Traversal and Unsafe File Overwrite

Content
View full analysis

Vulnerability Details

File Location: scripts/init_project.sh, lines 5–6 and 17–70
Vulnerability Type: Path traversal, symlink following, and arbitrary writable-file overwrite
Risk Level: Medium

Vulnerable Code

bash
PROJECT_NAME="$1"
TARGET_DIR="$2"

if [ -z "$PROJECT_NAME" ] || [ -z "$TARGET_DIR" ]; then
    echo "Usage: $0 <project_name> <target_directory>"
    exit 1
fi

echo "Initializing new project: $PROJECT_NAME in $TARGET_DIR"

# Create project directory if it doesn't exist
mkdir -p "$TARGET_DIR/$PROJECT_NAME"

# Create standard project structure
mkdir -p "$TARGET_DIR/$PROJECT_NAME"/{src,tests,docs,config}

# Create basic README
cat > "$TARGET_DIR/$PROJECT_NAME/README.md" << EOF
# $PROJECT_NAME

## Description
Brief description of the project goes here.

## Setup
Instructions for setting up the project locally.

## Usage
How to run and use the project.

## Contributing
Guidelines for contributing to the project.
EOF

# Create a basic .gitignore if git is available
if command -v git >/dev/null 2>&1; then
    cd "$TARGET_DIR/$PROJECT_NAME"
    git init
    cat > .gitignore << EOF
# Dependencies
node_modules/
__pycache__/
*.pyc
*.pyo
*.pyd
.Python
env/
venv/
.venv/

# Build outputs
build/
dist/
*.egg-info/
*.so

# Logs
*.log
logs/

# Environment variables
.env
.env.local

# OS generated files
.DS_Store
Thumbs.db
EOF
fi

echo "Project $PROJECT_NAME initialized successfully in $TARGET_DIR"

Technical Analysis

The script directly combines the caller-controlled TARGET_DIR and PROJECT_NAME values without validating or canonicalizing either path. Although the variables are quoted, quoting only prevents shell word splitting and ordinary shell metacharacter injection; it does not prevent filesystem traversal.

A PROJECT_NAME containing components such as ../ can resolve outside the intended target directory. The script then creates directories, initializes a Git repository, and writes README.md and .gitignore at the re ...[truncated 1579 chars]

Remediation
View remediation

Remediation Suggestions

  1. Restrict PROJECT_NAME to a single safe path component using an allowlist, for example:

    bash
    if [[ ! "$PROJECT_NAME" =~ ^[A-Za-z0-9][A-Za-z0-9._-]*$ ]] ||
       [[ "$PROJECT_NAME" == "." || "$PROJECT_NAME" == ".." ]]; then
        echo "Invalid project name" >&2
        exit 1
    fi
    
  2. Reject project names containing /, absolute paths, traversal components, control characters, or leading option syntax.

  3. Canonicalize the target root and computed destination, then verify that the destination remains beneath the canonical target root before performing any filesystem operation.

  4. Add option terminators to relevant commands:

    bash
    mkdir -p -- "$DESTINATION"
    cd -- "$DESTINATION" || exit 1
    
  5. Refuse to operate on an existing project destination by default. Require an explicit, clearly documented overwrite option if replacement is necessary.

  6. Reject symbolic links before writing template files. Prefer exclusive file creation with no-follow behavior rather than shell redirection where supported.

  7. Enable strict shell error handling and check every operation:

    bash
    set -euo pipefail
    
  8. Apply restrictive creation permissions where appropriate, such as setting a suitable umask, so generated files are not more broadly accessible than intended.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_project.sh (reported line 65)May include surrounding context.

sh
logs/

# Environment variables
.env
.env.local

# OS generated files

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init_project.sh (reported line 66)May include surrounding context.

sh
# Environment variables
.env
.env.local

# OS generated files
.DS_Store

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly directs creation and modification of code and project files but does not warn that following these instructions can change local files or create new artifacts on the user's system. In an agent setting, missing consent and safety boundaries around write operations increases the risk of unintended file changes, especially if the task scope is ambiguous or attacker-influenced.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

Listing Bash and Edit as integrated tools without any warning about their ability to execute commands or modify files normalizes potentially dangerous operations without surfacing local-system impact. In a programming assistant skill, these capabilities can directly affect the host environment, so omission of safeguards materially raises the chance of unsafe command execution or unintended edits.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.