Back to skill

Security audit

Release Preflight

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent release-checking purpose, but its scanner can follow symlinks and read outside the selected folder, so it should be reviewed before use.

Install or use this only if you are comfortable with a local scanner reading files in the target you provide. Avoid running it on untrusted bundles or broad directories until symlink rejection, resolved-path containment checks, regular-file validation, and file-size limits are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/release_preflight.py:101
Finding

Unbounded Out-of-Root File Reads Through Symbolic Links

Content
View full analysis

Vulnerability Details

File Location: scripts/release_preflight.py, lines 101-105 and 113-120
Vulnerability Type: Symbolic-link following, insufficient path-boundary validation, and unbounded file reads
Risk Level: Medium

Vulnerable Code

python
def scan_text_file(path: Path):
    try:
        return path.read_text(errors='ignore')
    except Exception:
        return ''

The vulnerable function is reached from the identity-leak scanner:

python
def find_identity_leaks(root: Path):
    hits = []
    for path in list_paths(root):
        if should_skip_identity_scan(root, path):
            continue
        if not path.is_file() or path.suffix.lower() not in TEXT_EXTS:
            continue
        text = scan_text_file(path)

Technical Analysis

The scanner recursively discovers paths beneath an audit target and reads files whose names have supported text extensions. It does not reject symbolic links or resolve each candidate and verify that the resolved path remains beneath the target root.

Both Path.is_file() and Path.read_text() follow symbolic links. Consequently, a symbolic link located inside an attacker-controlled bundle can point to a readable file outside the intended audit directory. If the link has an accepted extension, such as probe.md, the scanner opens and reads its external target with the privileges of the scanner process.

The complete file is also loaded into memory without a maximum size. A link to an oversized file or suitable special file can therefore consume excessive memory, stall the audit, or otherwise deny service. The broad exception handler does not prevent resource exhaustion that occurs while reading.

The current report does not reproduce arbitrary file contents. However, it can expose whether predefined path markers occur in the external file, creating a limited content oracle and confirming information about files outside the auth ...[truncated 1593 chars]

Remediation
View remediation

Remediation Suggestions

  1. Reject symbolic links before checking or reading candidate files:

    python
    if path.is_symlink():
        return ''
    
  2. Resolve both the root and candidate path, then require the candidate to remain beneath the resolved root:

    python
    resolved_root = root.resolve()
    resolved_path = path.resolve(strict=True)
    try:
        resolved_path.relative_to(resolved_root)
    except ValueError:
        # Skip and report an out-of-root path.
        continue
    
  3. Verify that candidates are regular files rather than devices, FIFOs, sockets, or other special files. Use lstat() where appropriate so validation does not silently follow links.

  4. Apply a conservative maximum file size using metadata before opening the file. Treat files exceeding the threshold as skipped findings rather than reading them completely.

  5. Read content incrementally and stop after a bounded number of bytes instead of using unrestricted read_text().

  6. Report skipped symbolic links, out-of-root paths, special files, and oversized files so users understand that the scan was incomplete.

  7. Where race conditions are relevant, open files using platform facilities that prohibit symbolic-link following, then validate the opened descriptor rather than relying only on path checks performed before opening.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Anti-Refusal Statement

High
Category
Anti-Refusal
Confidence
80% confidence
Finding

Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.

Content

Scanner excerpt · references/rules.md (reported line 40)May include surrounding context.

md
## Decision model
- `not_ready`: blocking issues exist.
- `ready_after_fixes`: no blocking issues, but warnings exist.
- `ready`: no blocking issues and no warnings worth stopping on.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill instructs the agent to read multiple reference files and run a local script, which implies filesystem access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an underspecified trust boundary: a host may permit broader file access than intended, increasing the chance of reading or operating on sensitive local content when the skill is invoked on arbitrary paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.