Back to skill

Security audit

Ambient Audio

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly an ambient-audio player, but its shell script has unsafe input and process handling that could affect the local machine beyond simply playing sound.

Review this skill before installing. It should not be treated as malicious, but the shell script should be fixed before use: validate duration and volume as bounded numbers, use a private runtime directory for PID state, and stop only the exact child process it started. Also install ffmpeg only if you are comfortable using sudo, and start with low volume because the skill can play sound immediately.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/play.sh:30
Finding

Command Injection Through Unvalidated Duration Input

Content
View full analysis
Remediation
View remediation
&2 exit 2 fi if (( DURATION > 86400 )); then printf 'Error: duration exceeds the permitted maximum\n' >&2 exit 2 fi ``` Additional hardening should include: 1. Reject a duration option when its value is missing: ```bash -d|--duration) [[ $# -ge 2 ]] || { printf 'Error: missing duration value\n' >&2 exit 2 } DURATION=$2 shift 2 ;; ``` 2. Apply similar strict numeric validation to `VOLUME` before inserting it into the `ffplay` filter. 3. Set documented minimum and maximum values to prevent excessive playback duration or resource use. 4. Use `printf` rather than `echo` for predictable error handling. 5. Add regression tests with malformed arithmetic expressions, command substitutions, negative values, empty values, and extremely large integers. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/play.sh:6
Finding

Unsafe Predictable PID File and Overbroad Process Termination

Content
View full analysis
/dev/null rm -f "$PID_FILE" fi pkill -9 -f "ffplay.*focus-audio" 2>/dev/null echo "⏹ Stopped" exit 0 fi ``` The same predictable file is removed and recreated during playback: ```bash # Kill any existing instance first (fast stop) pkill -9 -f "ffplay.*focus-audio" 2>/dev/null rm -f "$PID_FILE" # Start immediately in background ffplay -nodisp -loop 0 -af "volume=$VOLUME" -loglevel quiet "$AUDIO_FILE" -nostats & PID=$! echo $PID > "$PID_FILE" ``` Delayed cleanup again uses broad process-name matching: ```bash if [[ $DURATION -gt 0 ]]; then ( sleep "$DURATION" pkill -9 -f "ffplay.*focus-audio" 2>/dev/null rm -f "$PID_FILE" echo "⏹ Finished" ) & fi ``` ### Technical Analysis The script stores process state in the globally predictable path `/tmp/focus-audio.pid`. It does not verify: - File ownership. - File permissions. - Whether the path is a symbolic link. - Whether the content is exactly one numeric PID. - Whether the referenced PID belongs to an `ffplay` process started by this script. The expression `kill -9 $(cat "$PID_FILE")` uses unquoted command substitution. Shell word splitting allows a manipulated file to produce multiple arguments, causing multiple attacker-selected same-account processes to be passed to `kill`. The `rm -f` followed by `echo ... > "$PID_FILE"` sequence also creates a time-of-check/time-of-use window. A local attacker able to write to `/tmp` can race the script by replacing the path with a symbolic link before the redirection, potentially causing the script to overwrit ...[truncated 2288 chars]
Remediation
View remediation
&2 exit 1 } ``` 3. Verify that the process is the expected child, such as by checking `/proc/$pid/exe`, its command line, and process ownership where available. 4. Quote the validated PID: ```bash kill -TERM -- "$pid" ``` 5. Allow a graceful shutdown interval before using `SIGKILL` as a last resort. 6. Remove all `pkill -f` calls and terminate only the PID captured in `$!`. 7. Write state atomically using a temporary file created inside the protected directory, then rename it: ```bash tmp_pid=$(mktemp "$RUNTIME_DIR/player.pid.XXXXXX") || exit 1 printf '%s\n' "$PID" > "$tmp_pid" mv -f -- "$tmp_pid" "$PID_FILE" ``` 8. Use locking, such as `flock`, to prevent concurrent start and stop invocations from racing. 9. In delayed cleanup, retain the captured PID and terminate that exact process rather than performing command-line pattern matching. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

The skill description claims the audio is algorithmically generated with ffmpeg and focuses only on ambient playback, but the documentation also describes use of pre-generated local MP3 files and omits process-management behavior. This kind of capability/behavior mismatch undermines user trust and can hide operational side effects such as killing processes or managing PID files that a user did not expect from the declared purpose.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
78% confidence
Finding

The phrase 'scientifically-proven' presents a strong natural-language claim about health or performance benefits without qualification. This is a policy-quality concern because it overstates efficacy in user-facing documentation and may mislead users about the effects of the audio modes.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

  • ffmpeg: For audio playback
    bash
    sudo apt-get install ffmpeg
    
  • Audio output: Speakers or headphones connected to the server

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest states there are 'no copyright issues' because all audio is 'algorithmically generated using ffmpeg.' In this script, playback is implemented by selecting files from a samples directory and passing an MP3 file to ffplay, which indicates prerecorded assets are being used rather than generated on demand by ffmpeg.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes immediate audio playback on Linux servers and provides volume settings up to 2.0, but it does not include any user-facing warning that playback may be loud, disruptive, or unsuitable for headphones at high volume. Because the skill can directly affect the user's environment and comfort, a brief warning is warranted in the documentation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The inline documentation labels the script as a 'Focus Audio Player,' implying a narrower intent. The actual mode mapping includes non-focus use cases such as sleep, meditation, rain, binaural, and bowl sounds, which contradicts that stated intent rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.