Back to skill

Security audit

Full run checklist.md tasks in Claude Code skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent about project-local checklist automation, but it installs automatic Claude session hooks and broad script permissions that deserve manual review before use.

Review this before installing in any sensitive repository. Use it only where checklist.md is trusted, inspect .claude/settings.local.json after install, avoid leaving the SessionStart hook enabled unless you want automatic monitoring, and be careful with uninstall because unrelated local Claude settings may be removed in some cases.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cron-manager.sh:83
Finding

Untrusted PID File Can Cause Termination of Unrelated Processes

Content
View full analysis
/dev/null 2>&1; then kill $pid echo "Monitoring stopped (PID: $pid)" else echo "Monitor process does not exist" fi rm "$PID_FILE" ``` ### Technical Analysis The `stop_monitor` function trusts the contents of the project-local `.monitor.pid` file without validating that the value: - Is a single positive integer. - Identifies a process started by this Skill. - Belongs to the expected monitoring command. - Has not become stale and been reassigned to another process. The value is also passed to `ps` and `kill` without quoting or an option terminator. Because `.monitor.pid` is stored in the working project directory, any user or process able to modify project files can replace its content. Even a syntactically valid PID can identify an unrelated process. PID reuse can produce the same result without deliberate tampering: after the original monitor exits, the operating system may assign its PID to another process while the stale PID file remains. ### Attack Path 1. The Skill creates `.monitor.pid` in the project directory. 2. An attacker or untrusted project process replaces its contents with the PID of another process owned by the victim. 3. The victim or Agent invokes: ```bash ./scripts/main.sh stop ``` or: ```bash ./scripts/main.sh restart ``` 4. `ps` confirms that the attacker-selected PID exists. 5. `kill` sends the default termination signal to that unrelated process. ### Impact Assessment An attacker can terminate processes that the current user is authorized to signal. This may interrupt editors, build jobs, local services, Agent processes, or other user workloads. The flaw does n ...[truncated 124 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/uninstall.sh:81
Finding

Uninstall Logic Can Delete Unrelated Claude Project Settings

Content
View full analysis
/dev/null || echo "false") if [ "$is_empty" = "true" ]; then rm "$PROJECT_SETTINGS" echo " Removed empty settings file: $PROJECT_SETTINGS" fi ``` ### Technical Analysis The code claims to determine whether `.claude/settings.local.json` is empty, but it checks only: - `.permissions.allow` - `.hooks.SessionStart` It ignores every other root-level or nested setting. Consequently, the expression can return `true` when the file still contains unrelated configuration, such as other permission sections, environment configuration, model settings, or hook types other than `SessionStart`. The subsequent `rm` deletes the entire settings file rather than only data owned by Fullrun. ### Attack Path 1. A project has `.claude/settings.local.json` containing legitimate settings unrelated to Fullrun. 2. Its `permissions.allow` and `hooks.SessionStart` arrays are empty or become empty after Fullrun entries are removed. 3. The user runs: ```bash ./scripts/uninstall.sh ``` 4. The incomplete `jq` test evaluates to `true` while unrelated keys remain. 5. The uninstall script deletes the complete settings file. ### Impact Assessment The vulnerability can destroy unrelated project-local Claude configuration. Depending on the removed settings, this may disable security controls, remove required hooks, alter Agent behavior, or disrupt project workflows. The issue does not grant an attacker additional operating-system privileges, but it creates a configuration integrity and avail ...[truncated 45 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/install.sh:31
Finding

Wildcard Permission Trusts Mutable Project-Local Scripts

Content
View full analysis
"$PROJECT_SETTINGS" echo " Created: $PROJECT_SETTINGS" else echo " Found existing: $PROJECT_SETTINGS" fi # Add permissions for project scripts current_allow=$(jq -r '.permissions.allow // [] | .[]' "$PROJECT_SETTINGS" 2>/dev/null || echo "") project_script_pattern="Bash($PROJECT_CLAUDE_DIR/fullrun/scripts/*.sh)" if ! echo "$current_allow" | grep -qF "$project_script_pattern"; then jq --arg pattern "$project_script_pattern" '.permissions.allow += [$pattern]' "$PROJECT_SETTINGS" > "$PROJECT_SETTINGS.tmp" && \ mv "$PROJECT_SETTINGS.tmp" "$PROJECT_SETTINGS" echo " Added permission: $project_script_pattern" else echo " Permission already exists, skipping" fi # Add SessionStart hook for auto-monitoring # The hook checks for checklist.md and .claude-status.txt in current directory at runtime # Build hook JSON using jq to ensure proper escaping HOOK_NAME="fullrun-auto-monitor" HOOK_COMMAND="if [ -f \"\$(pwd)/checklist.md\" ...[truncated 2346 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill description omits that it also performs uninstallation and cleanup operations that delete files and modify .claude/settings.local.json. While cleanup is not inherently malicious, undocumented destructive behavior can surprise users and cause loss of expected project-local automation or settings.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill description omits that it also performs uninstallation and cleanup operations that delete files and modify .claude/settings.local.json. While cleanup is not inherently malicious, undocumented destructive behavior can surprise users and cause loss of expected project-local automation or settings.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The installer silently adds a persistent SessionStart hook that auto-executes a script in later sessions, which is a classic stealthy persistence mechanism even if presented as convenience. This is more dangerous in this skill context because the skill is designed to execute tasks automatically from checklist content, so future sessions may trigger behavior based on project-controlled files without a contemporaneous approval step.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/uninstall.sh (reported line 75)May include surrounding context.

sh
echo "[3/3] Removing installed files..."

if [ -d "$PROJECT_CLAUDE_DIR/fullrun" ]; then
    rm -rf "$PROJECT_CLAUDE_DIR/fullrun"
    echo "      Removed: $PROJECT_CLAUDE_DIR/fullrun"
else
    echo "      Skipped: $PROJECT_CLAUDE_DIR/fullrun (not found)"

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

The phrase 'automatically executes task checklists' indicates autonomous decision-making and action execution, which is risky in this context because tasks are sourced from a project file and delegated to Claude Code for handling. In a repository automation skill, this increases the chance of unintended commands, unsafe file changes, or persistent unattended behavior if checklist contents are mistaken, malicious, or stale.

Content

Scanner excerpt · README.md (reported line 3)May include surrounding context.

md
# Fullrun - Task Executor

A script system that automatically executes task checklists with state management and scheduled checking.

## Requirements

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly advertises unattended task execution and scheduled monitoring, but it does not prominently warn that the skill will modify project files, maintain execution state, and continue operating automatically. This creates a meaningful safety and consent problem: users may install and start it without understanding that it can perform ongoing actions and alter repository contents outside a single interactive run.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill describes shell-based installation, monitoring, and execution behavior but does not declare an explicit tool scope such as permissions or allowed-tools. This creates an authorization gap where a user may invoke the skill without clear visibility into its ability to run shell commands, copy scripts, and modify project-local settings, increasing the risk of unintended code execution.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
87% confidence
Finding

The skill is explicitly designed to automatically execute tasks from checklist.md and to continue scheduled checking via hooks/monitoring. Autonomous execution is risky here because checklist content is effectively treated as executable intent, allowing indirect command execution and repeated actions without per-task user approval, especially once monitoring is installed.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: fullrun
description: Automatically execute tasks from checklist.md with state management and scheduled checking
trigger: When user says "start execution", "run tasks", "execute checklist" or similar commands
---

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger uses the catch-all phrase "or similar commands," which makes activation ambiguous and easier to invoke accidentally from loosely related user requests. In a skill that can run shell scripts and register monitoring hooks, overly broad triggering materially raises the chance of unintended execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script launches fullrun.sh run in a background monitoring loop and only records activity to a log file, without giving a contemporaneous user-facing warning each time execution is triggered. In a skill designed to automatically execute checklist tasks, this can cause unexpected command execution and ongoing actions in the user's project directory after the initial invocation, increasing the chance of unnoticed modifications or unsafe chained behavior.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The script is explicitly designed to autonomously process tasks from checklist.md and present them for an agent to execute without any approval gate, trust boundary validation, or task sanitization. In an agent skill context, that creates an instruction-injection pathway where untrusted checklist content can drive arbitrary actions, including destructive commands or data exfiltration, making the automation materially dangerous.

Content

Scanner excerpt · scripts/fullrun.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash

# Fullrun Script
# Automatically execute tasks from checklist.md with state management and scheduled checking

set -e

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer edits project trust settings and injects a persistent SessionStart command that will execute on future sessions, which goes beyond simple file installation. Because this happens automatically and persists in project configuration, it creates a supply-chain style execution path where opening the project can trigger code without a fresh user decision.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installer grants execution permission for local scripts by modifying settings.local.json without first obtaining explicit confirmation from the user. Silent permission expansion weakens the trust boundary of the project and can normalize broader script execution than the user intended.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The injected SessionStart hook is not necessary for basic checklist execution and creates an automatic execution mechanism tied to future sessions. In the context of an agent skill, hidden or weakly disclosed auto-start behavior is especially risky because it can run scripts whenever the project is opened, expanding the blast radius of any later script modification or misuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script derives WORKDIR from the current directory and then creates, updates, and deletes hidden state files there (.claude-status.txt, .fullrun.log, .monitor.pid) as well as reads checklist.md. In this skill's context, automatic state management tied to whatever directory the user happened to be in can lead to unintended file modification, project pollution, or interference with unrelated repositories if started from the wrong location.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.