T09 · Insecure Skill Coding Practices
- Location
scripts/init_skill.py:181- Finding
Unvalidated Skill Name Allows Output-Directory Escape
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a legitimate skill-building assistant, but it has broad authority around creating, editing, testing, and packaging skills that deserves user review before installation.
Install only if you are comfortable with a skill that can guide an agent to create and edit skills, run local helper scripts, spawn evaluation agents, and package distributable .skill files. Before sharing any generated package, inspect the archive contents, keep secrets and private data out of skill folders, avoid symlinks inside skill directories, and make sure any local review server is stopped after use.
scripts/init_skill.py:181Unvalidated Skill Name Allows Output-Directory Escape
scripts/package_skill.py:72Symbolic-Link Dereference Can Include External Files in Skill Archives
The skill includes packaging and archive-generation behavior that is not clearly reflected in the high-level description. Hidden or under-disclosed file/archive creation capabilities can surprise users, increase the chance of unsafe execution, and make reviewers underestimate the skill's ability to generate distributable artifacts.
The skill includes packaging and archive-generation behavior that is not clearly reflected in the high-level description. Hidden or under-disclosed file/archive creation capabilities can surprise users, increase the chance of unsafe execution, and make reviewers underestimate the skill's ability to generate distributable artifacts.
The skill includes packaging and archive-generation behavior that is not clearly reflected in the high-level description. Hidden or under-disclosed file/archive creation capabilities can surprise users, increase the chance of unsafe execution, and make reviewers underestimate the skill's ability to generate distributable artifacts.
The skill explicitly tells the author to make generated skill descriptions 'pushy' and to trigger even when the user does not explicitly ask for that skill. This promotes overbroad auto-invocation, which can cause unrelated or more powerful skills to activate inappropriately, expanding access to tools, files, or workflows beyond user intent.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
# Print next steps
print(f"\n✅ Skill '{skill_name}' initialized successfully at {skill_dir}")
print("\nNext steps:")
print("1. Edit SKILL.md to complete the TODO items and update the description")
print("2. Customize or delete the example files in scripts/, references/, and assets/")
print("3. Run the validator when ready to check the skill structure")
The skill instructs the agent to read and write files, invoke shell commands, launch scripts, and optionally use network-adjacent tooling, but it declares no explicit tool scope or allowed-tools constraints. That creates an over-privileged skill surface where downstream agents may execute powerful operations without a clear least-privilege boundary or user-visible restriction.
Using nohup to launch the review server creates a background process that persists beyond the immediate interaction and may continue serving local content or consuming resources after the task ends. Persistent processes reduce auditability and can expose review artifacts or stale services if not reliably cleaned up.
nohup python <skill-creator-path>/eval-viewer/generate_review.py \
<workspace>/iteration-N \
--skill-name "my-skill" \
--benchmark <workspace>/iteration-N/benchmark.json \
The packager recursively includes every file under the skill directory, which can unintentionally bundle secrets, local test data, editor metadata, private notes, or other non-distribution artifacts into the resulting .skill archive. Because this tool is specifically for creating distributable packages, overbroad inclusion creates a realistic information disclosure risk if skill folders contain sensitive files that were never meant to be shipped.
No suspicious patterns detected.