Back to skill

Security audit

File Compress Optimizer

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently compresses user-selected memory/prose files, but users should know it sends the selected file content to Claude and then overwrites the file after making a backup.

Install only if you are comfortable sending the complete selected memory/prose file to Anthropic or the authenticated Claude CLI. Do not run it on notes that contain secrets, tokens, personal data, or confidential project details, and confirm the exact target path because successful compression overwrites that file while saving a .original.md backup.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/compress.py:155
Finding

Full File Contents May Be Disclosed to a Third-Party Model Despite Sensitive-Path Filtering

Content
View full analysis
bool: # Resolve and validate path filepath = filepath.resolve() MAX_FILE_SIZE = 500_000 # 500KB if not filepath.exists(): raise FileNotFoundError(f"File not found: {filepath}") if filepath.stat().st_size > MAX_FILE_SIZE: raise ValueError(f"File too large to compress safely (max 500KB): {filepath}") # Refuse files that look like they contain secrets or PII. Compressing ships # the raw bytes to the Anthropic API — a third-party boundary — so we fail # loudly rather than silently exfiltrate credentials or keys. Override is # intentional: the user must rename the file if the heuristic is wrong. if is_sensitive_path(filepath): raise ValueError( f"Refusing to compress {filepath}: filename looks sensitive " "(credentials, keys, secrets, or known private paths). " "Compression sends file contents to the Anthropic API. " "Rename the file if this is a false positive." ) print(f"Processing: {filepath}") if not should_compress(filepath): print("Skipping (not natural language)") return False original_text = filepath.read_text(errors="ignore") ``` The file content is subsequently embedded into the model prompt: ```python def build_compress_prompt(original: str) -> str: return f""" Compress this markdown into caveman format. STRICT RULES: - Do NOT modify anything inside ``` code blocks - Do NOT modify anything inside inline backticks - Preserve ALL URLs exactly - Preserve ALL headings exactly - Preserve file paths and commands - Return ONLY the compressed markdown body — do NOT wrap the entire output in a ```markdown fence or any other fence. Inner code block ...[truncated 4337 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is another variant of the same description-behavior inconsistency, emphasizing undisclosed validation/comparison and alternate CLI workflow. Such discrepancies make the skill harder to safely review and can conceal unexpected processing paths, especially since the skill operates on user-supplied files and launches code via the shell.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This is another variant of the same description-behavior inconsistency, emphasizing undisclosed validation/comparison and alternate CLI workflow. Such discrepancies make the skill harder to safely review and can conceal unexpected processing paths, especially since the skill operates on user-supplied files and launches code via the shell.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

This is another variant of the same description-behavior inconsistency, emphasizing undisclosed validation/comparison and alternate CLI workflow. Such discrepancies make the skill harder to safely review and can conceal unexpected processing paths, especially since the skill operates on user-supplied files and launches code via the shell.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/compress.py (reported line 21)May include surrounding context.

python
# Filenames and paths that almost certainly hold secrets or PII. Compressing
# them ships raw bytes to the Anthropic API — a third-party data boundary that
# developers on sensitive codebases cannot cross. detect.py already skips .env
# by extension, but credentials.md / secrets.txt / ~/.aws/credentials would
# slip through the natural-language filter. This is a hard refuse before read.
SENSITIVE_BASENAME_REGEX = re.compile(

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/compress.py (reported line 22)May include surrounding context.

python
# Filenames and paths that almost certainly hold secrets or PII. Compressing
# them ships raw bytes to the Anthropic API — a third-party data boundary that
# developers on sensitive codebases cannot cross. detect.py already skips .env
# by extension, but credentials.md / secrets.txt / ~/.aws/credentials would
# slip through the natural-language filter. This is a hard refuse before read.
SENSITIVE_BASENAME_REGEX = re.compile(
    r"(?ix)^("

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/compress.py (reported line 22)May include surrounding context.

python
# Filenames and paths that almost certainly hold secrets or PII. Compressing
# them ships raw bytes to the Anthropic API — a third-party data boundary that
# developers on sensitive codebases cannot cross. detect.py already skips .env
# by extension, but credentials.md / secrets.txt / ~/.aws/credentials would
# slip through the natural-language filter. This is a hard refuse before read.
SENSITIVE_BASENAME_REGEX = re.compile(
    r"(?ix)^("

Credential Access

High
Category
Privilege Escalation
Confidence
80% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/compress.py (reported line 27)May include surrounding context.

python
SENSITIVE_BASENAME_REGEX = re.compile(
    r"(?ix)^("
    r"\.env(\..+)?"
    r"|\.netrc"
    r"|credentials(\..+)?"
    r"|secrets?(\..+)?"
    r"|passwords?(\..+)?"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/detect.py (reported line 14)May include surrounding context.

python
# Extensions that are code/config and should be skipped
SKIP_EXTENSIONS = {
    ".py", ".js", ".ts", ".tsx", ".jsx", ".json", ".yaml", ".yml",
    ".toml", ".env", ".lock", ".css", ".scss", ".html", ".xml",
    ".sql", ".sh", ".bash", ".zsh", ".go", ".rs", ".java", ".c",
    ".cpp", ".h", ".hpp", ".rb", ".php", ".swift", ".kt", ".lua",
    ".dockerfile", ".makefile", ".csv", ".ini", ".cfg",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/detect.py (reported line 74)May include surrounding context.

python
# Extensions that are code/config and should be skipped
SKIP_EXTENSIONS = {
    ".py", ".js", ".ts", ".tsx", ".jsx", ".json", ".yaml", ".yml",
    ".toml", ".env", ".lock", ".css", ".scss", ".html", ".xml",
    ".sql", ".sh", ".bash", ".zsh", ".go", ".rs", ".java", ".c",
    ".cpp", ".h", ".hpp", ".rb", ".php", ".swift", ".kt", ".lua",
    ".dockerfile", ".makefile", ".csv", ".ini", ".cfg",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes a shell command and processes arbitrary file paths, but it declares no explicit tool scope or permission boundaries. In an agent environment, missing scope metadata can let the skill run with broader-than-expected file, environment, and shell access, increasing the chance of unsafe execution or misuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger includes broad natural-language activation like 'compress memory file,' which can cause accidental invocation on unintended files or contexts. Because the skill can overwrite originals and run shell/Python code, ambiguous triggering materially raises the risk of unsafe or unauthorized execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The usage/docstring omits that the script transmits the entire file body to Anthropic/Claude, which can mislead users into believing compression is performed locally. Because the tool targets human-authored memory files that may contain internal project context, personal preferences, or operational notes, lack of user-facing warning increases the chance of unintentional data exfiltration across a third-party boundary.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The implementation sends full file contents to Anthropic either through the SDK or the claude CLI, but the skill metadata/description presents the feature as local file compression and does not prominently disclose this third-party transmission. In a memory-management skill, users may reasonably pass sensitive notes, preferences, or task files, so undisclosed external transfer creates a meaningful confidentiality risk.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/compress.py (reported line 92)May include surrounding context.

python
pass  # anthropic not installed, fall back to CLI
    # Fallback: use claude CLI (handles desktop auth)
    try:
        result = subprocess.run(
            ["claude", "--print"],
            input=prompt,
            text=True,

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

For a skill presented as compressing memory markdown files, reading ANTHROPIC_API_KEY and CAVEMAN_MODEL from the environment introduces credential handling and runtime configuration behavior beyond the manifest's stated scope. This capability is only understandable because the implementation relies on an external LLM service, which itself is not declared in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.