Back to skill

Security audit

planning-with-files

Security checks for vulnerabilities and agentic risk

Overview

This planning skill is not clearly malicious, but it automatically feeds project-controlled planning files back into the agent before powerful actions, which users should review carefully.

Install only if you want an agent to create and maintain planning files in each project. Review any existing `task_plan.md` before using it, because the skill can automatically place that file's first lines into context before file edits or shell commands. Avoid using it in untrusted repositories unless the hook behavior is removed or the plan file is clearly treated as untrusted data.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:21
Finding

Untrusted Project Plan Content Is Repeatedly Injected into the Agent Context

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:21-25, SKILL.md:89-95, and templates/task_plan.md:126-130
Vulnerability Type: Indirect instruction hijacking through persistent, project-controlled planning files
Risk Level: Medium

Vulnerable Code

SKILL.md:21-25:

yaml
PreToolUse:
  - matcher: "Write|Edit|Bash"
    hooks:
      - type: command
        command: "cat task_plan.md 2>/dev/null | head -30 || true"

SKILL.md:89-95:

markdown
### 2. The 2-Action Rule
> "After every 2 view/browser/search operations, IMMEDIATELY save key findings to text files."

This prevents visual/multimodal information from being lost.

### 3. Read Before Decide
Before major decisions, read the plan file. This keeps goals in your attention window.

templates/task_plan.md:126-130:

markdown
## Notes
<!--
  REMINDERS:
  - Update phase status as you progress: pending → in_progress → complete
  - Re-read this plan before major decisions (attention manipulation)
  - Log ALL errors - they help avoid repetition

Technical Analysis

The PreToolUse hook reads task_plan.md from the current working directory and inserts its first 30 lines into the context before every Write, Edit, or Bash operation. The file is located in the active project rather than in a trusted, Skill-controlled state directory.

Consequently, a repository author, previous process, or indirect prompt-injection source can control the text printed by this hook. No ownership, provenance, integrity, or content validation is performed before the file is read. The content is also not clearly delimited as untrusted data that must never be interpreted as Agent instructions.

The surrounding Skill instructions amplify this trust-boundary failure by directing the Agent to reread the plan before decisions and persist discoveries in planning files. This creates two related risks:

  1. **Current-session instructio ...[truncated 2643 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove automatic context injection from project-controlled files. Do not print task_plan.md automatically before sensitive tool calls.
  2. Store trusted Agent state separately. Place planning state in a dedicated Skill or application state directory outside the target repository, with restrictive permissions and verified ownership.
  3. Treat project files as untrusted data. If a project plan must be loaded, surround it with explicit boundaries and instructions stating that its contents are data only and must not override user, system, or Skill policies.
  4. Validate provenance and integrity. Record whether the Skill created the file, reject symbolic links and unexpected owners where applicable, and use an integrity marker or structured schema rather than unrestricted Markdown instructions.
  5. Use structured fields. Parse only expected data such as phase names and status values instead of inserting arbitrary file contents into Agent context.
  6. Require approval for consequential actions. Any Bash command, external request, sensitive-file access, or out-of-scope modification derived from planning content should require explicit user confirmation.
  7. Prevent persistent instruction storage. Sanitize findings imported from web pages, repositories, documents, or tool output before writing them to persistent planning files. Never preserve imperative instructions from untrusted sources as Agent rules.
  8. Limit scope and lifecycle. Bind planning state to a specific task, expire or archive it at completion, and do not automatically reuse existing plans across unrelated sessions.
  9. Fail safely. If the plan is absent, malformed, untrusted, or unexpectedly modified, continue without injecting it rather than silently accepting arbitrary content.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill’s declared purpose emphasizes creating and managing planning files, but the implemented hooks also perform implicit runtime behaviors such as pre-tool file reads and a stop-time completion check. This mismatch can mislead users and reviewers about what executes automatically, reducing informed consent and making hidden workflow enforcement easier to introduce or abuse.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/findings.md (reported line 2)May include surrounding context.

md
# Findings & Decisions
<!--
  WHAT: Your knowledge base for the task. Stores everything you discover and decide.
  WHY: Context windows are limited. This file is your "external memory" - persistent and unlimited.
  WHEN: Update after ANY discovery, especially after 2 view/browser/search operations (2-Action Rule).

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/findings.md (reported line 20)May include surrounding context.

md
- Delete tasks
    - Python implementation
-->
<!-- Captured from user request -->
-

## Research Findings

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/task_plan.md (reported line 2)May include surrounding context.

md
# Task Plan: [Brief Description]
<!--
  WHAT: This is your roadmap for the entire task. Think of it as your "working memory on disk."
  WHY: After 50+ tool calls, your original goals can get forgotten. This file keeps them fresh.
  WHEN: Create this FIRST, before starting any work. Update after each phase completes.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · templates/task_plan.md (reported line 9)May include surrounding context.

md
-->

## Goal
<!--
  WHAT: One clear sentence describing what you're trying to achieve.
  WHY: This is your north star. Re-reading this keeps you focused on the end state.
  EXAMPLE: "Create a Python CLI todo app with add, list, and delete functionality."

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Broad auto-activation criteria can cause the skill to trigger during many normal tasks, expanding the circumstances in which its hooks run. In this skill, that increases unnecessary file access and shell-command execution, which raises operational and privacy risk even if the commands are simple.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Advertising vague auto-activation for 'complex tasks' without concrete limits encourages unpredictable activation and reduces user awareness of when shell-backed hooks will run. That ambiguity is risky in a skill with Bash access and automatic command hooks, because users may not realize project files are being read or validation scripts executed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This markdown file includes example actions such as writing task_plan.md, notes.md, summaries, and config.json, but does not warn readers that following the pattern will create or modify files in the workspace. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or system state.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The template is documented as a file-based planning aid, but the inline comment at L126 and repeated note at L131 explicitly describe re-reading the plan as "attention manipulation." That wording contradicts the manifest's benign planning/documentation purpose by characterizing the mechanism as manipulating the agent rather than organizing work.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.