Back to skill

Security audit

Brainstorming

Security checks for vulnerabilities and agentic risk

Overview

The skill is a legitimate brainstorming helper, but it also forces broad agent workflow changes and runs an under-scoped local web companion with persistence and unauthenticated event handling.

Review before installing. Use this only if you want a strict design-first workflow and a browser companion. Avoid binding the companion to 0.0.0.0 unless you can contain network access, add .superpowers/ to .gitignore, clean up session files, and get explicit approval before commits or long-running server use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Mandatory Workflow and Tool-Selection Hijacking

Content
View full analysis
Do NOT invoke any implementation skill, write any code, scaffold any project, or take any implementation action until you have presented a design and the user has approved it. This applies to EVERY project regardless of perceived simplicity. ``` ```markdown 1. **Explore project context** — check files, docs, recent commits 2. **Offer visual companion** (if topic will involve visual questions) — this is its own message, not combined with a clarifying question. See the Visual Companion section below. 3. **Ask clarifying questions** — one at a time, understand purpose/constraints/success criteria 4. **Propose 2-3 approaches** — with trade-offs and your recommendation 5. **Present design** — in sections scaled to their complexity, get user approval after each section 6. **Write design doc** — save to `docs/superpowers/specs/YYYY-MM-DD--design.md` and commit 7. **Spec review loop** — dispatch spec-document-reviewer subagent with precisely crafted review context (never your session history); fix issues and re-dispatch until approved (max 3 iterations, then surface to human) 8. **User reviews written spec** — ask user to review the spec file before proceeding 9. **Transition to implementation** — invoke writing-plans skill to create implementation plan ``` ```markdown **The terminal state is invoking writing-plans.** Do NOT invoke frontend-design, mcp-builder, or any other implementation skill. The ONLY skill you invoke after brainstorming is writing-plans. ``` ```markdown - Invoke the writing-plans skill to create a detaile ...[truncated 1881 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/server.cjs:164
Finding

Unauthenticated WebSocket Allows User-Event Spoofing

Content
View full analysis
{ buffer = Buffer.concat([buffer, chunk]); while (buffer.length > 0) { let result; try { result = decodeFrame(buffer); } catch (e) { socket.end(encodeFrame(OPCODES.CLOSE, Buffer.alloc(0))); clients.delete(socket); return; } if (!result) break; buffer = buffer.slice(result.bytesConsumed); switch (result.opcode) { case OPCODES.TEXT: handleMessage(result.payload.toString()); break; case OPCODES.CLOSE: socket.end(encodeFrame(OPCODES.CLOSE, Buffer.alloc(0))); clients.delete(socket); return; case OPCODES.PING: socket.write(encodeFrame(OPCODES.PONG, result.payload)); break; case OPCODES.PONG: break; default: { const closeBuf = Buffer.alloc(2); closeBuf.writeUInt16BE(1003); socket.end(encodeFrame(OPCODES.CLOSE, closeBuf)); clients.delete(socket); return; } } } }); socket.on('close', () => clients.delete(socket)); socket.on('error', () => clients.delete(socket)); } function handleMessage(text) { let event; try { event = JSON.parse(text); } catch (e) { consol ...[truncated 2649 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/stop-server.sh:10
Finding

Unvalidated Session Directory Enables Arbitrary Same-User Process Termination and Temporary-Directory Deletion

Content
View full analysis
"}' exit 1 fi PID_FILE="${SCREEN_DIR}/.server.pid" if [[ -f "$PID_FILE" ]]; then pid=$(cat "$PID_FILE") # Try to stop gracefully, fallback to force if still alive kill "$pid" 2>/dev/null || true # Wait for graceful shutdown (up to ~2s) for i in {1..20}; do if ! kill -0 "$pid" 2>/dev/null; then break fi sleep 0.1 done # If still running, escalate to SIGKILL if kill -0 "$pid" 2>/dev/null; then kill -9 "$pid" 2>/dev/null || true # Give SIGKILL a moment to take effect sleep 0.1 fi if kill -0 "$pid" 2>/dev/null; then echo '{"status": "failed", "error": "process still running"}' exit 1 fi rm -f "$PID_FILE" "${SCREEN_DIR}/.server.log" # Only delete ephemeral /tmp directories if [[ "$SCREEN_DIR" == /tmp/* ]]; then rm -rf "$SCREEN_DIR" fi echo '{"status": "stopped"}' else echo '{"status": "not_running"}' fi ``` ### Technical Analysis The script fully trusts its first argument as a session directory. It reads an arbitrary `.server.pid` beneath that path and sends both SIGTERM and, if needed, SIGKILL without confirming that the PID belongs to this project's Node.js server, the current session, or even a related process. The cleanup condition accepts every path textually beginning with `/tmp/`, not only directories generated under the intended `/tmp/brainstorm-*` namespace. It does not canonicalize the path, reject symlinks, verify session metadata, or ensure that the deletion target was created by the Skill. Consequently, a caller-controlled directory can select both a same-user process and a recursive deletion target. ### Attack Path 1. An attacker or unsafe cal ...[truncated 1092 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/helper.js:47
Finding

DOM-Based Cross-Site Scripting in Selection Indicator

Content
View full analysis
{ const indicator = document.getElementById('indicator-text'); if (!indicator) return; const container = target.closest('.options') || target.closest('.cards'); const selected = container ? container.querySelectorAll('.selected') : []; if (selected.length === 0) { indicator.textContent = 'Click an option above, then return to the terminal'; } else if (selected.length === 1) { const label = selected[0].querySelector('h3, .content h3, .card-body h3')?.textContent?.trim() || selected[0].dataset.choice; indicator.innerHTML = '' + label + ' selected — return to terminal to continue'; } else { indicator.innerHTML = '' + selected.length + ' selected — return to terminal to continue'; } }, 0); ``` ### Technical Analysis For a single selected option, the helper extracts a label using `textContent` and then concatenates that value into an `innerHTML` assignment. Extracting with `textContent` does not make the value safe for later HTML parsing. Character sequences that appear as visible encoded markup in the source can be decoded into text by the browser and then reparsed as active markup when assigned to `innerHTML`. The companion serves Agent-generated HTML screens and intentionally supports full HTML documents. If any option content is influenced by untrusted project data, copied external content, or maliciously crafted screen content, the label may contain an HTML payload. Clicking the option activates the vulnerable sink. No restrictive Content Security Policy is set by the HTTP server, so inline event handlers or other browser-supported payloads are not blocked by ...[truncated 1144 chars]
Remediation
View remediation
`, quotes, encoded elements, and event-handler payloads to confirm that they remain inert text. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (19)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is about pre-implementation intent and design exploration, but the code is a browser helper for interactive UI instrumentation and live communication. Its primary purpose is not requirements discovery or brainstorming logic; instead it captures clicks on elements with data-choice, manages selected-state UI, sends events over WebSocket, and responds to server messages by reloading the page. These are materially different capabilities from the declared purpose and include undeclared network communication and remote-control behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents the skill as a conceptual requirements/design exploration aid to be used before creative or implementation work. The supplied code does not implement intent exploration or design analysis logic; instead, it is operational infrastructure for launching a local/remote brainstorm server. Its primary purpose is process and server management, including filesystem writes, environment setup, network binding, and lifecycle control. While this server may support brainstorming indirectly, the code chunk itself materially differs from the declared purpose and performs undeclared capabilities centered on server startup and system/process management.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a requirements/design exploration skill used before implementation work. The supplied code does not perform any intent exploration, planning, or design analysis. Instead, it manages server shutdown by reading a PID file, sending signals to terminate a process, deleting server artifacts, and removing ephemeral directories. This is a materially different primary purpose and includes operational capabilities—process control and filesystem cleanup—that are not reflected in the description.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This file implements a full HTTP/WebSocket server with file serving, live reload, and lifecycle management, which materially exceeds the declared purpose of a brainstorming-only skill. Expanding a low-risk planning skill into a persistent network service increases attack surface, enables unexpected remote interaction, and creates a capability mismatch that can be abused or overlooked during review.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code maintains a persistent interactive HTTP/WebSocket service, accepts upgrades without authentication, and processes inbound client messages. Even though it binds to localhost by default, this is still dangerous in skill context because it introduces hidden runtime behavior and a long-lived communications channel unrelated to brainstorming, increasing the chance of unauthorized local interaction, data exposure, or misuse by other processes.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill declares it 'MUST' be used before any creative work and repeats mandatory gating throughout, making it applicable to nearly any development request. Overly broad trigger conditions can be abused to hijack agent control flow, force unnecessary context gathering, and delay or redirect user-requested actions even when not appropriate.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
## Checklist

You MUST create a task for each of these items and complete them in order:

1. **Explore project context** — check files, docs, recent commits
2. **Offer visual companion** (if topic will involve visual questions) — this is its own message, not combined with a clarifying question. See the Visual Companion section below.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to write a spec file and commit it to git as part of the default flow, but it does not require an explicit warning and consent immediately before modifying the repository. In an agent setting, automatic file creation and commits are security-relevant side effects that can surprise users, alter history, and persist potentially sensitive content.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script opens a WebSocket to the current host, streams interaction data, queues events for later transmission, and accepts server-driven reload commands. Those capabilities are unrelated to a brainstorming skill's stated purpose and create an unnecessary bidirectional control channel that can leak user behavior and allow remote manipulation of the page state.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code blindly trusts server-sent WebSocket messages and executes a page reload whenever it receives a message with type 'reload'. Even though reload is not code execution, it gives the remote endpoint an unjustified control primitive that can disrupt user workflow, cause denial of service through repeated reloads, and serve as a foothold for further manipulation if the page content changes on reload.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script captures user clicks and choice metadata, including text content and element identifiers, and transmits them over a WebSocket without any visible disclosure or consent mechanism. In the context of a brainstorming skill, this silent behavioral telemetry is unexpected and increases privacy and trust risks, especially because selected text may contain sensitive project or planning information.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The server logs user-supplied WebSocket events to stdout and appends selected events to a .events file on disk without clear necessity for a brainstorming skill. This creates unnecessary retention of interaction data, which can expose sensitive user choices or prompts to other local users, tools, or later processes and is especially unjustified given the stated non-implementation purpose.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/start-server.sh (reported line 67)May include surrounding context.

sh
FOREGROUND="true"
fi

# Windows/Git Bash reaps nohup background processes. Auto-foreground when detected.
if [[ "$FOREGROUND" != "true" && "$FORCE_BACKGROUND" != "true" ]]; then
  case "${OSTYPE:-}" in
    msys*|cygwin*|mingw*) FOREGROUND="true" ;;

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/start-server.sh (reported line 124)May include surrounding context.

sh
FOREGROUND="true"
fi

# Windows/Git Bash reaps nohup background processes. Auto-foreground when detected.
if [[ "$FOREGROUND" != "true" && "$FORCE_BACKGROUND" != "true" ]]; then
  case "${OSTYPE:-}" in
    msys*|cygwin*|mingw*) FOREGROUND="true" ;;

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

This same command sequence also reflects intentional session persistence because it is paired with later detachment from the shell job table. That makes the server harder for the invoking environment to track and can leave orphaned processes running if cleanup fails, which is a meaningful operational and security concern for agent-managed tooling.

Content

Scanner excerpt · scripts/start-server.sh (reported line 123)May include surrounding context.

sh
fi

# Start server, capturing output to log file
# Use nohup to survive shell exit; disown to remove from job table
nohup env BRAINSTORM_DIR="$SCREEN_DIR" BRAINSTORM_HOST="$BIND_HOST" BRAINSTORM_URL_HOST="$URL_HOST" BRAINSTORM_OWNER_PID="$OWNER_PID" node server.cjs > "$LOG_FILE" 2>&1 &
SERVER_PID=$!
disown "$SERVER_PID" 2>/dev/null

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

This same command sequence also reflects intentional session persistence because it is paired with later detachment from the shell job table. That makes the server harder for the invoking environment to track and can leave orphaned processes running if cleanup fails, which is a meaningful operational and security concern for agent-managed tooling.

Content

Scanner excerpt · scripts/start-server.sh (reported line 123)May include surrounding context.

sh
fi

# Start server, capturing output to log file
# Use nohup to survive shell exit; disown to remove from job table
nohup env BRAINSTORM_DIR="$SCREEN_DIR" BRAINSTORM_HOST="$BIND_HOST" BRAINSTORM_URL_HOST="$URL_HOST" BRAINSTORM_OWNER_PID="$OWNER_PID" node server.cjs > "$LOG_FILE" 2>&1 &
SERVER_PID=$!
disown "$SERVER_PID" 2>/dev/null

Session Persistence

Medium
Category
Rogue Agent
Confidence
91% confidence
Finding

Using 'disown' detaches the background server from the shell job table, reducing the parent shell's ability to manage or clean up the process. In this skill, that makes persistence more dangerous because the brainstorm server may outlive the invoking agent session and remain accessible unexpectedly.

Content

Scanner excerpt · scripts/start-server.sh (reported line 126)May include surrounding context.

sh
# Use nohup to survive shell exit; disown to remove from job table
nohup env BRAINSTORM_DIR="$SCREEN_DIR" BRAINSTORM_HOST="$BIND_HOST" BRAINSTORM_URL_HOST="$URL_HOST" BRAINSTORM_OWNER_PID="$OWNER_PID" node server.cjs > "$LOG_FILE" 2>&1 &
SERVER_PID=$!
disown "$SERVER_PID" 2>/dev/null
echo "$SERVER_PID" > "$PID_FILE"

# Wait for server-started message (check log file)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide explicitly directs the agent to persist browser-rendered HTML and user interaction events inside the project under .superpowers/brainstorm/, but it does not require clear user consent or a strong warning that these artifacts may remain on disk. That creates a privacy and data-retention risk because user selections, exploratory clicks, and potentially sensitive mockup content can be stored longer than expected and may later be read, backed up, or committed accidentally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Recommending --project-dir for persistence increases the chance that generated screens, helper metadata, and browser interaction artifacts are retained in the repository workspace without a sufficiently prominent privacy notice. In a brainstorming context, those artifacts may include product ideas, design drafts, or user preference signals that are sensitive and not intended for durable project storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.