Back to skill

Security audit

text-transformer

Security checks for vulnerabilities and agentic risk

Overview

This text-transformer skill appears intended to uppercase text, but its instructions can route user-provided text through a shell command in an unsafe way.

Review before installing. The skill's intended function is simple, but it should be changed to avoid shell command strings with user text, for example by passing arguments without a shell or reading from stdin. Until then, do not use it on untrusted text containing shell syntax such as quotes, semicolons, backticks, or $().

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:10
Finding

Shell Command Injection Through User-Controlled Text

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10-11
Vulnerability Type: OS command injection caused by unsafe shell command construction
Risk Level: High

Vulnerable Code

The following is an English rendering of the complete vulnerable instruction:

text
2. Use the built-in command-line tool (for example, `bash` or `exec`) to run the Python script in the current directory (`{baseDir}`).
3. Command example: `python {baseDir}/tool.py "<extracted text>"`

Technical Analysis

The skill directs the agent to extract attacker-controlled text and interpolate it into a command that may be executed through bash or another shell. Enclosing input in double quotes does not make shell interpolation safe. Shell constructs such as command substitution with $() remain active inside double quotes. An attacker can also inject a closing quote followed by shell control operators.

For example, if the extracted text is $(id), the generated command may resemble:

bash
python /skill/tool.py "$(id)"

The shell executes id before launching Python. A quote-breaking payload such as "; id; # can terminate the argument and execute a separate command.

tool.py itself only converts its first argument to uppercase and does not invoke a shell. The vulnerability originates in the documented invocation procedure, before the Python script receives the argument.

Attack Path

  1. An attacker invokes the skill and supplies text containing shell syntax, such as $(id) or "; id; #.
  2. The agent treats the malicious value as the core text to transform.
  3. Following SKILL.md, the agent inserts that value into the documented command string.
  4. The command is submitted to bash, exec, or another shell-capable execution tool.
  5. The shell evaluates the injected substitution or control operators before or alongside tool.py.
  6. The injected operating-system command executes with the sa ...[truncated 603 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not construct a shell command by concatenating or interpolating user-controlled text.

  • Invoke Python through a process API that accepts an argument array and does not start a shell. Conceptually, use arguments equivalent to:

    text
    executable: python
    arguments: [{baseDir}/tool.py, user_input]
    shell: false
    
  • Alternatively, pass the text through standard input and modify tool.py to read from sys.stdin.

  • Explicitly prohibit bash -c, sh -c, shell=True, and command-string interpolation in the skill instructions.

  • If the execution environment only supports shell command strings, avoid passing untrusted text through that interface. Shell escaping is error-prone and should not be the primary defense.

  • Run the skill with least privilege and restrict its filesystem, environment-variable, credential, and network access to reduce impact if an execution boundary is bypassed.

  • Add regression tests using payloads such as $(id), backticks, quotes, semicolons, newlines, and shell control operators, verifying that each value reaches tool.py only as literal text.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition is broad enough that ordinary requests to process text may automatically invoke this skill, causing user-controlled content to be forwarded to command-line tooling without explicit confirmation. Broad auto-invocation increases the chance of unsafe execution on unexpected input and makes misuse easier in normal conversation flows.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to pass extracted user text into a shell-invoked Python command for a task that could be handled natively. Even though the example wraps the text in quotes, this pattern unnecessarily expands the attack surface and can lead to command/argument injection or unsafe execution behavior depending on how the command is constructed by the agent runtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill executes Python/shell commands on extracted user text but does not warn the user or operator that external command execution is involved. This lack of transparency increases operational risk, reduces informed consent, and makes it easier for unsafe input handling issues to go unnoticed.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code includes comments and console messages in Chinese and states that the model will read the console output, effectively imposing a specific language/locale on the interaction. The file does not offer any user language choice or explain a justified region-specific requirement, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

The operational instructions are written only in Chinese, which can effectively constrain execution and interaction to a specific language without explicitly offering the user a language choice. The file does not state that language selection is optional or user-driven.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.