Back to skill

Security audit

Cc Statusline

Security checks for vulnerabilities and agentic risk

Overview

This Claude Code statusline skill is purpose-aligned, but it has unsafe script generation and automatic dependency installation paths that deserve review before installation.

Review the scripts before installing. Prefer using a system-installed jq, avoid automatic dependency installation, and do not pass untrusted text into custom layout, theme, icon, or target-path arguments. If installed, understand that it persists a Claude Code statusLine command in ~/.claude/settings.json and may run the generated script whenever the statusline refreshes.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/generate_custom_statusline.sh:52
Finding

Arbitrary Command Execution Through Unsafe Custom Statusline Generation

Content
View full analysis
> "$TARGET_PATH" # ---- cc-statusline custom layout override ---- export CC_STATUSLINE_CUSTOM_LAYOUT_MODE=true export CC_STATUSLINE_CUSTOM_THEME="${THEME}" export CC_STATUSLINE_CUSTOM_ICON_STYLE="${ICON_STYLE}" export CC_STATUSLINE_CUSTOM_LINE_1="${LINE_1}" export CC_STATUSLINE_CUSTOM_LINE_2="${LINE_2}" export CC_STATUSLINE_CUSTOM_LINE_3="${LINE_3}" EOF ``` ### Technical Analysis `THEME`, `ICON_STYLE`, and the three layout values originate from command-line arguments and are embedded directly into an executable Bash script. The values are neither strictly validated nor encoded as shell literals. An attacker-controlled value can contain shell syntax such as command substitution, closing quotation marks, or newline-delimited commands. For example, a layout value containing `$(attacker_command)` would produce a generated line similar to: ```bash export CC_STATUSLINE_CUSTOM_LINE_1="$(attacker_command)" ``` When the generated statusline is later executed, Bash evaluates the command substitution. A newline can similarly escape the intended assignment and add independent shell statements. This is particularly significant because `activate_custom_statusline.sh` stores the generated script as Claude Code's `statusLine.command`. Consequently, the injected payload may execute whenever Claude Code refreshes the statusline, rather than only during initial generation. The generated assignments are appended after the complete runtime script. The normal preset rendering path in `statusline.sh` does not terminate with an explicit `exit`, so Bash continues into the appended content and evaluates injected shell syntax. ### Attack Path 1. An attacker influences a module list, theme, icon style, or command supplied to ...[truncated 1200 chars]
Remediation
View remediation
> "$TARGET_PATH" ``` 4. Prefer storing customization in JSON and parsing it as data rather than generating executable shell source. 5. Generate configuration before runtime execution, or pass validated data as arguments, instead of appending executable statements to the end of the runtime script. 6. Refuse to overwrite an existing unmanaged target file without explicit confirmation and create a backup before replacement. 7. Add regression tests using quotes, command substitutions, backticks, semicolons, and multiline input to verify that none can produce executable statements. ]]>

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/install_jq.sh:42
Finding

Unverified Mutable jq Executables Are Downloaded and Executed Automatically

Content
View full analysis
/dev/null; then curl -fsSL -o "$dest" "$url" elif command -v wget &>/dev/null; then wget -q -O "$dest" "$url" elif command -v powershell.exe &>/dev/null; then powershell.exe -Command "Invoke-WebRequest -Uri '$url' -OutFile '$dest'" else echo "ERROR: No download tool found (curl/wget/powershell). Please download jq manually:" echo " $url" echo " Save to: $dest" exit 1 fi chmod +x "$dest" echo "jq installed at: $dest" } ``` The downloaded file is subsequently executed by the verification logic: ```bash if existing=$(check_jq); then echo "jq successfully installed: $($existing --version)" else echo "ERROR: jq installation failed. Please install manually from https://jqlang.github.io/jq/download/" exit 1 fi ``` The installers trigger this process automatically when jq is absent: ```bash ensure_jq() { if JQ_BIN=$(choose_jq_bin); then log "Using jq at $JQ_BIN" return 0 fi warn "jq not found. Attempting automatic install." if [ -f "$INSTALL_JQ_SCRIPT" ]; then bash "$INSTALL_JQ_SCRIPT" || true fi if JQ_BIN=$(choose_jq_bin); then log "jq installed successfully at $JQ_BIN" return 0 fi fail_manual 'jq is required for the statusline runtime and ...[truncated 2587 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (45)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The README explicitly states that the skill updates ~/.claude/settings.json and stores state under ~/.claude, which means it modifies the agent's configuration directory and can persist behavior across sessions. In the context of an AI-operated install flow, changing agent config is security-relevant because a compromised or trojanized skill could use this mechanism to alter future agent behavior or establish persistence.

Content

Scanner excerpt · README.en.md (reported line 65)May include surrounding context.

md
- theme and icon style switching
- backup of the target script to `<target>.bak`
- previous `statusLine` snapshot saved to `~/.claude/cc-statusline-state.json`
- updates only the `statusLine` field in `~/.claude/settings.json`
- uninstall removes only `statusLine` and keeps generated scripts on disk

## Current repository layout

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

This section describes writing a runtime script to ~/.claude/statusline.sh and updating ~/.claude/settings.json, again confirming direct modification of agent-controlled config and executable paths. Even though the intended use is legitimate statusline customization, any mechanism that places executable content in the agent config area and points settings at it creates a persistence and code-execution surface if abused.

Content

Scanner excerpt · README.en.md (reported line 89)May include surrounding context.

md
- backs up the target script to `<target>.bak`
- preserves the previous `statusLine` value in `~/.claude/cc-statusline-state.json`
- writes the runtime script to `~/.claude/statusline.sh` by default
- updates only the `statusLine` field in `~/.claude/settings.json`
- asks before replacing a foreign `statusLine` configuration

### 2. Generate a custom statusline

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The uninstall instructions still operate on ~/.claude/settings.json, confirming the skill has ongoing authority to alter agent configuration. While removal of statusLine is not inherently malicious, any documented workflow that instructs an agent to edit its config directory is security-sensitive because it can be repurposed to disable protections, redirect commands, or leave partial persistence artifacts on disk.

Content

Scanner excerpt · README.en.md (reported line 139)May include surrounding context.

bash ~/.claude/skills/cc-statusline/scripts/uninstall_statusline.sh

text

This removes only the `statusLine` field from `~/.claude/settings.json`.
Generated script files stay on disk unless the user explicitly wants them removed.

### 4. `.skill` packaging

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
92% confidence
Finding

The skill is explicitly designed to modify Claude's configuration under ~/.claude/settings.json and persist state in the agent config directory. Even if limited to the statusLine field, writes to agent configuration are security-sensitive because a compromised or flawed workflow could alter future agent behavior or establish persistent execution through a statusline command/script.

Content

Scanner excerpt · README.md (reported line 65)May include surrounding context.

md
- 支持主题与图标风格切换
- 覆盖安装前会将目标脚本备份到 `<目标路径>.bak`
- 会把旧的 `statusLine` 快照保存到 `~/.claude/cc-statusline-state.json`
- 只修改 `~/.claude/settings.json` 里的 `statusLine` 字段
- 卸载时只移除 `statusLine`,默认保留已生成脚本

## 当前仓库结构

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
94% confidence
Finding

This section documents writing an executable statusline script to ~/.claude/statusline.sh and then updating ~/.claude/settings.json to point at it. That combination creates persistent local code execution in the agent context whenever the statusline runs, so if the generated script or activation path is influenced by untrusted input it could become a durable execution vector.

Content

Scanner excerpt · README.md (reported line 89)May include surrounding context.

md
- 将目标脚本备份到 `<目标路径>.bak`
- 把旧的 `statusLine` 值保存到 `~/.claude/cc-statusline-state.json`
- 默认把运行时脚本写入 `~/.claude/statusline.sh`
- 仅修改 `~/.claude/settings.json` 里的 `statusLine` 字段
- 如果检测到外部已有 `statusLine` 配置,会先询问再覆盖

### 2. 生成自定义状态栏

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The uninstall flow still performs direct modification of ~/.claude/settings.json, which is privileged application state. Although the intended action is removal rather than persistence, any tool that edits agent configuration can be abused or can corrupt settings if parsing and field targeting are not tightly controlled.

Content

Scanner excerpt · README.md (reported line 139)May include surrounding context.

bash ~/.claude/skills/cc-statusline/scripts/uninstall_statusline.sh

text

该脚本只会移除 `~/.claude/settings.json` 中的 `statusLine` 字段。
除非用户明确要求,否则不会删除已生成的脚本文件。

### 4. `.skill` 打包

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared purpose is statusline configuration, but the behavior described by analysis includes installing jq, using sudo/package managers, and downloading binaries from GitHub releases. That is a materially broader trust boundary than users would expect from a UI/statusline customization skill, and it could lead to host-level changes or supply-chain exposure under misleading pretenses.

Content

No source excerpt is available for this finding.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The skill targets ~/.claude/settings.json and related files in the agent configuration directory, which are security-sensitive because they influence persistent agent behavior. Even though the text says only statusLine should be modified, compromising or misusing writes in this location can persist configuration changes across sessions.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

md
默认路径:
- preset target / 预设脚本:`~/.claude/statusline.sh`
- custom target / 自定义脚本:`~/.claude/statusline.custom.sh`
- settings / 设置文件:`~/.claude/settings.json`
- state snapshot / 状态快照:`~/.claude/cc-statusline-state.json`

## Language behavior / 语言行为

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The troubleshooting workflow explicitly directs inspection and likely modification of ~/.claude/settings.json, reinforcing that the skill operates on persistent agent configuration. Access to this file is sensitive because mistakes or abuse can alter future agent execution behavior beyond the immediate task.

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

md
When install or activation fails, inspect in this order:
安装或启用失败时,按这个顺序排查:
1. target script exists / 目标脚本是否存在
2. `~/.claude/settings.json` contains the expected `statusLine` / `settings.json` 是否写入预期 `statusLine`
3. jq availability / jq 是否可用
4. whether an old foreign `statusLine` blocked overwrite / 是否被旧的外部配置拦住
5. whether re-running the wrapper is enough / 是否只需重跑脚本

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

The post-action summary confirms that ~/.claude/settings.json is updated, indicating persistent config mutation is a core behavior of the skill. Persistent writes to agent config are inherently sensitive and should be treated as privileged operations even when limited to one field.

Content

Scanner excerpt · SKILL.md (reported line 285)May include surrounding context.

text
Done / 已完成
- Generated / 生成: <file or not needed>
- Updated / 更新: ~/.claude/settings.json (statusLine only)
- Backup / 备份: <path or none>
- Snapshot / 快照: ~/.claude/cc-statusline-state.json
- Active command / 当前命令: <statusLine.command or not active>

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

Using pacman -Sy --noconfirm is dangerous because -Sy refreshes package databases without a full upgrade and --noconfirm suppresses interaction, a combination that can lead to unsafe or inconsistent package operations. In an automated agent workflow, this creates a high-risk path for silent system modification and reduces the chance a user notices or stops an unexpected install.

Content

Scanner excerpt · scripts/install_jq.sh (reported line 95)May include surrounding context.

sh
sudo yum install -y jq
    elif command -v pacman &>/dev/null; then
        echo "Installing jq via pacman..."
        sudo pacman -Sy --noconfirm jq
    elif command -v zypper &>/dev/null; then
        echo "Installing jq via zypper..."
        sudo zypper install -y jq

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Accessing $HOME/.claude/settings.json gives the script visibility into agent configuration such as permissions mode, MCP server presence, thinking mode, and fast mode. While there is no exfiltration in this file, reading from the agent config directory is sensitive because it can reveal security posture and local integration details that may be surfaced in output or influence downstream behavior.

Content

Scanner excerpt · scripts/statusline.sh (reported line 401)May include surrounding context.

sh
fi
fi

settings_path="$HOME/.claude/settings.json"
project_settings="$cwd/.claude/settings.json"

effort_level="high"

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Accessing $cwd/.claude/settings.json allows the script to inspect project-specific Claude permissions and MCP configuration. In this skill context that may support useful display features, but it also means arbitrary workspace metadata is read from a sensitive project config location and reflected into status output without explicit user awareness.

Content

Scanner excerpt · scripts/statusline.sh (reported line 402)May include surrounding context.

sh
fi

settings_path="$HOME/.claude/settings.json"
project_settings="$cwd/.claude/settings.json"

effort_level="high"
[ -n "${CLAUDE_CODE_EFFORT_LEVEL:-}" ] && effort_level="$CLAUDE_CODE_EFFORT_LEVEL"

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/uninstall_statusline.sh (reported line 121)May include surrounding context.

sh
fi

    warn 'Automatic uninstall failed.'
    warn 'Manual fallback: remove only the statusLine field from ~/.claude/settings.json and keep script files as desired.'
    exit 1
}

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The manual install instructions establish persistent artifacts under ~/.claude/skills/cc-statusline, causing the skill to remain available in future Claude Code sessions. Persistence is expected for installed skills, but from a security perspective it is still a meaningful capability because maliciously modified skill contents could survive session restarts and continue influencing agent behavior.

Content

Scanner excerpt · README.en.md (reported line 42)May include surrounding context.

bash
git clone https://github.com/Miluer-tcq/cc-statusline
mkdir -p ~/.claude/skills/cc-statusline
cp -r cc-statusline/SKILL.md cc-statusline/scripts cc-statusline/presets cc-statusline/themes cc-statusline/icons cc-statusline/references ~/.claude/skills/cc-statusline/

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README states that Claude Code can trigger the skill via 'natural language' without defining clear activation constraints. This is ambiguous for a markdown skill description because it does not specify which phrases are in-scope versus out-of-scope, increasing the chance of unintended invocation from ordinary statusline-related requests.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.en.md (reported line 42)May include surrounding context.

bash
git clone https://github.com/Miluer-tcq/cc-statusline
mkdir -p ~/.claude/skills/cc-statusline
cp -r cc-statusline/SKILL.md cc-statusline/scripts cc-statusline/presets cc-statusline/themes cc-statusline/icons cc-statusline/references ~/.claude/skills/cc-statusline/

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

bash
git clone https://github.com/Miluer-tcq/cc-statusline
mkdir -p ~/.claude/skills/cc-statusline
cp -r cc-statusline/SKILL.md cc-statusline/scripts cc-statusline/presets cc-statusline/themes cc-statusline/icons cc-statusline/references ~/.claude/skills/cc-statusline/

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The documented install procedure copies files into ~/.claude/skills/cc-statusline, establishing persistence across future Claude Code sessions. Persistent installation is expected for a skill, but from a security perspective it increases blast radius because any later compromise of the skill contents or trust in the repository affects subsequent sessions automatically.

Content

Scanner excerpt · README.md (reported line 42)May include surrounding context.

bash
git clone https://github.com/Miluer-tcq/cc-statusline
mkdir -p ~/.claude/skills/cc-statusline
cp -r cc-statusline/SKILL.md cc-statusline/scripts cc-statusline/presets cc-statusline/themes cc-statusline/icons cc-statusline/references ~/.claude/skills/cc-statusline/

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to read files, write configuration under ~/.claude, and execute shell scripts, but it declares no explicit tool scope or permission boundary. That omission increases the chance the skill will run with broader-than-necessary capabilities, making unintended host modification harder to audit or constrain.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
1. target script exists / 目标脚本是否存在
2. `~/.claude/settings.json` contains the expected `statusLine` / `settings.json` 是否写入预期 `statusLine`
3. jq availability / jq 是否可用
4. whether an old foreign `statusLine` blocked overwrite / 是否被旧的外部配置拦住
5. whether re-running the wrapper is enough / 是否只需重跑脚本

Prefer re-running the wrapper script over telling the user to edit JSON manually.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 247)May include surrounding context.

md
1. target script exists / 目标脚本是否存在
2. `~/.claude/settings.json` contains the expected `statusLine` / `settings.json` 是否写入预期 `statusLine`
3. jq availability / jq 是否可用
4. whether an old foreign `statusLine` blocked overwrite / 是否被旧的外部配置拦住
5. whether re-running the wrapper is enough / 是否只需重跑脚本

Prefer re-running the wrapper script over telling the user to edit JSON manually.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

These Chinese trigger phrases are broad enough to match generic 'status bar' requests without requiring clear Claude Code context, which can cause the wrong skill to activate. In an agent system, over-triggering can lead to irrelevant configuration steps, unintended file changes, or confusing guidance in contexts unrelated to Claude Code.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The customization examples include generic phrases such as generating or adjusting a status bar/theme that could apply to many unrelated products. This increases the chance of accidental invocation on shell prompts, IDE bars, or web UI requests, causing the agent to apply the wrong skill in a broader operational context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code writes to the user's settings.json and replaces its statusLine configuration, and also persists state to a separate file. While there are success logs after completion, there is no prior confirmation prompt, inline comment/docstring warning, or other explicit disclosure near the write operations that user configuration files will be modified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.