Back to skill

Security audit

Skill Logger

Security checks for vulnerabilities and agentic risk

Overview

This skill is a task logger, but it automatically persists complete task details across conversations in broadly shared local locations without enough scoping, permissions, or user control.

Install only if you intentionally want task records, including parameters and results, to persist across conversations. Avoid using it for secrets, credentials, personal data, or sensitive campaign/business details unless storage is confined to a private directory with restrictive permissions and clear retention controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/path_detector.py:20
Finding

Insecure Storage Permissions and Symlink Handling for Sensitive Task History

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/path_detector.py:57
Finding

Unvalidated Persistent Anchor Can Redirect History Writes

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/query_tasks.py:89
Finding

Cross-Scope History Aggregation Can Disclose or Poison Task Records

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/record_task.py:121
Finding

Non-Atomic Unlocked History Updates Permit Record Loss and File Corruption

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (16)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill promotes cross-conversation sharing through a globally writable /tmp location but does not clearly warn users that task parameters, execution history, and platform metadata may become accessible across sessions. In an agent environment, that can leak sensitive operational data from one conversation or tenant into another.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly encourages retaining and querying complete task details in a globally shared store to enable cross-conversation access. That creates a direct confidentiality risk because later sessions can access prior sessions' data without strong isolation, especially in shared /tmp locations that are commonly readable or writable by multiple processes.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly says new conversations can query all previous task records from a globally readable/writable location. This is effectively an intentional cross-session data-sharing channel and can expose sensitive parameters, workflow details, and metadata between unrelated conversations or users.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents capabilities to read environment variables and read/write files, but it declares no explicit tool scope or permissions boundary. In practice this increases the chance that an agent or reviewer will approve or run the skill without understanding that it persists data to disk and inspects environment-derived paths.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documented code example contradicts the stated storage priority by trying workspace/home/cwd paths before /tmp, while the prose says /tmp global sharing is highest priority. This inconsistency is dangerous because operators and dependent skills may assume one storage boundary while the implementation behaves differently, causing unintended data placement, exposure, or failed assumptions about isolation.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The troubleshooting guidance reinforces the expectation that all conversations should share one history file, normalizing insecure data sharing as a feature. This increases the likelihood of deployment in environments where /tmp is shared, leading to unintended disclosure or tampering of task records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Claiming the storage is 'safe and reliable' is misleading because the skill records complete task parameters and detailed operation history, which may contain sensitive business or user data. This can cause users to underestimate confidentiality risks and enable logging where it is inappropriate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Comments, docstrings, exception text, and console output are written entirely in Chinese, including user-visible messages emitted when the script runs. Under the policy, forcing a specific language without user opt-in is a locale/language policy violation unless the constraint is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module probes multiple environment-derived and global locations, then persists the chosen history path in a stable anchor file under the user's home directory. In the context of a cross-dialog global logging skill, this behavior increases the risk of unintentionally collecting and retaining data across sessions and workspaces without clear disclosure or consent, which can expose sensitive task metadata and filesystem locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Natural-language strings in the module docstring and command-line help are fixed to Chinese, which imposes a specific language on users without any opt-in or documented locale constraint. The file does not indicate that the skill is region-specific or offer an alternative language.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script enumerates a broad set of locations including home, cwd, /tmp, /var/tmp, and multiple environment-derived directories, then aggregates records from all matching files. This over-broad search increases the risk of reading attacker-planted or unrelated data, especially because temporary directories and environment variables are easy to influence in many execution contexts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

A query-oriented script should not mutate persistent state, but this fallback path selection logic writes an anchor file and may create directories or test files while determining where history lives. In a shared or multi-tenant environment, this expands the script from read-only inspection into filesystem modification, which can surprise callers, alter global state across sessions, and be abused to influence later reads toward attacker-controlled locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code performs filesystem modifications by creating directories, writing a temporary test file, and deleting it to probe writability. Although the script later prints success or error output, there is no prior disclosure or confirmation to the user that it will modify paths such as the home directory, workspace-related directories, or temp directories.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script stores user-supplied parameters, operations, and results to disk in a shared persistent location without any explicit consent, minimization, or sensitivity filtering. In this skill context, those fields may contain credentials, prompts, internal workflow details, or other sensitive cross-session data, so silent persistence increases the risk of unintended disclosure to other users, tools, or later sessions.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The helper returns and may print more runtime context than is necessary for path selection, including cwd, home directory, workspace environment values, anchor contents, and the full Python version. In a shared agent or multi-tenant environment, these details can leak filesystem layout and prior storage locations, which can aid later targeting or cross-session data discovery.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The output includes exact storage paths and per-file read errors, which can reveal directory layouts, usernames, workspace names, and other environmental details. While low severity by itself, this information disclosure can help an attacker map the filesystem and identify where to place or target history files in conjunction with the script's broad path scanning.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.