Back to skill

Security audit

Config Sync — 16 AI Tools, 1 Source

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but its file-writing script can overwrite or read outside the chosen repository in symlinked projects and can broaden AI rules into persistent always-on instructions.

Install only if you are comfortable with a tool that rewrites AI assistant instruction files in a target repository. Run it first with --dry-run, avoid using it on untrusted repositories, inspect for symlinks before running, and review generated instruction files before committing or using them with AI coding assistants.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/config-sync.py:82
Finding

Repository-Controlled Symlinks Allow File Reads and Writes Outside the Target Repository

Content
View full analysis
Remediation
View remediation
Path: resolved_repo = repo.resolve(strict=True) resolved_path = path.resolve(strict=False) if not resolved_path.is_relative_to(resolved_repo): raise ValueError(f"Path escapes repository: {path}") return resolved_path ``` 2. Explicitly reject symbolic links for source files, output files, and each relevant parent directory. Do not rely only on lexical path checks. 3. For source files, use `lstat()` or equivalent no-follow checks before opening them. Recheck at open time where possible to reduce time-of-check/time-of-use race conditions. 4. For output files, use no-follow file-opening semantics such as `os.open()` with `O_NOFOLLOW` on platforms that support it. 5. Write output to a securely created temporary file inside the validated destination directory, flush and synchronize it, and then atomically replace the intended destination after repeating boundary and symlink checks. 6. Refuse to operate when `.claude`, `.claude/rules`, an output directory, or an existing output file is a symlink. 7. Add automated tests covering: - Symlinked `.claude/rules/*.md` files. - A symlinked `.claude/rules` directory. - Symlinked output files. - Symlinked output parent directories. - Paths that resolve outside the repository. ]]>

T01 · Skill Instruction Hijacking

Warning
Location
scripts/config-sync.py:76
Finding

Scoped Source Rules Are Converted into Global, Always-On AI Instructions

Content
View full analysis
str: """Remove YAML frontmatter (--- ... ---) from content.""" return re.sub(r"^---\n.*?\n---\n?", "", content, count=1, flags=re.DOTALL).strip() ``` ```python if rules_dir.is_dir(): md_files = sorted(rules_dir.glob("*.md")) if md_files: for f in md_files: raw = f.read_text(encoding="utf-8") clean = strip_frontmatter(raw) if clean: parts.append(f"## {f.stem}\n\n{clean}") return "\n\n".join(parts) ``` ```python def format_cursor(source: str) -> str: """MDC format for Cursor rules.""" mdc_front = "---\ndescription: Project coding rules (auto-synced)\nglobs: **\nalwaysApply: true\n---\n\n" return f"{mdc_front}{source}\n" ``` ### Technical Analysis The canonical Claude rule format can use YAML frontmatter to limit a rule by file pattern, activation mode, or other conditions. The implementation removes that metadata without parsing or preserving its security-relevant scope. All cleaned rules are then concatenated into flat instruction files. Cursor output is explicitly assigned: ```yaml globs: ** alwaysApply: true ``` This changes conditional or narrowly scoped instructions into global, always-active instructions. Root-level outputs such as `AGENTS.md`, `GEMINI.md`, and `.github/copilot-instructions.md` similarly receive rule content without the original activation restrictions. This behavior also conflicts with the documentation in `SKILL.md`, which states that glob patterns are converted to natural-language headers. The implementation performs no such conversion. The transformation can therefore amplify an untrusted instruction beyond the context in which it was intended to o ...[truncated 1676 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill explicitly instructs users to run a local script that reads from and writes to repository files, yet the skill metadata declares no tool scope or permission boundaries. In an agent ecosystem, missing file access constraints increases the risk of unintended modification of arbitrary paths or repos, especially because the examples accept a user-supplied repository path and default to generating many files.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation phrases are broad and loosely scoped, including generic requests like 'generate ai rules' and 'config sync', which can cause the skill to trigger in contexts the user did not clearly intend. Because the skill performs repository-wide config generation and file writes across many tool-specific locations, accidental invocation can lead to widespread unintended changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

In init mode, the script writes one or more rule files derived from CLAUDE.md, which changes repository contents and may replace existing files with the same generated names. The function prints what it created after the fact, but it does not warn beforehand or ask the user to confirm the potentially modifying operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code creates parent directories and writes tool-specific config files directly into the target repository, which can overwrite existing files and alter project state. Although the script has a top-level description and a dry-run option, there is no user-facing warning or confirmation at the point of write that these files will be modified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The natural-language activation text uses Spanish ('ACTIVAR cuando el usuario dice...') and includes Spanish trigger phrases, but the rest of the document is in English and does not explain any locale-specific requirement or offer language choice. This can create an implicit language/locale policy inconsistency without user opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest description enumerates outputs such as CLAUDE.md, AGENTS.md, GEMINI.md, Cursor, Copilot, Windsurf, Cline, CONVENTIONS.md, Kiro, Amazon Q, Goose, and Trae configs. However, the code also defines support for 'zed' and the module docstring claims support for '16+ AI coding tools' including tools like Codex/Amp/OpenCode/Warp beyond the manifest's stated list, expanding the behavior beyond the described scope.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.