Security checks for vulnerabilities and agentic risk
Overview
The skill is a coherent local changelog tool, but its installed command wrapper can run a same-named script from the current directory and its client/public outputs can include internal changelog data.
Review this skill before installing. Do not use the installed nex-changelog command from untrusted repositories unless the wrapper is fixed to execute only the real installed script. Treat imported commit messages, internal notes, client emails, repo paths, and security-fix descriptions as sensitive, and manually review email or Telegram output before sharing it externally.
Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)
T07 · Tool Hijacking and Spoofing
Error
Location
setup.sh:75
Finding
Current-Working-Directory Executable Hijacking in Installed CLI Wrapper
Content
View full analysis
Vulnerability Details
File Location: setup.sh, lines 75–78 and line 101 Vulnerability Type: Executable path hijacking through an untrusted current working directory Risk Level: High
Vulnerable Code
bash
# First, check if we're in the skill directory
if [ -f "nex-changelog.py" ]; then
SKILL_DIR="$(pwd)"
elif [ -f "$HOME/.local/share/nex-changelog/nex-changelog.py" ]; then
SKILL_DIR="$HOME/.local/share/nex-changelog"
elif [ -f "/opt/nex-changelog/nex-changelog.py" ]; then
SKILL_DIR="/opt/nex-changelog"
else
# Fallback: find relative to this script (works if properly linked from skill directory)
SCRIPT_REAL_PATH="$(cd "$(dirname "$(readlink -f "$WRAPPER_SCRIPT")")/../.." && pwd)/nex-changelog"
if [ -f "$SCRIPT_REAL_PATH/nex-changelog.py" ]; then
SKILL_DIR="$SCRIPT_REAL_PATH"
else
echo "ERROR: Could not find nex-changelog installation" >&2
exit 1
fi
fi
# Run the Python script
python3 "$SKILL_DIR/nex-changelog.py" "$@"
Technical Analysis
The setup script generates a globally accessible wrapper at ~/.local/bin/nex-changelog. That wrapper gives precedence to a file named nex-changelog.py in the caller's current working directory. Merely checking that the file exists does not establish that it is the legitimate application, nor does the wrapper validate its ownership, permissions, canonical path, or integrity.
Consequently, command resolution is influenced by an attacker-controlled directory. Although the user appears to invoke the trusted nex-changelog command, the wrapper can execute an unrelated local Python program. Quoting the path prevents shell injection but does not mitigate selection of the wrong executable.
The vulnerable selection occurs at lines 75–78, while the selected file is executed at line 101. Both operations form one exploitable data flow.
Attack Path
An attacker creates or distrib
...[truncated 1504 chars]
Remediation
View remediation
Remediation Suggestions
Remove current-working-directory discovery entirely. The installed wrapper must never select executable application code based on the caller's working directory.
Install the application into a dedicated, user-controlled directory such as:
text
~/.local/share/nex-changelog/
Generate the wrapper with a fixed absolute path to the installed entry point:
bash
#!/usr/bin/env bash
set -euo pipefail
exec python3 "$HOME/.local/share/nex-changelog/nex-changelog.py" "$@"
If setup-time path expansion is needed, safely embed the canonical installation path when creating the wrapper.
Canonicalize the trusted installation path and verify that the target is a regular file rather than an unexpected symbolic link.
Verify that the application file and its parent directories are owned by the expected user and are not writable by untrusted users.
Prefer packaging the application with a standard Python entry point or isolated virtual environment rather than implementing custom executable discovery.
Add a regression test that creates a malicious nex-changelog.py in the working directory, runs the installed command, and confirms that only the trusted installed application is executed.
The code substantially matches the general changelog/release-notes purpose: it can add entries, import from git, create releases, generate client email and Telegram outputs, export changelogs, and track unreleased items. However, there is a meaningful description/behavior mismatch because the declared description promises several specific capabilities not actually demonstrated in this code chunk, especially HTML output and explicit semantic-version management behavior. Conversely, the code includes additional project/database administration, search, and statistics features not mentioned in the description. These are not merely low-level implementation details because they represent user-facing capabilities beyond changelog generation. Therefore the description is broadly related but not fully accurate to the supplied code.
Content
No source excerpt is available for this finding.
Ae1
High
Category
analysis-evasion
Confidence
100% confidence
Finding
Referenced artifact was not completely inspected
Content
Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.
md
- "nex-changelog.py"
Tool Parameter Abuse
High
Category
Tool Misuse
Confidence
95% confidence
Finding
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
Content
Scanner excerpt · setup.sh (reported line 106)May include surrounding context.
sh
# Try to symlink the actual script directly if possible
if [ "$PLATFORM" != "windows" ]; then
# Remove old symlink if it exists
[ -L "$BIN_DIR/nex-changelog-real" ] && rm "$BIN_DIR/nex-changelog-real"
# Create symlink to the actual Python script
ln -sf "$SKILL_DIR/nex-changelog.py" "$BIN_DIR/nex-changelog-real" 2>/dev/null || true
fi
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
Content
Scanner excerpt · setup.sh (reported line 116)May include surrounding context.
sh
"$BIN_DIR/nex-changelog-real" ] && rm "$BIN_DIR/nex-changelog-real"
# Create symlink to the actual Python script
ln -sf "$SKILL_DIR/nex-changelog.py" "$BIN_DIR/nex-changelog-real" 2>/dev/null || true
fi
# Ensure the wrapper is in PATH
if [[ ":$PATH:" != *":$BIN_DIR:"* ]]; then
echo ""
echo "Add $BIN_DIR to your PATH by running:"
if grep -q "bashrc" <<< "$SHELL"; then
echo " echo 'export PATH=\"\$HOME/.local/bin:\$PATH\"' >> ~/.bashrc"
echo " source ~/.bashrc"
else
echo " echo 'export PATH=\"\$HOME/.local/bin:\$PATH\"' >> ~/.zshrc"
echo " source ~/.zshrc"
fi
fi
echo ""
echo "============================================"
echo " Setup Complete!"
echo "============================================"
echo ""
echo "Data directory: $DATA_DIR"
echo "CLI command: nex-changelog"
echo ""
echo "Getting started:"
echo " 1. Add a project:"
echo " nex-changelog project add --name \"My App\" --description \"My application\""
echo "
Missing User Warnings
Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding
The README promotes importing git history and generating client-facing outputs, but it does not clearly warn that commit messages, author metadata, client contact data, and manually entered notes are persisted locally and may be reproduced in exports. In this skill’s context, that omission can lead users to unintentionally store sensitive internal details and leak them into emails, changelogs, or Telegram announcements intended for external audiences.
Content
No source excerpt is available for this finding.
Session Persistence
Medium
Category
Rogue Agent
Confidence
60% confidence
Finding
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Content
Scanner excerpt · README.md (reported line 69)May include surrounding context.
--version 1.3.0
text
### Create a Release
```bash
nex-changelog release \
Undeclared Tool Scope
Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding
The skill instructs the agent to run shell commands and perform persistent file/database writes, but it does not declare any explicit tool scope such as allowed tools or permissions. That makes the capability boundary implicit rather than enforceable, increasing the risk of over-broad execution or accidental use in contexts where shell/file-write access should be denied.
Content
No source excerpt is available for this finding.
Vague Triggers
Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding
The trigger phrases are very broad everyday terms such as 'what changed' and 'new features', which can cause unintended invocation in unrelated conversations. Unintended activation is risky here because the skill can run shell commands, inspect repositories, and modify a persistent local database, so a casual request could produce side effects without the user's clear intent.
Content
No source excerpt is available for this finding.
Session Persistence
Medium
Category
Rogue Agent
Confidence
94% confidence
Finding
The skill persists project and changelog data in a local SQLite database under ~/.nex-changelog across sessions. Session-persistent storage can retain sensitive internal release notes, client names, emails, repository paths, and security-fix details longer than users expect, creating confidentiality and integrity risks if reused, exposed, or modified in later sessions.
Content
Scanner excerpt · SKILL.md (reported line 290)May include surrounding context.
md
## Troubleshooting
- **"Project not found"**: Use `nex-changelog project list` to see available projects, or `nex-changelog project add` to create a new one.
- **"No entries found"**: Use `nex-changelog list` to view all entries, or `nex-changelog add` to create one.
- **"Git import failed"**: Ensure the repository path is correct and the directory contains a `.git` folder.
- **Database errors**: The database is initialized automatically; check that `~/.nex-changelog/` directory exists and is writable.
Intent-Code Divergence
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
The function documentation says it filters to CLIENT audience entries only, but when no entries are marked CLIENT it silently falls back to all entries. In this skill’s context, that can expose internal-only or non-client-safe changelog content in client-facing release emails, causing unintended information disclosure about internal work, refactors, or sensitive security changes.
Content
No source excerpt is available for this finding.
subprocess module call
Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
Content
Scanner excerpt · lib/git_parser.py (reported line 34)May include surrounding context.
The client-facing email generation loads all entries for the specified version with db.list_entries(project_id=project['id'], version=args.version) and passes them directly to format_client_email without filtering by audience. In a tool explicitly designed to separate internal and client/public release notes, this can leak internal-only changes, refactoring details, or sensitive security/remediation notes to external recipients, causing unintended information disclosure.
Content
No source excerpt is available for this finding.
Description-Behavior Mismatch
Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding
The Telegram release message generation has the same issue: it fetches all entries for a release version and sends them to format_telegram without any audience-based filtering. Because Telegram announcements are often broadly distributed and compact summaries may still include sensitive internal items, this creates a direct confidentiality risk and can publicly expose non-client-facing operational details.
Content
No source excerpt is available for this finding.
Sudo/Root Execution
Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
Content
Scanner excerpt · setup.sh (reported line 62)May include surrounding context.
sh
echo "[3/4] Creating data directory..."
mkdir -p "$DATA_DIR"
if [ "$PLATFORM" != "windows" ]; then
chmod 700 "$DATA_DIR"
fi
echo " Data directory: $DATA_DIR"
Missing User Warnings
Low
Category
Not specified by scanner
Confidence
94% confidence
Finding
This code performs a file write via output_file.write_text(output), which can modify or overwrite local files. While the operation is part of an export feature, there is no explicit confirmation, cautionary message, or inline comment/docstring warning that the command will write to disk when --output is used.
Content
No source excerpt is available for this finding.
Missing User Warnings
Low
Category
Not specified by scanner
Confidence
87% confidence
Finding
This shell script creates a data directory under $HOME, creates $HOME/.local/bin, and writes a wrapper executable there. Although the actions are visible in the code, there is no explicit user warning that running setup.sh will modify the user's filesystem and install a command into their PATH-related bin directory before those writes occur.