Back to skill

Security audit

Nex Ghostwriter

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but its export command can be abused to overwrite user-writable files outside its data folder.

Install only if you are comfortable storing meeting notes, contacts, drafts, and exports locally under ~/.nex-ghostwriter. Avoid exporting to user-supplied or untrusted filenames, and be cautious opening CSV exports in spreadsheet software until path validation and CSV formula neutralization are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
nex-ghostwriter.py:401
Finding

Arbitrary Writable-File Overwrite Through Export Path Traversal

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
lib/storage.py:395
Finding

Spreadsheet Formula Injection in CSV Exports

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises shell execution, environment access, and file-writing behavior via setup and CLI usage, but it does not declare any explicit tool scope such as allowed tools or permissions. That creates a trust-boundary problem: an agent may invoke shell/file-capable operations without a narrowly declared contract, increasing the chance of unintended command execution or filesystem modification if the skill is auto-selected or used with untrusted user input.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger phrases include broad, common language such as 'draft an email', 'recap', 'meeting notes', and 'action items', which can cause the skill to activate in contexts the user did not intend. Because this skill can write files and invoke shell-backed commands, accidental invocation could persist sensitive meeting data locally or cause side effects without clear user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill handles sensitive business data including meeting notes, attendee names, client emails, action items, deadlines, and exports, but the description and usage guidance do not prominently warn users up front that this information is stored locally. In practice, users may disclose confidential or regulated information without realizing it will be persisted on disk and exported into searchable files.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The export command builds the destination path from a user-supplied filename using EXPORT_DIR / output_file and then writes to it without validating that the resolved path stays inside the export directory. An attacker or untrusted local user could supply path traversal values such as ../../somefile or an absolute path to overwrite arbitrary files accessible to the process, which is especially risky because the exported content contains meeting notes, contacts, and email data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The export command writes all meeting data to a file, which likely includes notes, attendee details, client names, and email addresses. While the code prints the destination after writing, there is no prior warning, confirmation, or descriptive comment/docstring alerting the user that potentially sensitive meeting data will be persisted to disk.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · setup.sh (reported line 57)May include surrounding context.

sh
done

if [[ "$(uname)" != MINGW* ]] && [[ "$(uname)" != MSYS* ]] && [[ "$(uname)" != CYGWIN* ]]; then
    chmod 700 "$DATA_DIR" 2>/dev/null || true
fi

echo ""

Static analysis

No suspicious patterns detected.