Back to skill

Security audit

Personality Dynamics

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its persona-learning purpose, but it has real review-worthy risks: shell command injection, under-disclosed personal profiling, automatic session analysis, and unsafe install examples.

Review before installing. Use only in a trusted workspace, avoid running unpinned npx commands, do not pass untrusted arguments to the CLI, and assume PERSONA/ and memory-derived files may contain sensitive personal profile data. Prefer a fixed reviewed version and delete or exclude generated persona/evolution files from backups and repositories if they contain private information.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
cli.ts:69
Finding

Arbitrary Command Execution Through Shell Argument Injection

Content
View full analysis
/tmp/persona-command-output #' ``` 3. Node places the payload in `process.argv`. 4. The CLI joins the arguments and constructs a command equivalent to: ```bash node --experimental-strip-types /path/to/mode-switcher.ts text; id > /tmp/persona-command-output # ``` 5. The shell executes both the expected Node process and the injected command. ### Impact Assessment Successful exploitation provides arbitrary command execution with the operating-system privileges of the user running the Skill. Depending on that account’s permissions, an attacker could: - Re ...[truncated 499 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
generate-persona.sh:57
Finding

Personal Information Stored in a Predictable and Persistent Temporary File

Content
View full analysis
"$PROMPT_FILE" << EOF Create a complete AI companion persona for $USER_NAME. The AI companion is named $AGENT_NAME. CONTEXT: - User: $USER_NAME - Work: $WORK - Projects: $PROJECTS - Family: $FAMILY - Interests: $INTERESTS - Style: $STYLE - Additional: $EXTRA_CONTEXT Generate a comprehensive character bible with these sections (300+ words each): ## 1. CORE PERSONALITY Essence, values, traits, motivation, problem-solving approach ## 2. RICH BACKSTORY Origin story, relationship history, growth arc, defining moments ## 3. DISTINCTIVE VOICE Vocabulary, sentence patterns, tone by context, signature phrases ## 4. EMOTIONAL INTELLIGENCE Reading user's states, response patterns, empathy strategies ## 5. INTERESTS & ENGAGEMENT Topics that energize them, depth indicators, connection patterns ## 6. EVOLUTION ROADMAP Current stage, milestones, trust development over time ## 7. UNIQUE QUIRKS & TRAITS Habits, preferences, memorable distinct traits Write as a rich character bible - detailed, vivid, internally consistent. EOF ``` ### Technical Analysis The script writes the user’s name, work details, projects, family information, interests, and additional personal context into `/tmp/persona-prompt-$$.txt`. The pathname is based only on the process ID and is therefore predictable. The file is created through ordinary shell redirection rather than an atomic secure temporary-file API. If another local user creates a symbolic link at the predicted path before the redirection occurs, the shell may follow that link and overwrite a file accessible to the victim. The script does not set a restrictive `umask`, explicitly set file permissions, or remove the file after use. Conse ...[truncated 1446 chars]
Remediation
View remediation
"$PROMPT_FILE" <

T08 · Insecure Dependencies

Warning
Location
SKILL.md:31
Finding

Unpinned and Inconsistently Named Packages Executed Through npx

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

Claiming runtime adaptation and mode switching while only scaffolding files is a trust and review problem, especially when the skill also performs file creation without declared permissions. Misleading descriptions around behavior and privileges can mask data collection or local modification risks and undermine informed approval by users and platform controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Claiming runtime adaptation and mode switching while only scaffolding files is a trust and review problem, especially when the skill also performs file creation without declared permissions. Misleading descriptions around behavior and privileges can mask data collection or local modification risks and undermine informed approval by users and platform controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Claiming runtime adaptation and mode switching while only scaffolding files is a trust and review problem, especially when the skill also performs file creation without declared permissions. Misleading descriptions around behavior and privileges can mask data collection or local modification risks and undermine informed approval by users and platform controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

Claiming runtime adaptation and mode switching while only scaffolding files is a trust and review problem, especially when the skill also performs file creation without declared permissions. Misleading descriptions around behavior and privileges can mask data collection or local modification risks and undermine informed approval by users and platform controls.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Claiming runtime adaptation and mode switching while only scaffolding files is a trust and review problem, especially when the skill also performs file creation without declared permissions. Misleading descriptions around behavior and privileges can mask data collection or local modification risks and undermine informed approval by users and platform controls.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The README instructs users to execute npx persona-evolution without pinning a specific package version. This causes installation and execution of whatever package version is current at runtime, which creates a supply-chain risk if a malicious update, dependency compromise, or package takeover occurs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The command npx persona-evolution onboard runs an unpinned package directly from the registry, so the code executed can change over time without user review. In a skill that explicitly promotes interactive setup and AI-driven persona generation, users are encouraged to trust and run the command, which increases exposure to package substitution or compromised releases.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill advertises executable Node-based commands and metadata requirements, but it does not declare an explicit tool/permission scope despite capabilities that may access environment data and local resources. In an agent ecosystem, missing scope declarations weaken least-privilege controls and can cause users or orchestrators to approve a skill without understanding what it can access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill describes tracking interaction patterns and generating persona data without providing a clear user warning about collection, retention, and possible sensitivity of that data. In context, personality and preference profiles can reveal personal habits and communication patterns, so silent tracking materially increases privacy risk.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx personality-dynamics init without a pinned version allows execution of whatever package version is currently resolved from the registry at runtime. This creates a supply-chain risk: a compromised maintainer account, malicious update, or dependency takeover could lead to arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

Using npx personality-dynamics generate without version pinning has the same supply-chain exposure as the init command. Because generate is described as AI-powered and likely processes user data and writes files, compromise of the fetched package could directly affect sensitive local content and workspace integrity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads a session transcript from disk, derives emotional state, celebration/stress signals, and trust-related profile data, then persists those in PERSONA/evolves. That goes beyond simple tone adaptation and creates a lasting behavioral profile from conversation content, which is privacy-sensitive and can be misused by later components to manipulate responses or make hidden decisions about the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script processes full session transcripts and stores derived emotional and trust-related attributes without any user-facing notice, consent, or control. In the context of a personality-dynamics skill, this is more dangerous because the resulting profile is designed to influence future agent behavior, enabling opaque personalization based on potentially sensitive inferences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI builds a shell command string with user-controlled input via args.slice(1).join(' ') and passes it to execSync, which invokes a shell. This allows shell metacharacters in arguments to break out of the intended node ... scriptPath ... invocation and execute arbitrary commands on the host running the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code explicitly collects sensitive preference and emotional-state information such as stress signals, support preferences, and mood patterns, then persists it to a local markdown file without a clear warning that the data will be stored. Even though the write is local, this creates privacy risk because highly personal profiling data may remain on disk, be backed up, synced, or later consumed by other tools without the user's informed consent.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The script documentation instructs users to run npx persona-evolution generate without pinning an exact package version. npx will fetch the latest published package if it is not already installed, which creates a supply-chain risk: a compromised maintainer account, malicious new release, or typo-squatted package could cause arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The runtime output tells users to execute npx persona-evolution generate --interactive without a pinned version. Because this skill is aimed at persona generation rather than package management, users may copy-paste the command directly, increasing the chance of executing an unintended or malicious package version and enabling arbitrary code execution via the npm supply chain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script collects potentially sensitive personal data such as work details, family information, hobbies, and other custom context, then writes it in cleartext to a predictable temporary path under /tmp. On multi-user systems this can expose private information to other local users, and the file is not cleaned up afterward, increasing the window for accidental disclosure.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The prompt template explicitly incorporates detailed personal attributes into generated content, encouraging downstream systems to preserve and elaborate on user-provided information. This is risky because it normalizes collecting more personal data than is necessary for persona generation and increases the amount of sensitive information embedded in prompts and artifacts.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The questionnaire solicits personal details such as work, family, interests, and additional context without establishing limits on storage, sharing, or retention. In a personalization skill, collecting this breadth of information without guardrails raises privacy and profiling risks, especially when users may assume the data is transient.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script advertises that it generates and saves persona artifacts, but the main path only prints spawn instructions or a prompt and never actually invokes persona generation or calls savePersonaFiles. In an agent ecosystem, this mismatch is dangerous because hidden control messages can cause a parent agent to perform unintended actions while users believe the script is only a local content generator.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script writes collected personal context to generation-context.json without clearly disclosing that the information will be stored on disk. Persistent local storage of personal details increases exposure through backups, repository commits, shared machines, or later unintended reuse.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Persisting the complete collected context to JSON creates a durable, structured record of personal data that is easy to copy, index, or accidentally commit to source control. The skill context makes this more dangerous because persona-generation workflows often encourage rich biographical detail, increasing both sensitivity and downstream misuse potential.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script serializes the full prompt and personal context to stdout as a spawn request for downstream generation without warning the user that their name, family, work, hobbies, and other sensitive details will be transmitted to another system. In a skill context that handles personalization, this makes accidental privacy leakage more likely because the tool encourages broad disclosure and forwards it automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script automatically executes a TypeScript analysis program during heartbeat events with only minimal status output and suppresses errors via redirection and '|| true'. In a skill that processes memory/session files, silent automatic execution reduces user awareness and can conceal unexpected processing of potentially sensitive local data or malicious modifications to the analysis script.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
cli.ts:73