Back to skill

Security audit

Student Orientation

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for creating PersonWise student-orientation courses, but its update flow asks agents to run opaque commands returned by the CLI/service after approval.

Install only if you trust PersonWise and are comfortable with the agent using browser OAuth, uploading selected course materials, consuming existing course credits, and potentially publishing links when requested. Review any printed update command carefully before approving it, because the skill currently tells the agent to run that command exactly as returned.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:110
Finding

Remote-Controlled Update Command Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 110-127
Vulnerability Type: Execution of an insufficiently validated command supplied by a remote service
Risk Level: High

Vulnerable Code

markdown
Every successful CLI response may also carry a top-level `updates` block. Handle it deterministically:

- If `updates.cli.status` or `updates.skill.status` is `update_available` or `below_minimum`,
  tell the user once which component is outdated (installed versus latest) and quote the exact
  `action` command. The task cannot continue until that update is installed. Ask for approval;
  with approval, run exactly that command (it already carries the required `--approve-upgrade`
  argument). If the user declines, stop and do not run business commands with the outdated
  component, and do not ask again in this session unless the user changes that decision.
- If a command fails with `CLI_VERSION_BELOW_MINIMUM` or `SKILL_VERSION_BELOW_MINIMUM`, the task
  cannot continue until the update is installed. Explain this, ask for approval, run exactly the
  printed update command, then retry the failed step once.
- When both are outdated, update the CLI first, then the Skill.

When the printed `action` refreshes this installed Skill, replace `<skill-directory>` with the
directory of this installed Skill (the directory containing this Skill's SKILL.md). Never run
`doctor` or a generic capability preflight to check freshness; the `update check` command above is
the freshness check. Never ask more than once per component per session, and never substitute
another command, flag, origin, or download path for the printed `action`.

Technical Analysis

The Skill directs the agent to execute the exact command returned through the CLI's action field. The command is treated as an opaque executable instruction rather than structured update metadata from which the agent constructs a locally constrain ...[truncated 2025 chars]

Remediation
View remediation

Remediation Suggestions

Replace opaque command execution with a structured, locally enforced update mechanism:

  1. Require the service to return structured metadata such as component, version, artifact identifier, digest, signature, and approved origin—not a shell command.
  2. Construct the update command locally using a fixed executable and an allowlisted set of subcommands and flags.
  3. Reject shell metacharacters, redirections, command substitutions, pipelines, environment assignments, and unexpected arguments.
  4. Restrict downloads to explicit HTTPS origins declared by the signed service descriptor.
  5. Independently verify the update manifest and artifact using the bundled PersonWise public key and pinned cryptographic digests.
  6. Enforce canonical, expected installation destinations and reject path traversal, symbolic-link targets, and arbitrary destination overrides.
  7. Display the validated component, version, origin, digest, and destination when requesting approval.
  8. Prefer invoking the bundled, reviewed bootstrap scripts with fixed approval flags instead of executing a command supplied by a remote response.
  9. Fail closed if the update response contains unknown fields, an unsupported component, an unapproved origin, or a command string.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a clear description/behavior mismatch. While the description mentions that the skill may install or update the PersonWise CLI with explicit approval, that is presented as a secondary/conditional capability in service of a student-orientation skill. The actual code chunk only performs CLI bootstrap/install logic. It enforces approval flags, selects platform-specific artifacts, downloads from releases.personwise.ai, verifies sizes and SHA-256 hashes, and installs/upgrades/rolls back the executable in ~/.local/bin. There is no code related to student orientation, course generation, grounding to supplied materials, digital-human interaction, voice questions, or browser OAuth. The undeclared rollback operation further increases the mismatch. Bash permission is consistent with the script, but the code’s primary purpose materially differs from the declared skill purpose.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · assets/bootstrap.sh (reported line 165)May include surrounding context.

sh
echo "Release executable checksum mismatch." >&2
  exit 6
fi
chmod 700 "$candidate"
if [ "$(uname -s)" = "Darwin" ] && [ "$native_signature_status" = "verified" ]; then
  codesign --verify --deep --strict --verbose=2 "$candidate"
  spctl --assess --type execute --verbose=2 "$candidate"

Static analysis

No suspicious patterns detected.