T09 · Insecure Skill Coding Practices
- Location
examples/file-manager-skill/index.ts:38- Finding
Base-directory containment bypass permits unauthorized filesystem access
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent cinematic script-writing skill with expected memory, Google Drive, and local export behavior, but it has packaging and dependency hygiene issues users should review.
Install only if you are comfortable with a Node/npm skill that can store story project state, call Google OAuth/Drive APIs when you connect Drive, and write exported project files to local storage when configured. Prefer running it in a normal workspace, review Google Drive permissions during OAuth, and update development dependencies before using this repository for development or CI.
examples/file-manager-skill/index.ts:38Base-directory containment bypass permits unauthorized filesystem access
handlebars 4.7.8 has multiple serious issues including prototype pollution and possible code or script injection through template compilation pathways. Even though this is a dev dependency via ts-jest rather than an obvious runtime dependency, the severity is higher because template engines become dangerous quickly if any untrusted template content reaches build or test tooling.
This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.
This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.
This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.
This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.
This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.
This mismatch appears to overstate the skill's capabilities rather than hide a more dangerous implementation: if the package is mainly a cinematography reference API and lacks claimed script writing, voice, anachronism, and Drive features, it is still a trust and integrity problem. Users may grant installation or permissions expecting one behavior while receiving another, which undermines informed consent and safe review.
The implemented skill is a general-purpose local file manager, which materially diverges from the declared cinematic script-writing purpose. This mismatch is dangerous because it can conceal broad filesystem read/write/delete capabilities behind an innocuous manifest, increasing the chance that users or reviewers grant the skill access they would not approve if its true behavior were disclosed.
The implementation is a persistent todo-list manager, while the declared skill is a cinematic script writer. This capability mismatch is dangerous because it can mislead reviewers and users about what the skill actually does, potentially enabling unauthorized data storage and state manipulation under an unrelated trust boundary. In the context of an agent skill ecosystem, deceptive or mislabeled functionality materially increases supply-chain and user-consent risk.
The file’s behavior is materially inconsistent with the declared cinematic-script-writer skill: it implements a weather client, performs external API calls, and stores weather data. In a skill ecosystem, capability/manifest mismatch is dangerous because it defeats user and reviewer expectations and can conceal unauthorized data access or network activity under an unrelated label.
brace-expansion 1.1.12 has multiple denial-of-service issues involving pathological brace patterns that can trigger extreme CPU or memory consumption. Although this instance is only transitively present in dev tooling, it remains a true vulnerability because tools handling attacker-controlled glob-like input could be stalled or crashed.
minimatch 3.1.2 is associated with ReDoS conditions from crafted glob patterns that cause catastrophic backtracking or combinatorial matching behavior. In this skill, the package is part of lint/test/build dependencies rather than production logic, which lowers exposure but does not eliminate the underlying denial-of-service risk in CI or local tooling.
js-yaml 3.14.2 has known CPU exhaustion issues when parsing specially crafted YAML merge structures. Here it is a transitive dev dependency, so the primary risk is denial of service in development or CI pipelines that parse untrusted YAML rather than compromise of end users at runtime.
brace-expansion 2.0.2 has the same class of DoS weaknesses as 1.x, allowing crafted expansion expressions to consume excessive CPU or memory. Even as a dev-only transitive dependency, it can still disrupt CI or local execution if exposed to attacker-controlled patterns.
browserslist 4.28.1 is flagged for crash/prototype-write and unbounded memory growth issues under untrusted input conditions. In this repository it is part of development tooling, so impact is mainly denial of service or tooling instability, but prototype mutation risks can make CI/build contexts more fragile if they process attacker-supplied configuration.
flatted 3.3.3 is reported vulnerable to unbounded recursion DoS and prototype pollution during parse(). This is a real issue in the package, though here it is transitively present in development tooling, making the most likely impact build/test disruption or unsafe object mutation if untrusted serialized data is parsed.
js-yaml 4.1.1 retains reported CPU exhaustion issues on crafted YAML structures, making it vulnerable to denial of service when parsing attacker-controlled YAML. In the context of this skill repository, it appears in development tooling, so the risk is more to maintainers and CI systems than to end users of cinematic script generation.
The implemented skill is a generic template with greeting, memory, and calculation functions, but the manifest describes a cinematic script writing tool with Google Drive/script-generation capabilities. This mismatch is dangerous because users and orchestrators may grant trust, permissions, or invoke the skill under false assumptions, increasing the chance of unsafe tool exposure and policy bypass through unintended functionality.
The manifest claims this is a generic template skill rather than the advertised cinematic-script-writer skill, creating a strong identity mismatch between the package metadata and the expected behavior. This can mislead reviewers, users, and automated policy systems, and is especially dangerous because the same manifest also requests sensitive permissions that do not align with the declared template purpose.
The declared tools, such as 'greet' and 'calculate', do not match the cinematic script-writing, character consistency, or cinematography functions described in the skill metadata provided for this review. A mismatch between advertised purpose and exposed tools is a security concern because it obscures actual functionality and can hide unintended or unauthorized behaviors behind an apparently harmless skill.
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
- `createContext()` - Create story world
- `listContexts()` - List all contexts
- `getContext()` - Get specific context
- `deleteContext()` - Delete context
### Story Generation
- `generateStoryIdeas()` - Generate story ideas
Skill manipulates agent memory, state, or stored context. Memory corruption can alter personality, override safety rules, or cause unpredictable behavior.
- `createContext()` - Create story world
- `listContexts()` - List all contexts
- `getContext()` - Get specific context
- `deleteContext()` - Delete context
### Story Generation
- `generateStoryIdeas()` - Generate story ideas
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
era: string,
style: string
) {
return promptBuilder.createCharacterReference(
characterId,
characterName,
visualDescription,
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
era: string,
style: string
) {
return promptBuilder.createCharacterReference(
characterId,
characterName,
visualDescription,
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
era: string,
style: string
) {
return promptBuilder.createCharacterReference(
characterId,
characterName,
visualDescription,
Detected: suspicious.exposed_secret_literal