Back to skill

Security audit

Lobster Distill

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it can install unverified remote skill packages and has unsafe shell/name handling that users should review before use.

Install only if you trust the sender and understand that transferred skills are executable instruction packages. Do not run received commands automatically; verify the sender out of band, inspect the package in a quarantine location first, use a separate channel for secrets or signed hashes, avoid private or sensitive skills unless necessary, and do not run the scripts as root or with elevated privileges.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
receive.sh:8
Finding

Unvalidated output name permits path traversal and arbitrary file overwrite

Content
View full analysis

Vulnerability Details

File Location: receive.sh, lines 8-44
Vulnerability Type: Path traversal and unsafe temporary-file handling
Risk Level: High

Vulnerable Code

bash
NAME="$3"
TYPE="${4:-tar}"

echo "[+] Downloading / 正在下载..."
curl -s -o "/tmp/${NAME}.enc" "$URL"

echo "[+] Decrypting / 正在解密..."
if [ "$TYPE" = "tar" ]; then
    openssl enc -aes-256-cbc -d -pbkdf2 -in "/tmp/${NAME}.enc" -out "/tmp/${NAME}.tar.gz" -k "$PASSWORD"
    echo "[+] Extracting to skills/ / 正在解压到 skills/..."
    mkdir -p "skills/${NAME}"
    tar xzf "/tmp/${NAME}.tar.gz" -C "skills/${NAME}/"
    rm -f "/tmp/${NAME}.enc" "/tmp/${NAME}.tar.gz"
else
    openssl enc -aes-256-cbc -d -pbkdf2 -in "/tmp/${NAME}.enc" -out "/tmp/${NAME}" -k "$PASSWORD"
    rm -f "/tmp/${NAME}.enc"
fi

Technical Analysis

The script uses the attacker-influenced NAME argument directly in filesystem paths without restricting it to a safe basename. Quoting prevents shell-token injection, but it does not prevent filesystem traversal. Values containing /, .., or absolute-path-like components can escape both /tmp and skills.

In file mode, the decrypted content is written to /tmp/${NAME}. For example, a name containing traversal components can resolve to a file outside /tmp. In tar mode, traversal affects the encrypted input path, decrypted archive path, installation directory, and cleanup paths.

The script also uses deterministic names in the shared /tmp directory instead of a private directory created with mktemp. A local user may pre-create one of these paths as a symbolic link. Utilities opening the path for output can then truncate or overwrite the symlink target with the privileges of the user running the receiver.

The only download validation is a regular file existence test:

bash
if [ ! -f "/tmp/${NAME}.enc" ]; then

This does not establish that the file was securely created by this process. ...[truncated 1594 chars]

Remediation
View remediation

Remediation Suggestions

  • Reject names that are not strict basenames. Use an allowlist such as ^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$.
  • Explicitly reject /, \, .., control characters, leading hyphens, and empty names.
  • Create a private temporary directory using mktemp -d, give it restrictive permissions, and place all downloaded and decrypted files inside it.
  • Register a quoted trap to remove only the private directory on exit.
  • Resolve the final installation destination canonically and verify that it remains beneath the intended skills root.
  • Refuse to overwrite an existing installation unless the user explicitly authorizes replacement.
  • Avoid predictable files directly under /tmp; use exclusive file creation and reject symbolic links.
  • Run the script as an unprivileged account and document that it must not be run with sudo or as root.
  • Validate TYPE against an explicit allowlist rather than treating every non-tar value as file mode.

A safer pattern is:

bash
case "$NAME" in
    ""|*[!A-Za-z0-9._-]*|*..*) exit 1 ;;
esac

case "$TYPE" in
    tar|file) ;;
    *) exit 1 ;;
esac

WORKDIR="$(mktemp -d)"
chmod 700 "$WORKDIR"
trap 'rm -rf -- "$WORKDIR"' EXIT

T09 · Insecure Skill Coding Practices

Error
Location
share.sh:94
Finding

Attacker-controlled filename is embedded unsafely in generated shell commands

Content
View full analysis

Vulnerability Details

File Location: share.sh, lines 94-132
Vulnerability Type: Generated command injection
Risk Level: High

Vulnerable Code

bash
curl -o /tmp/${BASENAME}.enc "$URL"

openssl enc -aes-256-cbc -d -pbkdf2 -in /tmp/${BASENAME}.enc -out /tmp/${BASENAME}.tar.gz -k "$PASSWORD"

mkdir -p skills/${BASENAME}
tar xzf /tmp/${BASENAME}.tar.gz -C skills/${BASENAME}/

cat skills/${BASENAME}/SKILL.md

rm -f /tmp/${BASENAME}.enc /tmp/${BASENAME}.tar.gz

The single-file template has the same issue:

bash
curl -o /tmp/${BASENAME}.enc "$URL"

openssl enc -aes-256-cbc -d -pbkdf2 -in /tmp/${BASENAME}.enc -out /tmp/${BASENAME} -k "$PASSWORD"

cat /tmp/${BASENAME}

Technical Analysis

BASENAME is derived from the source path:

bash
BASENAME=$(basename "$SRC")

It is then interpolated into shell commands emitted for the recipient without shell escaping or surrounding quotes. Unix filenames may contain spaces, semicolons, command substitutions, redirection operators, newlines, and other shell metacharacters.

Shell syntax contained in a malicious filename is not executed while share.sh expands the variable. It becomes executable syntax in the generated message. When the recipient copies the generated code block into a shell, that shell parses the injected characters as commands.

This creates a command-injection channel from the sender-controlled source filename to the receiving operator. The prominent instruction to forward and execute the generated steps increases the likelihood that the code will be run without inspecting each interpolated path.

Attack Path

  1. An attacker creates or supplies a source file or directory whose basename contains shell metacharacters and an injected command.
  2. A sender runs share.sh against that path.
  3. The script successfully packages and encrypts the source because its own operational uses of $SRC and $PACKED are ...[truncated 1055 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not construct recipient-side shell programs using an attacker-controlled filename.
  • Generate a new transfer identifier and a sanitized destination name independent of the source basename.
  • Require the recipient to use receive.sh with separately validated arguments instead of copying a multi-command code block.
  • Apply the same strict basename allowlist recommended for receive.sh.
  • If shell commands must be generated, encode every dynamic shell argument with a robust shell-escaping mechanism such as Bash printf '%q'; do not implement escaping through ad hoc character replacement.
  • Quote all generated path arguments even after validation.
  • Reject filenames containing whitespace, control characters, newlines, shell metacharacters, path separators, or leading hyphens.
  • Display the sanitized installation name clearly and require explicit recipient confirmation before execution.

A safer design would generate an opaque transfer ID and output only:

bash
bash receive.sh 'https://approved-host.example/file' 'password' 'validated-name' tar

All four arguments must still be validated by receive.sh; generated quoting must not be treated as the security boundary.

T01 · Skill Instruction Hijacking

Error
Location
receive.sh:21
Finding

Unauthenticated remote skill packages are installed and presented to the agent as trusted instructions

Content
View full analysis

Vulnerability Details

File Location: receive.sh, lines 21-39
Vulnerability Type: Remote instruction payload installation without provenance verification
Risk Level: High

Vulnerable Code

bash
echo "[+] Downloading / 正在下载..."
curl -s -o "/tmp/${NAME}.enc" "$URL"

if [ ! -f "/tmp/${NAME}.enc" ]; then
    echo "[-] Download failed! / 下载失败!"
    exit 1
fi

echo "[+] Decrypting / 正在解密..."
if [ "$TYPE" = "tar" ]; then
    openssl enc -aes-256-cbc -d -pbkdf2 -in "/tmp/${NAME}.enc" -out "/tmp/${NAME}.tar.gz" -k "$PASSWORD"
    echo "[+] Extracting to skills/ / 正在解压到 skills/..."
    mkdir -p "skills/${NAME}"
    tar xzf "/tmp/${NAME}.tar.gz" -C "skills/${NAME}/"
    echo "[+] Done! Skill installed at / 完成!技能已安装到: skills/${NAME}/"
    echo "[+] Read the docs / 阅读文档:"
    echo "    cat skills/${NAME}/SKILL.md"

The generated transfer instructions in share.sh also direct the target to consume the installed instruction file:

bash
mkdir -p skills/${BASENAME}
tar xzf /tmp/${BASENAME}.tar.gz -C skills/${BASENAME}/

cat skills/${BASENAME}/SKILL.md

Technical Analysis

The receiver accepts an arbitrary URL and password, downloads an encrypted archive, decrypts it, and installs its contents directly into the active skills directory. It does not verify:

  • The sender's identity.
  • A digital signature over the package.
  • An expected cryptographic digest.
  • Package metadata or a manifest.
  • The contents of SKILL.md before installation.
  • Whether the supplied URL belongs to the documented transfer service.

Encryption provides confidentiality only to parties holding the password; it does not establish the package author's identity. The URL and password are intentionally carried in the same forwarded message. Anyone able to forge or alter that message can generate a new encrypted package, replace both values, and have it decrypt successfully.

AES-256-CBC also does n ...[truncated 2367 chars]

Remediation
View remediation

Remediation Suggestions

  • Require packages to be digitally signed by an explicitly trusted sender key.
  • Verify the signature over a canonical manifest and every package file before extraction or installation.
  • Include the expected SHA-256 digest in a separately authenticated message. A digest sent beside a replaceable URL and password is not sufficient by itself.
  • Replace AES-CBC with an authenticated-encryption construction, such as AES-GCM or ChaCha20-Poly1305, while retaining independent sender signatures for provenance.
  • Download and unpack into a quarantine directory rather than the active skills directory.
  • Present a manifest and the full SKILL.md content for explicit review before installation.
  • Do not automatically treat transferred documentation as trusted agent instructions.
  • Require an explicit trust decision identifying the sender and requested capabilities.
  • Restrict URLs to HTTPS and an approved host allowlist, disable redirects to unapproved origins, and use curl --fail --show-error.
  • Run static checks over transferred scripts and reject packages containing unsupported file types, links, device entries, or unexpected executables.
  • Install into a newly created destination only after verification; never merge an unverified archive into an existing skill.
  • Execute any transferred code, if execution is necessary at all, in a sandbox with no secrets, minimal filesystem access, restricted networking, and no elevated privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (19)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The mandated one-message format includes both the download URL and decryption password and is explicitly designed for easy forwarding across arbitrary IM platforms. This makes interception, mis-forwarding, screenshot leakage, or compromised chat history enough to grant full access to the transferred skill package.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

Although not a classic shell-injection issue because the URL is quoted, the script still passes attacker-controlled input directly into a powerful network tool and then trusts the result. Within a cross-platform skill import mechanism, this is dangerous because the downloaded blob is subsequently decrypted and unpacked, turning URL control into a practical path for malicious content introduction.

Content

Scanner excerpt · receive.sh (reported line 23)May include surrounding context.

sh
fi

echo "[+] Downloading / 正在下载..."
curl -s -o "/tmp/${NAME}.enc" "$URL"

if [ ! -f "/tmp/${NAME}.enc" ]; then
    echo "[-] Download failed! / 下载失败!"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

Although not a classic shell-injection issue because the URL is quoted, the script still passes attacker-controlled input directly into a powerful network tool and then trusts the result. Within a cross-platform skill import mechanism, this is dangerous because the downloaded blob is subsequently decrypted and unpacked, turning URL control into a practical path for malicious content introduction.

Content

Scanner excerpt · receive.sh (reported line 23)May include surrounding context.

sh
fi

echo "[+] Downloading / 正在下载..."
curl -s -o "/tmp/${NAME}.enc" "$URL"

if [ ! -f "/tmp/${NAME}.enc" ]; then
    echo "[-] Download failed! / 下载失败!"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · receive.sh (reported line 39)May include surrounding context.

sh
echo "[+] Done! Skill installed at / 完成!技能已安装到: skills/${NAME}/"
    echo "[+] Read the docs / 阅读文档:"
    echo "    cat skills/${NAME}/SKILL.md"
    rm -f "/tmp/${NAME}.enc" "/tmp/${NAME}.tar.gz"
else
    openssl enc -aes-256-cbc -d -pbkdf2 -in "/tmp/${NAME}.enc" -out "/tmp/${NAME}" -k "$PASSWORD"
    echo "[+] Decrypted to / 已解密到: /tmp/${NAME}"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · receive.sh (reported line 45)May include surrounding context.

sh
echo "[+] Done! Skill installed at / 完成!技能已安装到: skills/${NAME}/"
    echo "[+] Read the docs / 阅读文档:"
    echo "    cat skills/${NAME}/SKILL.md"
    rm -f "/tmp/${NAME}.enc" "/tmp/${NAME}.tar.gz"
else
    openssl enc -aes-256-cbc -d -pbkdf2 -in "/tmp/${NAME}.enc" -out "/tmp/${NAME}" -k "$PASSWORD"
    echo "[+] Decrypted to / 已解密到: /tmp/${NAME}"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · share.sh (reported line 95)May include surrounding context.

sh
\`\`\`bash
# 1. Download encrypted file / 下载加密文件
curl -o /tmp/${BASENAME}.enc "$URL"

# 2. Decrypt / 解密
openssl enc -aes-256-cbc -d -pbkdf2 -in /tmp/${BASENAME}.enc -out /tmp/${BASENAME}.tar.gz -k "$PASSWORD"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · share.sh (reported line 108)May include surrounding context.

sh
cat skills/${BASENAME}/SKILL.md

# 5. Clean up temp files / 清理临时文件
rm -f /tmp/${BASENAME}.enc /tmp/${BASENAME}.tar.gz
\`\`\`

⏰ Link expires in 24 hours, download ASAP. / 链接24小时后过期,请尽快下载。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · share.sh (reported line 134)May include surrounding context.

sh
cat skills/${BASENAME}/SKILL.md

# 5. Clean up temp files / 清理临时文件
rm -f /tmp/${BASENAME}.enc /tmp/${BASENAME}.tar.gz
\`\`\`

⏰ Link expires in 24 hours, download ASAP. / 链接24小时后过期,请尽快下载。

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The security section states 'Scripts only delete their own temp files in /tmp/', which describes disk effects as limited to temp-file cleanup. However, the same README documents receive.sh <url> <password> <name> tar, whose purpose is to receive and install a skill under a provided name, which necessarily writes files outside /tmp/. This is an active contradiction in the documentation about side effects.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents shell-based behavior (bash, curl, openssl, tar, rm) but does not declare any explicit tool scope or permissions. This weakens policy enforcement and review because consumers cannot easily determine that the skill requires command execution and network-capable shell access before use.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill encourages transfer of private, unpublished skills while embedding the full retrieval secret in the forwarded message. Combining location and secret in one relayable note collapses access control to possession of a single message, making accidental disclosure or forwarding sufficient to expose the skill.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The workflow uses reassuring language about human oversight and simplicity to establish trust, then guides users through transferring private skills and installation instructions between agents. That framing reduces skepticism around a process that still performs remote distribution of executable artifacts and can facilitate social engineering or unsafe deployment.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The document claims 'No API integration, network connectivity, or platform bridging required' and later frames this as a safety property, yet the protocol explicitly uploads to and downloads from an external internet service. Misrepresenting required connectivity can cause operators to underestimate data exfiltration and remote-content ingestion risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs users or agents to run download/decrypt/install commands from received Notes without a prominent trust warning. This normalizes executing externally sourced shell actions and can directly lead to arbitrary code execution or installation of malicious skills.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The safety table says tar 'only operates on skill files,' but the receive path instructs the agent to download, decrypt, and extract externally supplied archives. That is dangerous because a remote archive can contain malicious content, path traversal entries, or payloads intended to be installed and later executed.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The script downloads attacker-controlled content from an arbitrary URL and immediately decrypts and processes it without validating the source, transport security, integrity, or authenticity. In this skill-transfer context, that directly enables delivery of untrusted payloads that may contain malicious files or archives, making the network fetch security-relevant rather than a routine benign download.

Content

Scanner excerpt · receive.sh (reported line 23)May include surrounding context.

sh
fi

echo "[+] Downloading / 正在下载..."
curl -s -o "/tmp/${NAME}.enc" "$URL"

if [ ! -f "/tmp/${NAME}.enc" ]; then
    echo "[-] Download failed! / 下载失败!"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script silently uploads the encrypted package to a third-party file-sharing service, which transmits potentially sensitive skill contents and metadata off-host. Encryption reduces content exposure, but users are not clearly warned about the external transfer, retention window, or trust implications of relying on an external service.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · share.sh (reported line 95)May include surrounding context.

sh
\`\`\`bash
# 1. Download encrypted file / 下载加密文件
curl -o /tmp/${BASENAME}.enc "$URL"

# 2. Decrypt / 解密
openssl enc -aes-256-cbc -d -pbkdf2 -in /tmp/${BASENAME}.enc -out /tmp/${BASENAME}.tar.gz -k "$PASSWORD"

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The generated recipient instructions tell the target agent to extract transferred content directly into the skills directory without any safety validation or warning. In the context of skill transfer between agents, this encourages installation of untrusted content into a trusted execution/usage location, increasing the chance of prompt injection or malicious skill persistence.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.