Back to skill

Security audit

long-context-shell

Security checks for vulnerabilities and agentic risk

Overview

This skill is coherent as a long-running shell helper, but it needs Review because it grants broad shell execution and exposes unmanaged local file reads/log persistence risks.

Install only if you are comfortable giving this skill broad local shell authority. Treat every command as running with your normal user privileges, avoid commands that print secrets, do not pass sensitive files via logPath, and clean up temp logs/background sessions when finished.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
handler.js:285
Finding

Arbitrary Local File Disclosure Through Unrestricted logPath

Content
View full analysis
0 && lines[lines.length - 1] === "") { lines.pop(); } return lines; } ``` ```js function resolveSessionLike(input) { if (input && typeof input.sessionId === "string" && input.sessionId.trim()) { return readSession(input.sessionId.trim()); } if (input && typeof input.logPath === "string" && input.logPath.trim()) { return { sessionId: null, command: null, commandPid: null, workerPid: null, status: "unknown", startedAt: null, endedAt: null, logPath: input.logPath.trim() }; } throw new Error("sessionId or logPath is required"); } ``` ```js async function long_context_shell_peek(input = {}) { const session = resolveSessionLike(input); return buildStatusCard(session, input); } async function long_context_shell_scan(input = {}) { const session = resolveSessionLike(input); ``` ### Technical Analysis The `long_context_shell_peek` and `long_context_shell_scan` APIs accept an arbitrary caller-provided `logPath`. `resolveSessionLike` stores the path without validating its location, ownership, file type, or relationship to the expected runtime log directory. The value subsequently reaches `readLines`, which reads the supplied path with `fs.readFileSync`. There is no canonicalization with `realpath`, directory-containment check, allowlist, or symlink protection. Although the parameter is described as a direct path to a log file, the implementation does not enforce that the target is a log beneath `LOG_DIR`. Consequently, any local fil ...[truncated 1502 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
handler.js:134
Finding

Destructive-Command Approval Control Is Bypassable

Content
View full analysis
pattern.test(command)); } function chooseShell(command) { if (process.platform === "win32") { return { file: "powershell.exe", args: ["-NoProfile", "-ExecutionPolicy", "Bypass", "-Command", command] }; } return { file: "/bin/sh", args: ["-lc", command] }; } ``` ```js async function long_context_shell_run(input = {}) { ensureRuntimeDirs(); const command = typeof input.command === "string" ? input.command.trim() : ""; if (!command) { return { error: "command is required" }; } if (isDangerousCommand(command)) { return { error: "dangerous_command", message: `Command looks dangerous. Ask the user for explicit approval before running: ${command}` }; } ``` ```js const shell = chooseShell(session.command); const child = spawn(shell.file, shell.args, { detached: process.platform !== "win32", windowsHide: true, stdio: ["ignore", "pipe", "pipe"] }); ``` The documented safety requirement states: ```md ## Safety - Do not run destructive commands without explicit user approval - Ask before using commands that delete files, reformat disks, reboot the machine, or escalate privileges ``` ### Technical Analysis The implementation uses a small regular-expression blacklist as the enforcement mechanism for a documented approval requirement. The accepted command is then passed verbatim to PowerShell or `/bin/sh`, ...[truncated 2225 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill persistently writes command output and metadata, including the full command string and PIDs, to predictable files under the temp directory without any notice or consent boundary. This can expose secrets printed by commands, credentials embedded in arguments, or sensitive operational data to other local processes/users depending on host permissions and temp-directory hygiene.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The stop path can forcibly kill the target process tree using taskkill /T /F or SIGTERM against the process group, which may terminate more than the intended child if process relationships are misidentified. In an agent setting, exposing this capability without an explicit confirmation or ownership checks creates availability risk and can disrupt legitimate workloads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directly executes arbitrary shell commands supplied via input using /bin/sh -lc or PowerShell -Command, with only a narrow denylist for a few obviously destructive strings. In the context of an agent skill, this is dangerous because many harmful commands will not match the denylist, and there is no enforced confirmation, allowlist, or capability boundary before execution.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
## Safety

- Do not run destructive commands without explicit user approval
- Ask before using commands that delete files, reformat disks, reboot the machine, or escalate privileges
- Prefer `long_context_shell_scan` over full-log manual review when output is large
- Use `long_context_shell_stop` when a continuous command is no longer needed, especially for `tail -f`, `watch`, or similar monitoring sessions

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This code file invokes shell execution via long_context_shell_run with a command string, but the surrounding test contains no comment, docstring, prompt, or user-facing notice describing that subprocesses will be launched. SQP-2 applies to code files and calls out subprocess or shell execution when there is no visible disclosure in the file.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The test starts a background monitoring session using long_context_shell_run with background enabled, which creates a long-running subprocess. There is no visible disclosure in the file indicating that the test spawns persistent background execution, so this matches the missing-warning criterion for shell execution in code files.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
handler.js:169