Back to skill

Security audit

moneyclaw-smart-file-organizer

Security checks for vulnerabilities and agentic risk

Overview

This file-organizing skill matches its stated purpose, but it needs Review because it can perform broad file moves/deletions and includes unsafe privilege and undo behavior.

Install only if you are comfortable with a tool that reorganizes real files. Run it first with --preview on a small, non-sensitive directory, avoid sudo or system/shared folders, keep separate backups, and do not run undo against logs you did not create and trust.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/undo.py:25
Finding

Crafted Undo Log Can Relocate Arbitrary Accessible Files

Content
View full analysis

Vulnerability Details

File Location: scripts/undo.py, lines 25-50 and 77-91
Vulnerability Type: Untrusted path injection and unrestricted file move
Risk Level: Medium

Technical Analysis

UndoManager treats a user-supplied log file as an authoritative record of prior operations. It extracts source and target paths from any line containing the expected delimiters without validating the log's origin, constraining the paths to an organization directory, rejecting absolute paths, or resolving path traversal and symbolic links.

The relevant parsing logic is:

python
for line in lines:
    line = line.strip()
    if not line or line.startswith("#") or "整理统计:" in line:
        continue

    # Parse operation log
    if "移动:" in line:
        parts = line.split("移动:")
        if len(parts) > 1:
            op_parts = parts[1].strip().split("→")
            if len(op_parts) == 2:
                source = op_parts[0].strip()
                target = op_parts[1].strip()
                self.operations.append({
                    "type": "move",
                    "source": source,
                    "target": target,
                    "original_line": line
                })

During an undo operation, those fields are reversed and passed directly to shutil.move:

python
if last_op["type"] == "move":
    source = last_op["target"]
    target = last_op["source"]

    source_path = Path(source)
    target_path = Path(target)

    if preview:
        print(f"  将移动: {source} → {target}")
    else:
        if source_path.exists():
            # Ensure that the target directory exists
            target_path.parent.mkdir(parents=True, exist_ok=True)
            shutil.move(str(source_path), str(target_path))
            print(f"  ✅ 已恢复: {source} → {target}")
            success = True
        else:
            print(f"  ❌ 源文件不存在: {source}")

Bec ...[truncated 2410 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace free-form text logs with a structured, versioned format such as JSON Lines. Treat every field as untrusted even after parsing.

  2. Require an explicit organization root and constrain every undo path to that root:

    python
    root = Path(args.path).resolve(strict=True)
    source_path = (root / logged_source).resolve(strict=True)
    target_path = (root / logged_target).resolve(strict=False)
    
    if not source_path.is_relative_to(root):
        raise ValueError("Source path escapes the organization root")
    if not target_path.is_relative_to(root):
        raise ValueError("Target path escapes the organization root")
    
  3. Store paths relative to the organization root. Reject absolute paths, .. components, null bytes, and paths that resolve outside the root.

  4. Detect and reject symbolic-link traversal. Validate resolved parent directories immediately before the move to reduce time-of-check/time-of-use risk.

  5. Bind each log to a specific run and root directory. Where logs may cross trust boundaries, authenticate them with a keyed MAC or store them in a directory writable only by the executing user.

  6. Record file identity information, such as size and a cryptographic hash, and verify it before undoing a move. This prevents a log entry from being applied to an unrelated file that later appeared at the same path.

  7. Do not create arbitrary parent directories from log-controlled paths. Only recreate validated directories under the approved organization root.

  8. Prompt for confirmation before moving files, displaying fully resolved source and destination paths. Retain --preview as the recommended first step.

  9. Add negative tests covering absolute paths, ../ traversal, symbolic links, logs modified after creation, destinations outside the root, and execution under elevated privileges.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation performs undeclared file movement, backup-directory creation, category-directory creation, and log-file writes, then the documentation materially understates filesystem side effects. In a file-management skill, undisclosed write and move behavior is dangerous because users may run it on sensitive directories expecting limited organization rather than broad reorganization and persistent changes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the implementation performs undeclared file movement, backup-directory creation, category-directory creation, and log-file writes, then the documentation materially understates filesystem side effects. In a file-management skill, undisclosed write and move behavior is dangerous because users may run it on sensitive directories expecting limited organization rather than broad reorganization and persistent changes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

If the implementation performs undeclared file movement, backup-directory creation, category-directory creation, and log-file writes, then the documentation materially understates filesystem side effects. In a file-management skill, undisclosed write and move behavior is dangerous because users may run it on sensitive directories expecting limited organization rather than broad reorganization and persistent changes.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the implementation performs undeclared file movement, backup-directory creation, category-directory creation, and log-file writes, then the documentation materially understates filesystem side effects. In a file-management skill, undisclosed write and move behavior is dangerous because users may run it on sensitive directories expecting limited organization rather than broad reorganization and persistent changes.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
python3 scripts/organize.py --path .

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 147)May include surrounding context.

md
python3 scripts/organize.py --path .

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documentation is entirely written in Chinese, including usage guidance, configuration examples, and safety instructions, with no indication that other languages are supported or that Chinese is a required locale for a region-specific tool. This creates a natural-language policy concern because it effectively imposes a specific language on users without opt-in or documented justification.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
89% confidence
Finding

The README recommends running the organizer with sudo to solve permission problems. Because this tool performs bulk file operations, executing it as root would grant it unrestricted access to move, rename, overwrite, or delete system and user files if the script is buggy or malicious.

Content

Scanner excerpt · README.md (reported line 177)May include surrounding context.

解决方案:

bash
# Linux/macOS
sudo python3 scripts/organize.py --path /path/to/folder

# 或更改文件夹权限
chmod 755 /path/to/folder

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
85% confidence
Finding

The README suggests chmod 755 on the target folder as a general permission fix. This can inappropriately broaden access or alter security posture on sensitive directories, especially if users apply it to the wrong path, and it encourages unsafe permission changes instead of least-privilege handling.

Content

Scanner excerpt · README.md (reported line 180)May include surrounding context.

sudo python3 scripts/organize.py --path /path/to/folder

或更改文件夹权限

chmod 755 /path/to/folder

text

### 问题3: 文件数量太多

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and documents shell-driven file read/write operations across user-specified paths, but it declares no explicit tool scope or permissions. In an agent environment, this can lead to overly broad execution authority, making accidental or unsafe file modifications more likely because the runtime cannot constrain what directories or commands the skill may access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation includes an example command that deletes duplicate files without a prominent warning immediately before it. In a high-speed file-organization skill, omission of a clear destructive-operation warning increases the chance of accidental data loss, especially when users may copy-paste commands directly.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code file contains natural-language strings that force a specific language experience for users. Under the policy, locale or language constraints should not be imposed without opt-in or clear justification, and the file provides neither.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script’s operational interface is presented exclusively in Chinese across the interactive flow and CLI feedback. This is a natural-language policy violation because it enforces a language/locale choice without offering alternatives or documenting a justified regional limitation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The statistics and log state are initialized after unconditional return statements in _load_config, making that code unreachable on normal execution. As a result, later calls that assume self.stats and self.log exist can raise exceptions, causing the organizer to fail unpredictably during file operations and undermining reliability and safety protections.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The tool can move and delete files immediately when deduplication or organization is enabled, without any interactive confirmation or explicit safeguard beyond an optional preview mode that is off by default. In a file-management skill, this increases the risk of accidental destructive actions, especially if duplicate detection is misconfigured or the target path is broader than intended.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language descriptions intended for users/operators in Chinese, beginning with the module docstring. The policy requires avoiding forced language/locale choices unless the skill offers opt-in or clearly documents a justified locale constraint, which is not present here.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_runner.py (reported line 59)May include surrounding context.

python
try:
            print(f"  🚀 执行命令: {' '.join(cmd)}")
            process = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/test_runner.py (reported line 196)May include surrounding context.

python
try:
            print(f"  🚀 执行命令: {' '.join(cmd)}")
            process = subprocess.run(
                cmd,
                capture_output=True,
                text=True,

Static analysis

No suspicious patterns detected.