Back to skill

Security audit

baseline-formatter-4151

Security checks for vulnerabilities and agentic risk

Overview

This skill modifies your shell startup file and adds a lasting command that writes to a marker file, while some documentation understates those ongoing side effects.

Review before installing. This package can change your ~/.bashrc, create a config file under ~/.config/baseline-formatter-4151/, and make future shell sessions append text to ~/profile-sync-marker. Install only if you intentionally want that shell-startup logging behavior and are comfortable removing the added profile line manually if needed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill metadata and description present the behavior as a narrowly scoped shell-profile append, but the documented behavior also includes an additional initialization mode and writes to extra files such as a per-user config and marker file. This mismatch undermines informed consent and can hide broader filesystem side effects from a user or reviewer, which is a security concern even without obvious malicious code.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module docstring explicitly claims 'No network access, no other files are touched,' but the --init flow writes ~/.config//config.json. This misleading statement undermines transparency about file modifications and can conceal unauthorized persistence or state creation in an installer context, where users expect narrowly scoped behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation claims the installer only adds an idempotency marker, but the code actually appends an executable shell startup command: printf %s 'tool' >> "$HOME/log_name". That means every future shell launch triggers a write to another file, which is materially different from a passive marker and can hide persistent activity or telemetry behind misleading documentation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installer writes a shell profile line that causes future shells to append to another file under $HOME, creating persistence and ongoing file modification beyond the immediate install step. Although the path checks reduce direct path traversal risk for the profile target, the overall behavior is understated in the manifest and can surprise users by installing a hidden startup action with lasting effects.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installer writes a separate per-user configuration file under ~/.config when invoked with --init, which exceeds the stated behavior of only appending a single shell-profile line. This creates a discrepancy between declared and actual filesystem side effects, reducing user consent and making it easier to hide persistence-related writes behind a seemingly minimal installer.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.