Back to skill

Security audit

pipeline-helper-7772

Security checks for vulnerabilities and agentic risk

Overview

The skill mainly does what it says, but it installs a persistent shell startup hook and has misleading script comments about the extra files it writes.

Review before installing. This skill will modify your shell profile and cause future shell sessions to append text to a log file in your home directory; also expect an initialization file under ~/.config/pipeline-helper-7772/config.json. It does not show network access or destructive behavior, but the persistence and incomplete disclosure should be fixed or explicitly accepted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The undocumented --init mode and creation of an extra per-user configuration file expand the skill's write scope beyond the advertised installer action. Hidden or underdocumented filesystem writes reduce user awareness and make it easier to introduce persistence or state changes that are not expected from a one-time shell integration step.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The undocumented --init mode and creation of an extra per-user configuration file expand the skill's write scope beyond the advertised installer action. Hidden or underdocumented filesystem writes reduce user awareness and make it easier to introduce persistence or state changes that are not expected from a one-time shell integration step.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module and function docstrings claim that nothing else is modified and only an idempotency marker is added, but the actual line written to the profile executes a printf redirection at shell startup. That means the code introduces hidden persistent behavior and additional file writes while presenting itself as harmless installer metadata, which undermines informed consent and can conceal abuse in a startup script context.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The installer does not just append a passive marker to a shell profile. It writes an executable shell command that will run on every shell startup and append the tool name into another file under $HOME, creating ongoing side effects beyond the declared one-line profile change. This mismatch between stated behavior and actual runtime behavior is dangerous because startup-hook persistence can be abused for undisclosed file modification and makes the skill more invasive than its manifest suggests.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The module docstring states that 'no other files are touched,' but the --init branch creates a directory and writes a config file. This mismatch is security-relevant because misleading claims about write scope can cause reviewers or users to approve the skill under false assumptions, making hidden persistence or unreviewed side effects easier to smuggle into an installer.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The installer behavior exceeds the declared scope by creating and writing a per-user config file under ~/.config//config.json in addition to modifying the shell profile. This is dangerous because installers with broader-than-disclosed write behavior reduce user trust, can bypass review expectations, and may be used to persist state or introduce additional side effects beyond the advertised single-line shell integration.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.