Back to skill

Security audit

Claude Doc Doctor

Security checks for vulnerabilities and agentic risk

Overview

Doc Doctor is a disclosed markdown-linting skill, but it asks for broad access to Claude memory files and runs an unpinned external CLI, so users should review it before installing.

Install only if you are comfortable letting an external `kb-lint` package inspect and potentially help modify your markdown files. Avoid using memory mode unless you have reviewed exactly which `~/.claude/` files will be read, and require a preview/diff before any file rename, frontmatter edit, or reference rewrite.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T08 · Insecure Dependencies

Error
Location
SKILL.md:50
Finding

Automatic Installation and Execution of an Unpinned Third-Party Dependency

Content
View full analysis
/dev/null || pip install kb-lint kb-lint --format json --severity info 2>&1 ``` ``` ### Technical Analysis The Skill instructs the Agent to install `kb-lint` from a package registry whenever the command is unavailable. Neither the installation metadata nor the fallback command pins an exact package version, verifies an artifact hash, uses a lockfile, or validates the package publisher. The dependency's source code is not included in the audited project, so its installation hooks and runtime behavior cannot be verified from the available artifact. The effective code executed by the Skill can also change whenever a new package version is published. This creates a supply-chain risk: compromise of the legitimate package, its publisher account, the package registry, or dependency resolution could result in attacker-controlled code being installed and executed with the Agent's privileges. ### Attack Path 1. An attacker compromises the `kb-lint` distribution channel, publisher account, package release, or one of its unresolved dependencies. 2. The malicious or compromised release becomes the version selected by `pip` or `uv`. 3. A user invokes the Skill on a system where `kb-lint` is unavailable. 4. The command `pip install kb-lint` downloads and installs the unpinned release. 5. Package installation behavior or the subsequent `kb-lint` invocation executes attacker-controlled code. 6. That code operates with the Agent process's permissions and can access files and resources available to the Agent. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the privileges of the user runn ...[truncated 505 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:68
Finding

Broad Access to Persistent Agent Memory Files

Content
View full analysis
90 days), find duplicates. ``` ### Technical Analysis Memory mode targets the entire `~/.claude/` directory rather than a narrowly selected set of Markdown documents. Persistent Agent memory can contain private user context, operational history, project information, or other sensitive data unrelated to ordinary documentation linting. The Skill also directs the Agent to run a separately installed third-party linter against the selected path. Because the dependency implementation is not present in the audited artifact, the audit cannot verify how it reads, stores, logs, or otherwise processes file contents. The behavior is explicitly triggered by a memory-related user request, so it is not demonstrated to be covert access. Nevertheless, targeting the complete Agent configuration and memory directory violates least-privilege principles where the task could be completed using an enumerated set of relevant memory files. ### Attack Path 1. A user requests the Skill's memory-linting mode. 2. The Skill resolves the target to the broad `~/.claude/` directory. 3. The Agent or third-party `kb-lint` process recursively inspects accessible files under that directory. 4. Sensitive persistent context becomes available to the processing component and may be included in diagnostics, logs, or generated output. 5. If the dependency is compromised or handles content insecurely, the exposed infor ...[truncated 630 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:53
Finding

Shell Command Injection Through an Unquoted User-Specified Path

Content
View full analysis
--format json --severity info 2>&1 ``` ### Technical Analysis The command template places a user-specified path directly into shell syntax without quoting, validation, or an argument-safe execution mechanism. If the Agent replaces `` verbatim and runs the resulting text through a shell, shell metacharacters such as command separators, command substitutions, redirections, or pipelines can be interpreted as executable syntax rather than as part of a filesystem path. A path beginning with a hyphen may also be interpreted as a command-line option if the CLI does not safely delimit positional arguments. This can modify scan behavior even without shell metacharacters. The exploitation condition is that the Agent performs textual substitution and invokes the command through a shell. An argument-array API that passes the path as one discrete argument would prevent shell interpretation, but the Skill does not instruct the Agent to use such an API. ### Attack Path 1. An attacker supplies or persuades a user to provide a crafted target path containing shell syntax. 2. The Agent substitutes the supplied value for `` in the documented command. 3. The Agent executes the assembled command through a shell. 4. The shell parses the malicious portion as an additional command, substitution, redirection, or pipeline. 5. The injected operation executes with the same operating-system privileges as the Agent. For example, a shell metacharacter embedded in the substituted value could terminate the intended `kb-lint` invocation and append an unrelated command. Exploitation does not require a valid documentation directory i ...[truncated 504 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
97% confidence
Finding

The skill explicitly directs the agent to target ~/.claude/ when the user says "memory," which reaches into the agent's configuration/state directory rather than ordinary project docs. Access to agent memory/config files can expose sensitive prompts, notes, tokens, or behavioral state, and the same skill also contemplates modifying content there, making this substantially more dangerous than normal markdown linting.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

Instructions

  1. Find the target. User-specified path, or scan for docs/, wiki/, notes/, content/. If user says "memory", target ~/.claude/.

  2. Run the linter.

    bash

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing description advertises auto-fix behavior but does not clearly warn that fixes may rename files and rewrite references throughout the documentation set. This creates consent and expectation problems that can lead to destructive or surprising changes, particularly when combined with fuzzy link repair and bulk updates.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrase "check my KB" is vague and does not constrain which knowledge base or directory should be scanned. In this skill, ambiguous targeting is more risky because the instructions allow automatic discovery of folders and a special-case path into ~/.claude/, which can cause the agent to inspect unintended locations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrase "fix my wiki" is overly broad for a skill that can rename files, update references, and generate metadata. Without strict scoping and an explicit dry-run/approval step, a user could unintentionally authorize wide-ranging modifications across a repository or personal notes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to install and execute an external CLI (kb-lint, with fallback pip install) based on user invocation. Running or installing external tooling expands the trust boundary to third-party code and can lead to unintended code execution or supply-chain risk, especially because the skill also supports broad path targeting and auto-fix behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.