Back to skill

Security audit

Idea Spark

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent idea-generation helper, but its optional validation step uses an unsafe shell command pattern with generated text, so it should be reviewed before installation.

Install only if you are comfortable with the skill sending your idea domain to web search. Avoid using sensitive private business ideas with it, and do not enable the optional automatic idea-check validation unless the command is changed to a structured, shell-safe tool call or the agent asks before running it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:57
Finding

Shell Command Injection Through Unsafely Interpolated Idea Pitch

Content
View full analysis
\" depth=quick" } ``` ``` ### Technical Analysis The skill instructs the agent to insert the generated `` value directly into a command executed through the `exec` tool. The pitch is derived from user input and information obtained from untrusted websites, including Reddit, Hacker News, and GitHub. Wrapping the value in double quotes does not make it safe for shell execution. Shell constructs such as command substitution—`$(command)` or backticks—are still evaluated inside double-quoted strings. An embedded quotation mark could also terminate the intended argument and introduce additional shell operators or commands. For example, if the resulting pitch contains: ```text Useful project $(touch /tmp/idea-spark-injected) ``` the constructed command becomes: ```bash mcporter call idea-reality.idea_check idea_text="Useful project $(touch /tmp/idea-spark-injected)" depth=quick ``` A shell would execute `touch /tmp/idea-spark-injected` before invoking `mcporter`. More harmful commands could be substituted in the same way. Exploitation requires the optional validation workflow to be available and invoked, and the attacker-controlled shell syntax must survive the idea-synthesis step. Nevertheless, the documented command construction establishes an unsafe path from untrusted content to shell execution. ### Attack Path 1. An attacker supplies a domain, request, or other input containing shell command-substitution syntax, or publishes crafted content likely to appear in one of the configured web searches. 2. The skill searches external websites and generates a project pitch from user-controlled or remotely controlled content. 3. The generat ...[truncated 1235 chars]
Remediation
View remediation
- depth=quick ``` The runtime must pass these arguments directly to the process without invoking a shell. 2. **Prefer a structured tool call.** If `idea-reality.idea_check` is available as an MCP tool, call it directly using structured JSON rather than routing it through `exec`. 3. **Treat generated content as untrusted.** Apply the same security controls to model-generated pitches as to direct user input because pitches incorporate untrusted user and web content. 4. **Do not rely only on double quotes or character removal.** Generic filtering is error-prone across shells and platforms. If shell execution is unavoidable, use a platform-specific, well-tested argument-escaping library and reject unexpected control characters, newlines, and shell metacharacters as defense in depth. 5. **Run validation with least privilege.** Restrict filesystem, environment-variable, credential, and network access available to the validation process so that any residual command-execution flaw has limited impact. 6. **Add adversarial tests.** Verify that pitches containing payloads such as `$(id)`, backticks, quotes, semicolons, newlines, redirections, and logical operators are passed as literal data and are never interpreted by a shell. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage examples are broad enough to match common conversational requests like 'give me ideas' or 'what should I build,' which can cause the skill to activate outside a narrowly intended scope. This is not directly exploitable like code execution, but ambiguous triggering can lead to inappropriate routing, over-invocation, or unintended use of web-search-backed behavior in contexts where the user did not explicitly ask for this skill.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest uses broad trigger phrases like "give me ideas" and "what should I build," which are common conversational requests and may cause over-selection of this skill in ambiguous contexts. Overly broad activation increases the chance that the agent invokes external searches and optional command execution when a simpler local response would have sufficed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow directs the agent to send user-derived queries to external web search services and optionally execute a local command, but it provides no user-facing disclosure or consent step. This can expose user interests or sensitive context to third parties and may trigger local side effects without the user's informed approval, making the skill materially riskier in privacy- or security-sensitive environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs use of the exec tool to invoke an external command (mcporter call ...) using text derived from generated idea content. For an idea-generation skill, spawning a subprocess is unnecessary and expands the attack surface to command execution, local environment access, and unintended side effects if the command or surrounding tooling is compromised or interprets input unsafely.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill is presented as an idea-generation helper, but its follow-up instructs the agent to "proceed with development," which broadens the capability from ideation into action. This scope creep can cause the skill to trigger code-generation or implementation workflows the user did not clearly authorize, increasing the chance of unsafe tool use or unintended modifications in downstream systems.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.