Back to skill

Security audit

Cloud Service Agreement

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent instruction-only agreement drafting helper, but users should be careful with its optional local CLI setup and shell command handling.

Before installing, prefer the Remote MCP only if you are comfortable sending agreement terms to openagreements.org. For local use, install the pinned CLI version, validate template and output names exactly as documented, quote shell arguments, and review generated legal documents before signing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
template-filling-execution.md:69
Finding

Unquoted and Unvalidated Shell Parameters in Local Rendering Command

Content
View full analysis
-d "$VALUES_FILE" -o .docx ``` ``` ### Technical Analysis The local rendering workflow places the template name and output filename into a shell command without showing shell quoting or performing validation at the point of use: - `` is derived from template inventory data, which the project itself identifies as untrusted third-party data. - `` may be influenced by user input. - Unlike `"$VALUES_FILE"`, neither placeholder is shown as a quoted shell argument. - Although `SKILL.md:42-48` defines validation requirements, the linked execution workflow does not apply those requirements before invoking the CLI. If an agent translates these placeholders into raw shell text, shell metacharacters in either value may be interpreted as shell syntax rather than as part of a single argument. Merely documenting validation in another file does not ensure that an agent following this command performs it. ### Attack Path 1. The attacker supplies a crafted output filename, or influences a template name returned by an untrusted template catalog. 2. The value contains shell syntax such as command separators, substitutions, pipes, redirects, or other metacharacters. 3. An agent follows the documented local CLI workflow and directly substitutes that value for `` or ``. 4. The shell parses the injected syntax because the substituted argument is not quoted. 5. The injected command executes under the operating-system account running the agent or CLI. Exploitation depends on the executing agent treating the displayed placeholders as direct shell substitutions without independently applying the separate validation guidance. ### ...[truncated 682 chars]
Remediation
View remediation
&2 exit 1 fi ``` 3. Validate the template name using both an allowlisted character set and inventory membership: ```bash if [[ ! "$TEMPLATE_NAME" =~ ^[A-Za-z0-9_-]+$ ]]; then printf '%s\n' "Invalid template name" >&2 exit 1 fi ``` The workflow must additionally verify that `TEMPLATE_NAME` exactly matches a name in the previously returned template inventory. 4. Do not construct the command through `eval`, `sh -c`, string concatenation, or another shell-parsing layer. 5. Add the validation requirements directly beside the rendering command so the executable workflow does not depend on guidance in a separate file. 6. Add negative tests covering semicolons, command substitutions, whitespace, path separators, redirects, pipes, ampersands, extra filename extensions, and template names absent from the inventory. ]]>

T08 · Insecure Dependencies

Warning
Location
template-filling-execution.md:76
Finding

Unpinned Global npm Installation Creates Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
Before installing, understand what the skill can and cannot enforce.

**This skill is instruction-only.** It ships no code and executes nothing by itself. When the Local CLI path is used, the agent executes shell commands (`open-agreements fill ... -o <output-name>.docx`, plus `cat > /tmp/oa-values.json` and `rm /tmp/oa-values.json`) whose parameters come from user-supplied values and template-derived data. The skill cannot enforce sanitization itself — only the agent running the instructions can.

### Shell command parameter sanitization (mandatory for Local CLI path)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
Before installing, understand what the skill can and cannot enforce.

**This skill is instruction-only.** It ships no code and executes nothing by itself. When the Local CLI path is used, the agent executes shell commands (`open-agreements fill ... -o <output-name>.docx`, plus `cat > /tmp/oa-values.json` and `rm /tmp/oa-values.json`) whose parameters come from user-supplied values and template-derived data. The skill cannot enforce sanitization itself — only the agent running the instructions can.

### Shell command parameter sanitization (mandatory for Local CLI path)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
ecution.md) documents the same rules. This section exists so a scanner reading `SKILL.md` alone can verify that the skill acknowledges shell safety.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · template-filling-execution.md (reported line 58)May include surrounding context.

If Local CLI: Write values to a per-run temporary JSON file with restrictive permissions:

bash
VALUES_FILE="$(mktemp /tmp/oa-values.XXXXXX.json)"
chmod 600 "$VALUES_FILE"
trap 'rm -f "$VALUES_FILE"' EXIT

cat > "$VALUES_FILE" << 'FIELDS'

Static analysis

No suspicious patterns detected.