Back to skill

Security audit

Pilot Translate

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a straightforward translation helper, but its install instructions ask users to install an unverified downloaded executable system-wide with sudo.

Review the install steps before use. Prefer a verified, pinned translation tool from a trusted package manager or a local/self-hosted translator, avoid sudo where possible, and do not translate confidential messages through third-party services unless that is acceptable for your data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Error
Location
SKILL.md:136
Finding

Unverified Remote Executable Installed with Elevated Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 136–139
Vulnerability Type: Unverified third-party executable fetched from a shortened URL
Risk Level: High

Vulnerable Code

bash
# Linux/macOS
wget git.io/trans
chmod +x ./trans
sudo mv trans /usr/local/bin/

Technical Analysis

The documented installation procedure downloads trans through the shortened URL git.io/trans, marks the downloaded content as executable, and installs it globally under /usr/local/bin/. It does not pin a version, validate the resolved origin, verify a cryptographic checksum, or authenticate a release signature.

Consequently, the executable installed by users may differ from the artifact that was originally reviewed. If the shortened URL, its destination, the hosting account, or the distribution infrastructure is compromised, attacker-controlled code can be substituted. The use of sudo expands the installation step beyond the current user's directory and places the unverified executable in a shared command-search location.

This issue most directly represents an insecure dependency acquisition process. It also creates a remote-payload execution condition when the installed trans command is subsequently invoked, but the best matching classification is insecure dependencies.

Attack Path

  1. An attacker compromises or gains control over the shortened URL destination, upstream hosting account, or associated delivery infrastructure.
  2. The attacker replaces the expected trans script with a malicious executable or script.
  3. A user follows the documented instructions and runs wget git.io/trans.
  4. The user makes the unverified file executable with chmod +x ./trans.
  5. The user invokes sudo mv and places the payload at /usr/local/bin/trans.
  6. The Skill workflow later executes commands such as:
    bash
    echo "$MESSAGE" | trans en:es
    
  7. The malicious payload executes with the privileges of the user or agent running the tra ...[truncated 763 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the shortened URL with the project's canonical, HTTPS-protected release URL.
  2. Pin the dependency to a specific reviewed version rather than retrieving a mutable latest artifact.
  3. Publish and verify a SHA-256 or stronger cryptographic checksum before execution or installation.
  4. Prefer signed releases and validate the signature against a documented, independently obtained maintainer key.
  5. Avoid installing with sudo; place the verified executable in a user-controlled directory such as $HOME/.local/bin.
  6. Use a trusted package manager where available, with an explicitly pinned package version and authenticated repository metadata.
  7. Fail closed if integrity verification does not succeed. For example:
    bash
    VERSION="PINNED_VERSION"
    URL="https://official.example/releases/${VERSION}/trans"
    EXPECTED_SHA256="PINNED_REVIEWED_SHA256"
    
    curl --fail --location --proto '=https' --tlsv1.2 \
      --output trans "$URL"
    printf '%s  %s\n' "$EXPECTED_SHA256" trans | sha256sum --check -
    install -m 0755 trans "$HOME/.local/bin/trans"
    
  8. Document the expected publisher, release version, checksum, and signature-verification procedure so users can authenticate the dependency independently.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly recommends external translation tools and services, which can send message contents to third-party systems, but it provides no privacy warning or guidance on handling sensitive data. In a messaging/agent-collaboration skill, this omission can cause users to unintentionally disclose confidential prompts, customer data, or agent outputs to external providers.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

Linux/macOS

wget git.io/trans chmod +x ./trans sudo mv trans /usr/local/bin/

text

## Dependencies

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs users to persistently modify translation-related configuration without warning that these settings may affect future sessions and message handling. This can lead to unexpected behavior, accidental translation of later communications, or privacy mistakes if users assume the change is temporary.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.