Back to skill

Security audit

GOG Sync

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward GOG sync helper, but users should configure the remote backup target carefully and verify the dependency name mismatch before installing.

Install only if you are comfortable sending GOG saves and selected config files to the configured rsync destination. Set GOG_CONFIG_REMOTE to a trusted host, review GOG_CONFIG_DIR before running sync-config, and verify whether gogrepo or gogrepoc is the intended dependency.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
sync.sh:13
Finding

Environment-Controlled rsync Operands Permit Option Injection

Content
View full analysis

Vulnerability Details

File Location: sync.sh, lines 13-26
Vulnerability Type: Improper neutralization of option-like path values
Risk Level: Medium

Vulnerable Code

bash
CONFIG_SRC="${GOG_CONFIG_DIR:-$HOME/Games/GOG/config}"
CONFIG_DST="${GOG_CONFIG_REMOTE:-user@remote:/backups/gog/config}"
echo "Syncing GOG game custom configs from $CONFIG_SRC..."
if [ ! -d "$CONFIG_SRC" ]; then
  echo "Config directory not found: $CONFIG_SRC"
  echo "Set GOG_CONFIG_DIR to your config path."
  exit 1
fi
rsync -av --include='*/' --include='*.ini' --include='*.cfg' \
  --include='*.json' --include='*.xml' --include='*.bind' \
  --exclude='*' "$CONFIG_SRC/" "$CONFIG_DST/"
echo "Config sync complete."

Technical Analysis

The values of GOG_CONFIG_DIR and GOG_CONFIG_REMOTE are supplied directly as rsync command-line operands. Shell quoting prevents word splitting and shell metacharacter expansion, but it does not prevent rsync from interpreting an argument beginning with - as an option.

The source directory check only verifies that the supplied string identifies a directory. It does not reject option-shaped names. An attacker who can control the working directory and environment could create a directory whose name begins with an rsync option and then assign that name to GOG_CONFIG_DIR.

The unconditional trailing / restricts which injected options can be used successfully, but options that accept directory-like values may still be parsed. At minimum, this can alter transfer behavior, cause the operation to fail, or prevent the intended backup. More severe effects depend on the installed rsync version and the specific option accepted.

Attack Path

  1. Obtain control over the environment variables used to launch the Skill.
  2. Create an option-shaped directory that satisfies the -d validation, such as a relative hierarchy whose first component begins with an rsync option.

...[truncated 795 chars]

Remediation
View remediation

Remediation Suggestions

  • Reject GOG_CONFIG_DIR and GOG_CONFIG_REMOTE values that begin with -.
  • Canonicalize the local source with a trusted mechanism such as realpath and require it to be an absolute directory under an approved root.
  • Validate remote destinations against a strict expected syntax or an allowlist of approved hosts and base paths.
  • Use an explicit -- option terminator before path operands where supported by the deployed rsync version.
  • Keep transport-related options fixed in the script rather than allowing environment-controlled values to affect option parsing.
  • Abort on transfer failures by checking the rsync exit status, preferably with set -euo pipefail and explicit error reporting.
  • Add tests covering values beginning with -, embedded whitespace, remote-specifier characters, and unexpected path traversal.

T08 · Insecure Dependencies

Note
Location
skill.json:7
Finding

Dependency Name Mismatch Creates Dependency-Confusion Risk

Content
View full analysis

Vulnerability Details

File Location: skill.json, line 7; SKILL.md, line 41; sync.sh, line 5
Vulnerability Type: Inconsistent third-party dependency identity
Risk Level: Low

Vulnerable Code

skill.json declares:

json
"dependencies": ["gogrepoc", "rsync"],

SKILL.md documents a different dependency:

markdown
- `gogrepo` (optional, for library sync)

The implementation invokes the documented name:

bash
gogrepo sync ~/Games/GOG/library/

Technical Analysis

The package metadata names gogrepoc, while both the documentation and executable script refer to gogrepo. This is consistent with a typographical error or stale dependency declaration.

If the Skill platform automatically resolves entries from skill.json, it may attempt to install or trust a package that is not the component actually used by the script. Package-name discrepancies are a common prerequisite for typosquatting and dependency-confusion attacks. The reviewed files do not prove that gogrepoc is malicious or that automatic installation occurs, so the supply-chain impact is conditional on the platform's dependency-resolution behavior.

Attack Path

  1. A user or automated platform installs the Skill.
  2. The installer reads the dependency list from skill.json.
  3. The installer resolves gogrepoc rather than the intended gogrepo component.
  4. If an unintended or attacker-controlled package exists under that name, it is downloaded or trusted.
  5. Installation hooks or the resulting executable may run with the installer or user account's privileges.
  6. Independently, the Skill later invokes gogrepo, producing inconsistent behavior or execution failure.

Impact Assessment

In a resolver that automatically installs metadata dependencies, an unintended package could execute with the privileges of the installing user or service and affect files and credentials accessible to that a ...[truncated 235 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace gogrepoc with the verified canonical dependency name if gogrepo is intended.
  • Confirm the package identity using its official repository, publisher, and cryptographic release information.
  • Pin an audited version and trusted source rather than resolving an unbounded package name.
  • Make dependency declarations consistent across skill.json, SKILL.md, and sync.sh.
  • If gogrepo is optional, represent it as optional metadata and make sync.sh check for it with command -v gogrepo before invocation.
  • Configure installers to reject unknown package names and avoid running third-party installation hooks without review.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README promotes syncing save files and configuration files to a remote destination but does not warn users that potentially sensitive local data will be transmitted off-device. Save data and config files can contain personal information, account identifiers, hostnames, paths, or other private metadata, so omission of disclosure and safety guidance creates a real privacy and data-exposure risk.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · sync.sh (reported line 28)May include surrounding context.

sh
;;
  list-games)
    echo "Installed GOG games:"
    ls -la ~/Games/GOG/library/
    ;;
  *)
    echo "Usage: gog-sync [sync|sync-saves|sync-config|list-games]"

Static analysis

No suspicious patterns detected.