Back to skill

Security audit

Windows File Search Skill via Everything

Security checks for vulnerabilities and agentic risk

Overview

This Windows file-search skill appears purpose-aligned, but it gives broad filesystem search/export examples and unsafe installation guidance that users should review before installing.

Install only if you are comfortable with a tool that can enumerate large parts of your Windows filesystem. Prefer a verified Everything installer from the official publisher, avoid copying es.exe into C:\Windows, scope searches to specific approved folders, and treat CSV exports as sensitive files that should be stored and deleted deliberately.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Executable Downloads Lack Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23-32
Vulnerability Type: Unverified third-party executable download
Risk Level: Medium

Code Snippet:

markdown
1. **Download and Install Everything:**
   - Visit the official Everything website: https://www.voidtools.com/downloads/
   - Download and install the latest version of Everything
   - Ensure that the "ES Command Line Tool" option is selected during installation
   
   **Direct Download Links:**
   
   **Everything 1.4.1 (Stable Version):**
   - Portable ZIP: https://www.voidtools.com/Everything-1.4.1.1032.x64.zip
   - Installer: https://www.voidtools.com/Everything-1.4.1.1032.x64-Setup.exe

Technical Analysis

The skill directs users to download and execute third-party installers or portable binaries but provides no pinned cryptographic hashes or instructions to verify the executable's Authenticode signature. HTTPS protects data in transit under normal conditions, but it does not independently verify that the downloaded artifact is the exact artifact reviewed or intended by the skill author.

If the vendor's distribution infrastructure, DNS resolution, TLS trust chain, or linked artifact is compromised, a substituted executable could run arbitrary code. The direct links use the stated vendor's HTTPS domain, so the documentation does not establish malicious intent or an active compromise; the issue is the absence of artifact-level verification.

Attack Path

  1. An attacker compromises or successfully impersonates an element of the executable delivery path.
  2. The installer or ZIP referenced by the skill is replaced with a modified artifact.
  3. A user follows the skill instructions and downloads the artifact without checking a pinned hash or trusted publisher signature.
  4. The user launches the installer or extracted executable.
  5. The substituted binary executes attacker-controlled code with the privileges of the i ...[truncated 529 chars]
Remediation
View remediation

Remediation Suggestions

  • Publish and pin a SHA-256 digest for every supported installer and ZIP artifact.
  • Instruct users to compare the downloaded file's digest against the pinned value before execution.
  • Require Authenticode verification and identify the expected publisher certificate subject.
  • Reject artifacts with an invalid, missing, expired, or unexpected publisher signature.
  • Prefer a reputable Windows package manager where package identity and version can be pinned and independently validated.
  • Avoid recommending an unpinned “latest version” when reproducible review is required.
  • Periodically update versions, hashes, and expected signing-certificate information through a controlled review process.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:41
Finding

Third-Party Executable Is Copied into the Windows System Directory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 41-43
Vulnerability Type: Unsafe privileged installation guidance
Risk Level: Medium

Code Snippet:

markdown
**Method B - Copy es.exe to System Directory:**
- Copy the es.exe file to your Windows system directory (`%systemroot%`)
- This is typically `C:\Windows`

Technical Analysis

The documented installation method recommends copying a third-party executable directly into %systemroot%, normally C:\Windows. Writing to this directory typically requires administrative elevation and makes the executable available through a globally searched system location.

This approach violates least-privilege installation practices because the tool does not need to reside in the Windows system directory to perform file searches. It also increases executable-resolution ambiguity: commands invoking es may resolve to the globally installed binary rather than a version stored in a dedicated, access-controlled application directory. The same document already describes adding a dedicated installation directory to PATH, making the system-directory method unnecessary.

This guidance does not itself bypass Windows access controls; a user must still authorize or possess the required privileges. The risk arises from unnecessarily requesting privileged system modification and globally exposing a third-party binary.

Attack Path

  1. A user obtains es.exe, potentially without performing artifact integrity verification.
  2. Following the documented Method B, the user grants administrative elevation to copy it into %systemroot%.
  3. The executable becomes available from a system-wide command-search location.
  4. Users or processes invoking es may execute that globally installed binary without specifying or validating its full path.
  5. If the binary was substituted before installation or is later replaced through another privileged compromise, subsequent le ...[truncated 558 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove Method B and do not place third-party utilities in %systemroot% or another operating-system directory.
  • Install es.exe in a dedicated application directory, such as a vendor-specific directory under Program Files or a controlled per-user tools directory.
  • Apply restrictive filesystem permissions so unprivileged users cannot replace a system-wide executable.
  • Add the dedicated directory to the user-level PATH when system-wide availability is unnecessary.
  • Prefer invoking the utility through a fully qualified path in automation.
  • Verify the executable's SHA-256 digest and Authenticode publisher signature before installation.
  • Avoid administrative elevation unless a documented feature strictly requires it.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents -csv and -export-csv features without warning that they create persistent artifacts on disk that may contain sensitive file names, paths, and metadata. In a file-search skill that can enumerate broad portions of the filesystem, silent export capability increases the risk of unintended data disclosure if users or downstream agents write inventories of sensitive locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The example shows exporting hidden-file results from C:\ to hidden_files.csv without any caution about persistence or sensitivity. Hidden files often include configuration, system, and user artifacts, so producing a disk-backed inventory of them can materially aid reconnaissance or leak sensitive environment details if mishandled.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.