Back to skill

Security audit

focusnoteapp

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it adds user-provided text to today’s FocusNote daily note by writing local FocusNote note files.

Install only if you are comfortable with the agent modifying your local FocusNote files. Consider replacing uuid with Node’s built-in crypto.randomUUID() or pinning the dependency before use, and ask the agent to show the target note path before first write if you want tighter control.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:377
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 377–378
Vulnerability Type: Unpinned npm dependency installation
Risk Level: Medium

Complete Code Snippet

markdown
2. Install dependencies: `npm install uuid`
3. Make it executable: `chmod +x add-to-daily-note.js`

The dependency is subsequently loaded by the example implementation:

javascript
const { v4: uuidv4 } = require("uuid"); // npm install uuid

Technical Analysis

The installation instructions use npm install uuid without specifying an exact reviewed version or providing a lockfile with integrity metadata. Consequently, the dependency resolved at installation time may differ from the version originally reviewed.

This creates a supply-chain risk if the package, its publication account, or one of its transitive dependencies is compromised. npm packages may contain lifecycle scripts that execute during installation under the installing user's privileges. Even without malicious behavior, mutable dependency resolution undermines reproducibility and can introduce incompatible or vulnerable releases.

The audit did not identify evidence that the current uuid package is malicious. The finding concerns the unsafe, unpinned installation practice and the resulting exposure to future package changes.

Attack Path

  1. An attacker compromises the dependency's publication channel or a dependency version later becomes malicious.
  2. A user follows the skill's instruction and runs npm install uuid.
  3. npm resolves and downloads the mutable package version and its dependency graph.
  4. Any malicious lifecycle script can execute during installation, or malicious package logic can execute when the skill calls require("uuid") and uses the package.
  5. The payload runs with the privileges of the user installing or invoking the skill.

Impact Assessment

Successful exploitation could execute arbitrary code with the local ...[truncated 426 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer the built-in Node.js API crypto.randomUUID() and remove the external uuid dependency entirely.
  • If the dependency must remain, pin it to an exact reviewed version rather than using a floating version.
  • Include a committed package.json and package-lock.json, and instruct users to run npm ci for reproducible installation with integrity verification.
  • Review both direct and transitive dependencies and run npm audit as part of release checks.
  • Disable installation scripts where operationally feasible with npm ci --ignore-scripts, after verifying that required dependencies do not depend on lifecycle scripts.
  • Perform dependency updates through a controlled review process rather than resolving the latest release during installation.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is activated by a very general natural-language condition ('when the user asks to add text to their daily note') without requiring a confirmation step or tighter guardrails. Because the action writes to the filesystem and may create new note structures automatically, ambiguous triggering could cause unintended modification of user data from loosely related prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill creates directories and writes multiple JSON files if the daily note does not already exist, but the description does not clearly warn the user that it will automatically create and modify files on disk. This lack of disclosure increases the risk of surprise persistence and unintended data changes, especially in an agent setting where users may not realize the action has side effects beyond simple note entry.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.