Back to skill

Security audit

Network Log Analysis

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent, but some documented log-analysis commands can be unsafe when run on attacker-controlled logs or shared systems.

Review before installing. The skill does not appear malicious and has no hidden installer or network egress, but do not run its awk timestamp-conversion examples on untrusted logs as written. Prefer safer parsing tools or scripts that do not pass log text through a shell, use private mktemp directories for intermediate files, and run analysis under an unprivileged read-only account.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
references/cli-reference.md:166
Finding

Shell Command Injection Through Untrusted Log Timestamp Fields

Content
View full analysis

Vulnerability Details

File Location: references/cli-reference.md, lines 166–169 and 218–221
Vulnerability Type: Shell command injection through dynamically constructed commands
Risk Level: High

Vulnerable Code

The timestamp conversion example at lines 166–169 contains:

awk
awk '{
  cmd = "date -d \""$1" "$2" "$3"\" +%s 2>/dev/null"
  cmd | getline epoch; close(cmd)
  print epoch, $0
}' logfile.log | sort -n | cut -d' ' -f2-

The correlation helper repeats the same vulnerable construction at lines 218–221:

awk
awk -v target="$TARGET_EPOCH" -v win="$WINDOW" '{
  cmd = "date -d \""$1" "$2" "$3"\" +%s 2>/dev/null"
  cmd | getline epoch; close(cmd)
  if (epoch >= target-win && epoch <= target+win) print
}' network.log

Technical Analysis

In AWK, cmd | getline executes cmd through a command shell. The command incorporates $1, $2, and $3 directly from each analyzed log record:

awk
cmd = "date -d \""$1" "$2" "$3"\" +%s 2>/dev/null"

These fields are enclosed in shell double quotes but are not validated or escaped. A hostile field containing a double quote can terminate the intended argument. Shell metacharacters placed after that quote can introduce additional commands.

Syslog records are not necessarily trusted input. They can originate from compromised network devices, forged UDP syslog packets, malicious applications, or users with permission to append to an analyzed log. Consequently, treating timestamp fields as safe shell syntax creates a command-injection boundary.

The issue is present in two documented helpers: general RFC 3164 timestamp normalization and extraction of events around a target time.

Attack Path

  1. An attacker gains the ability to submit a crafted record to the collector or modify a log file that will be analyzed.
  2. The attacker places shell-breaking syntax in one of the first three whitespace-delimited fie ...[truncated 1334 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not invoke a shell with timestamp text taken from log records.
  • Replace the AWK cmd | getline construction with a script that parses timestamps through a date/time library without shell evaluation.
  • If an external process is unavoidable, pass arguments through an API that accepts an argument array rather than a command string.
  • Strictly validate RFC 3164 fields before processing:
    • Month must be one of Jan through Dec.
    • Day must contain only one or two decimal digits and be within the valid range.
    • Time must exactly match HH:MM:SS with valid ranges.
  • Reject and separately preserve malformed records rather than attempting to normalize them.
  • Run analysis under a dedicated, unprivileged account with read-only access to source logs.
  • Add test cases containing quotes, command substitutions, semicolons, newlines, and other shell metacharacters to ensure malformed logs cannot trigger execution.
  • Apply the corrected implementation to both occurrences at lines 166–169 and 218–221.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:167
Finding

Predictable Shared Temporary Files Permit Symlink Clobbering and Evidence Manipulation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 167 and 206–207
Vulnerability Type: Unsafe predictable temporary-file handling
Risk Level: Medium

Vulnerable Code

The merged timeline is written to a fixed path:

bash
cat /var/log/rtr*.log /var/log/sw*.log | sort -k1,3 > /tmp/merged-timeline.log

The mnemonic comparison also uses fixed paths:

bash
grep -oP '%\S+-\d-\S+' /var/log/cisco.log | sort -u > /tmp/current.txt
comm -23 /tmp/current.txt /tmp/baseline-mnemonics.txt

Technical Analysis

/tmp is commonly writable by every local user. Although its sticky bit normally prevents one user from deleting another user's files, it does not prevent an attacker from creating an unused predictable filename in advance.

Shell output redirection opens the named path and follows symbolic links. If an attacker pre-creates /tmp/merged-timeline.log or /tmp/current.txt as a symbolic link, the analyst's command can truncate and overwrite the symlink target when the analyst has permission to write to it.

Fixed paths also create integrity and race-condition concerns. An attacker able to create or modify these artifacts may contaminate intermediate evidence, cause analysis failures, or influence later commands that consume them.

Attack Path

  1. A local attacker predicts the documented filename, such as /tmp/current.txt.
  2. Before the analyst runs the command, the attacker creates that path as a symbolic link to a file writable by the analyst.
  3. The analyst executes the documented command, potentially with elevated privileges needed to read protected network logs.
  4. Shell redirection follows the symbolic link and opens the target with truncation.
  5. The target is overwritten with generated analysis data.

For evidence manipulation, an attacker may instead pre-create or race modifications to an intermediate artifact. If a later workflow trusts that artifact, the attacker can i ...[truncated 666 chars]

Remediation
View remediation

Remediation Suggestions

  • Create a private temporary directory with an unpredictable name:
bash
tmpdir=$(mktemp -d) || exit 1
chmod 700 "$tmpdir"
trap 'rm -rf -- "$tmpdir"' EXIT HUP INT TERM
  • Store all temporary artifacts beneath that directory:
bash
merged_timeline="$tmpdir/merged-timeline.log"
current_mnemonics="$tmpdir/current.txt"
  • Quote every temporary pathname when used in redirections or command arguments.
  • Do not reuse fixed /tmp paths across runs.
  • Run forensic analysis as a dedicated unprivileged account rather than root.
  • Keep source logs read-only during analysis.
  • If artifacts must persist, write them into a user-owned evidence directory with restrictive permissions and create files atomically.
  • Document checksums and ownership for retained forensic artifacts to detect later tampering.
  • Apply the same private-directory design to the fixed path at line 167 and the files at lines 206–207.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The manifest frames this skill as device-level network log analysis using raw syslog, console logs, and SNMP trap data, but the troubleshooting guidance includes using ss -ulnp | grep 514 to inspect live listener state on the collector. Checking socket/listener state is an operational host/network diagnostic capability rather than analysis of log evidence, and it is not clearly justified by the stated read-only log-analysis purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.