Back to skill

Security audit

child-screen-time

Security checks for vulnerabilities and agentic risk

Overview

This is a local screen-time tracking tool whose sensitive child records are purpose-aligned and disclosed, but users should protect the local data file.

Install only on a device/account you trust. The tool stores child names, ages, activity history, awards, deductions, and compliance-related notes in ~/.screen_time.json; consider restricting that file to the account owner and avoid entering highly sensitive free-text details.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/screen_time.py:38
Finding

Screen-Time Records Are Created Without Restrictive File Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/screen_time.py, lines 38–72
Vulnerability Type: Insecure storage of sensitive child and behavioral data
Risk Level: Medium

Vulnerable Code

python
DB_PATH = os.path.expanduser("~/.screen_time.json")

# --- Database ---

def load_db():
    if os.path.exists(DB_PATH):
        with open(DB_PATH, "r") as f:
            return json.load(f)
    return {"children": {}}

def save_db(db):
    with open(DB_PATH, "w") as f:
        json.dump(db, f, indent=2, default=str)

Technical Analysis

The application stores children's names, ages, screen-use history, activities, behavioral rewards, deductions, and compliance information in ~/.screen_time.json. The database is written with a normal open(..., "w") operation without explicitly enforcing owner-only permissions.

When the file is first created, its effective permissions depend on the process umask. For example, a permissive or common multi-user configuration may create the file with mode 0644, making it readable by other local users if the home directory is traversable. More permissive umasks or shared-group environments can also make the file writable by unintended users.

The application also does not inspect or repair the permissions of an existing database. Consequently, records remain exposed if the file was created with unsafe permissions, copied from another location, or manually assigned permissive access.

This is particularly relevant because the database concerns minors and can contain detailed behavioral and activity records. Although no passwords or authentication tokens are stored, the information has privacy and safeguarding implications.

Attack Path

  1. A parent runs a state-changing command such as add-child, log, award, or deduct on a multi-user system.
  2. save_db() creates ~/.screen_time.json using the process's current umask rather than explicitly selecti ...[truncated 1504 chars]
Remediation
View remediation

Remediation Suggestions

Enforce owner-only permissions when creating and updating the database:

python
import json
import os
import stat
import tempfile

def save_db(db):
    directory = os.path.dirname(DB_PATH)
    os.makedirs(directory, mode=0o700, exist_ok=True)

    fd, temporary_path = tempfile.mkstemp(
        prefix=".screen_time.",
        suffix=".tmp",
        dir=directory,
    )
    try:
        os.fchmod(fd, 0o600)
        with os.fdopen(fd, "w", encoding="utf-8") as f:
            json.dump(db, f, indent=2, default=str)
            f.flush()
            os.fsync(f.fileno())

        os.replace(temporary_path, DB_PATH)
        os.chmod(DB_PATH, 0o600)
    except Exception:
        try:
            os.unlink(temporary_path)
        except FileNotFoundError:
            pass
        raise

Additional hardening measures should include:

  1. Validate the permissions of an existing database during startup and reject or repair group/world-accessible modes.
  2. Confirm that the database is a regular file owned by the current user before reading or replacing it.
  3. Use atomic replacement to reduce corruption from interrupted writes.
  4. Use explicit UTF-8 encoding for deterministic handling of names and activity descriptions.
  5. Document that the database contains private records concerning minors and should not be placed in shared directories.
  6. Consider optional encryption at rest where the host threat model includes administrators, shared backups, or device theft; restrictive permissions alone do not protect against those threats.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes file read/write behavior by storing data in a local JSON file, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens transparency and consent boundaries because an agent or runtime may access the filesystem without the user being clearly informed of that capability in the manifest.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/earned-time-economy.md (reported line 62)May include surrounding context.

md
When a child wants more time than they have, the system evaluates the request:

### Auto-Approve Conditions
- Child has >70% compliance score over last 7 days
- Request is for ≤15 extra minutes
- Child has completed today's homework

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · scripts/screen_time.py (reported line 463)May include surrounding context.

python
conditions = []
    approved = False
    conditional = False
    # Auto-approve conditions
    if compliance >= 70 and minutes <= 15 and over < 30 and edu_today >= 30:
        approved = True
    elif compliance >= 60 and minutes <= 15 and over <= 0:

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill stores child-related behavioral and usage data locally, including screen habits, compliance, and rewards, but does not warn users about the sensitivity of this information. Even though storage is local, this can expose minors' personal and behavioral data to other local users, backups, or malware, and users may not realize that deleting the file erases records permanently.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.