Back to skill

Security audit

exam-stress-coach

Security checks for vulnerabilities and agentic risk

Overview

This exam stress coaching skill is purpose-aligned and locally scoped, but users should understand that stress notes and generated plans are saved as plaintext files.

Install and run this only from a trusted copy, preferably in a virtual environment with pinned dependencies. Avoid putting highly sensitive details in stress notes, and delete or protect stress_log.json if the machine, project folder, backups, or sync services are shared. Be careful with --output because it can overwrite files your account can write.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
README.md:60
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/stress_coach.py:451
Finding

Arbitrary Writable File Overwrite Through the Plan Output Path

Content
View full analysis
= 1"); sys.exit(1) plan = generate_study_plan(args.subjects, args.days, args.hours_per_day) print_plan_summary(plan) if args.output: with open(args.output, "w") as f: json.dump(plan, f, indent=2) ``` ### Technical Analysis The `--output` value is accepted as an unrestricted path and passed directly to `open(..., "w")`. Write mode truncates an existing file before writing the generated JSON. The implementation does not: - Restrict output to a dedicated application directory. - Normalize and validate the destination against an approved root. - Reject symbolic links. - Detect or confirm replacement of existing files. - Use exclusive or atomic file creation. This is not command injection and does not independently elevate privileges. However, if an untrust ...[truncated 1532 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/stress_coach.py:300
Finding

Sensitive Stress Records Stored in Plaintext Without Explicit Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README promotes logging stress levels and free-form notes over time but does not warn users that these entries may be stored persistently on disk. Because stress notes can contain sensitive mental-health, academic, or personal context, users may disclose more than intended, creating privacy risk if the device is shared, compromised, or backed up to less secure locations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs users to log daily stress levels and notes to a JSON file without warning that this creates local records of potentially sensitive mental-health-related information. Even if stored only locally, users may not realize this data persists, could be readable by other local users/processes, or may be included in backups and sync services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.