Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md python scripts/meme_gen.py make 'Unit tests?' 'No tests.' --template drake --output meme.svg
Security audit
Security checks for vulnerabilities and agentic risk
This is a local meme-generation skill whose file reads and writes match its stated purpose, with only ordinary overwrite cautions.
Install only if you are comfortable with a local CLI that writes SVG/HTML files and may overwrite default output names such as meme.svg; use explicit output paths in a dedicated working directory.
Referenced artifact was not completely inspected
python scripts/meme_gen.py make 'Unit tests?' 'No tests.' --template drake --output meme.svg
Referenced artifact was not completely inspected
python scripts/meme_gen.py make 'Unit tests?' 'No tests.' --template drake --output meme.svg
Referenced artifact was not completely inspected
python scripts/meme_gen.py make 'Unit tests?' 'No tests.' --template drake --output meme.svg
Referenced artifact was not completely inspected
python scripts/meme_gen.py make 'Unit tests?' 'No tests.' --template drake --output meme.svg
Referenced artifact was not completely inspected
python scripts/meme_gen.py make 'Unit tests?' 'No tests.' --template drake --output meme.svg
Referenced artifact was not completely inspected
python scripts/meme_gen.py make 'Unit tests?' 'No tests.' --template drake --output meme.svg
The skill documentation exposes file read/write capabilities through commands that read templates and write SVG/HTML outputs, but it does not declare any explicit tool scope or permissions. In agent environments, undeclared filesystem access weakens sandboxing and user visibility, allowing the skill to write files or read local template inputs beyond what a reviewer may expect.
In the no-subcommand path, providing a global template causes the program to write directly to a fixed filename, meme.svg, in the current working directory without prompting or requiring an explicit output path. This can overwrite an existing file unexpectedly, which is a real integrity risk even though it is not likely to lead to code execution or privilege escalation in this meme-generation context.
No suspicious patterns detected.