Back to skill

Security audit

story-spark

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated purpose, but its writing prompts can expose private photo locations and journal text if users point it at sensitive folders.

Install only if you are comfortable letting it read the folders you point it at. Use small, selected folders rather than an entire photo library or journal archive, and avoid saving outputs where others may see them because prompts can contain location, time, filename, and personal text details.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The documented behavior and declared purpose do not fully match the actual capabilities: the skill uses filesystem access without declared permissions and includes behaviors not clearly reflected in the description. This mismatch is dangerous because users may consent to a creative-writing tool without understanding that it will traverse personal directories and process sensitive content beyond what is explicitly and safely scoped.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

Step 1: Scan your sources

bash
python scripts/story_spark.py photos ~/Pictures/2025/ --count 10 --output prompts.json

Step 2: Review generated prompts

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/story_spark.py (reported line 437)May include surrounding context.

python
✍️  Your turn. Free-write for 15 minutes. Don't edit. Let the story surprise you.""",
    }
    return prompt


# ---------------------------------------------------------------------------

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/story_spark.py (reported line 498)May include surrounding context.

python
def output_prompts(prompts, args):
    """Print prompts and optionally save to file."""
    for i, p in enumerate(prompts, 1):
        print(f"\n{'═' * 60}")
        print(f"  ✦ STORY SPARK #{i}/{len(prompts)} — {p['id']}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README explicitly promotes scanning personal photos, journal entries, notes, and EXIF GPS metadata, but does not warn users that these inputs may contain highly sensitive location history, intimate thoughts, or other private information. In an agent skill context, that omission is security-relevant because users may invoke the skill without understanding the privacy exposure or minimizing the data they provide.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly describes reading user directories containing photos and journals and exporting generated prompts, which implies file read/write capability, yet it declares no explicit tool scope or permissions. This creates an authorization transparency gap: a user or hosting platform may not realize the skill needs access to sensitive local files, increasing the chance of unintended data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill processes highly sensitive personal data, including journal entries, notes, and photo metadata such as dates and locations, but the description lacks a clear privacy warning or consent language. In this context, that omission is risky because users may expose intimate or location-revealing information to the tool without understanding the sensitivity or handling implications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The photos mode extracts EXIF metadata including GPS coordinates and incorporates location details into generated prompts without an explicit privacy warning or consent checkpoint. In this skill's context, users are encouraged to scan personal photos, so sensitive home, travel, or routine-location data may be surfaced on screen or persisted to disk unexpectedly.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The text mode reads journal and note files, extracts emotionally salient sentences, and reprints them in prompts without a clear warning that highly personal content will be processed and echoed back. Because the skill is specifically aimed at personal memories and journaling, it increases the chance that intimate or sensitive material is exposed to anyone viewing the terminal or saved outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

When --output is used, the tool serializes prompts containing source details and potentially verbatim journal excerpts to JSON without warning about persistence of sensitive data. This creates a lasting local artifact that may retain private memories, locations, and emotional content beyond the user's immediate session.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The manifest frames the skill as scanning personal content and transforming it into fiction seeds, which implies read/transform behavior. The code additionally supports writing JSON output to a user-specified file, a behavior not reflected in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.