Back to skill

Security audit

goplaces-togo

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent restaurant recommendation purpose, but it persists sensitive location history and shows unsafe shell-style lookup commands using user-controlled place names.

Review before installing. Use it only if you are comfortable storing saved places, notes, visit history, and preferences locally and sending lookup terms through goplaces/Google Places. Do not run it on untrusted pasted CSVs or place names unless the agent invokes goplaces with shell execution disabled and literal argument arrays.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:103
Finding

Shell Command Injection Through Untrusted Place Names

Content
View full analysis
" --limit 1 --json ``` ``` The same unsafe command construction is repeated for unresolved entries: ```markdown Only re-run resolve for entries that still have `placeId: null` (e.g. manually added entries): ```bash goplaces resolve "" --limit 1 --json ``` ``` Place names can originate from an imported CSV: ```markdown For each non-empty data row (skip the header and blank rows): - `Title` → `name` ``` ### Technical Analysis The Skill instructs the Agent to insert a place name originating from user-supplied CSV data or direct user input into a Bash command. Wrapping the value in double quotes does not make it safe for shell evaluation. Shell substitutions such as `$(command)` and backtick substitutions remain active inside double-quoted strings. An attacker can also attempt to terminate the quoted argument by supplying embedded quotation marks and shell operators. For example, a CSV title containing a value similar to: ```text Restaurant $(touch /tmp/goplaces-injection) ``` could produce: ```bash goplaces resolve "Restaurant $(touch /tmp/goplaces-injection)" --limit 1 --json ``` If the Agent executes the documented command through a shell, the substitution is evaluated before `goplaces` starts. The vulnerability is repeated during initial city classification and later resolution of entries whose place IDs remain unset. The exploitability depends on the Agent's command-execution interface. An API that invokes an executable with a literal argument array would not evaluate shell syntax, but the Skill explicitly presents the operation as a Bash command and does not require such safe invocation. ...[truncated 1434 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:14
Finding

Sensitive Location and Visit History Persisted in Predictable Plaintext Storage

Content
View full analysis
": { "name": "string", "city": "string | null", "visits": [ { "date": "YYYY-MM-DD", "time": "HH:MM", "note": "string | null" } ] } } } ``` ``` The imported data is saved before any API operation: ```markdown After parsing, write the resulting array to `savedList` in `skills/goplaces-togo/goplaces-visits.json` immediately, before doing any API calls. This ensures the list is never lost even if the session ends early. ``` Confirmed visits are also persisted: ```markdown 3. Append a new visit entry: ```json { "date": "YYYY-MM-DD", "time": "HH:MM", "note": null } ``` Use today's date and the current local time (24-hour format). Do not touch `savedList`. 4. Write the full updated object (both `savedList` and `places`) back to `skills/goplaces-togo/goplaces-visits.json`. ``` ### Technical Analysis The Skill stores a user's saved locations, Google Maps URLs, place identifiers, city information, personal comments, dated visit history, visit times, and preferences in a predictable plaintext file under the Skill directory. This collection can reveal sensitive behavioral and movement patterns. Exact visit dates and times, recurring destinations, preferred areas, ...[truncated 2194 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill performs live lookups against the Google Places API using user-supplied place names, location preferences, and saved-list content, but it does not warn the user that their data will be transmitted to an external service. This creates a privacy and data-handling vulnerability because user location interests and personal notes may be inferred or sent off-device without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill persists the user's saved places list, comments, and visit history to a local file without an explicit privacy notice or clear consent language. This is sensitive behavioral and location-adjacent data, and silent retention increases the risk of unauthorized disclosure, unexpected profiling, and user surprise if the machine is shared or the file is later reused.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file declares a single persistent-state schema, but later instructions add persisted state such as lastPreferences and modified comments that are not represented in that schema. This mismatch is dangerous because implementations may serialize unexpected fields inconsistently, drop data, or corrupt state during reads/writes, especially when multiple flows update the same JSON file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a skill that asks for a saved places list, looks up places, and recommends the best one to visit today based on preferences and visit history. However, the documented behavior also supports always-on capture actions such as logging past visits, updating sentiment notes, clearing/removing entries, browsing by city, and storing last-used preferences, which is materially broader than a single recommendation workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.