Back to skill

Security audit

Content Multiplier

Security checks for vulnerabilities and agentic risk

Overview

This skill mostly does local content rewriting, but its included script can write output files outside the chosen folder if given a crafted topic.

Review before installing if you plan to run the included Python script. Use only trusted input files and topics, avoid confidential source material unless you are authorized to process it, and do not run the script with untrusted topic strings until filename sanitization and output-directory containment are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/multiplier.py:267
Finding

Arbitrary File Overwrite Through Unsanitized Topic

Content
View full analysis

Vulnerability Details

File Location: scripts/multiplier.py, lines 267–271
Vulnerability Type: Path traversal leading to arbitrary file creation or overwrite
Risk Level: Medium

Vulnerable Code:

python
filename = f"{topic.replace(' ', '_')}_{platform}.md"
filepath = os.path.join(output_dir, filename)

with open(filepath, 'w', encoding='utf-8') as f:
    f.write(content)

Technical Analysis

The user-controlled --topic argument is incorporated directly into an output filename. Replacing spaces with underscores does not remove path separators, absolute-path prefixes, or .. traversal components.

The resulting path is joined with output_dir without canonicalization or a containment check. Opening that path with mode w creates the file if it does not exist and truncates it if it does. Python will also follow a symbolic link at the destination.

Although the selected platform adds a fixed suffix such as _linkedin.md, an attacker can still target writable paths whose final names include that suffix.

Attack Path

  1. The attacker invokes the script with a crafted topic containing traversal components, for example:

    bash
    python scripts/multiplier.py \
      --input source.txt \
      --platforms linkedin \
      --topic "../../target" \
      --output ./generated_content
    
  2. The script constructs the filename:

    text
    ../../target_linkedin.md
    
  3. os.path.join() produces:

    text
    ./generated_content/../../target_linkedin.md
    
  4. Filesystem path resolution escapes the intended output directory.

  5. The script creates or truncates target_linkedin.md outside that directory and writes generated Markdown into it.

  6. If the calculated destination is a symbolic link, the linked target may be overwritten instead.

Exploitation requires control over the command-line topic and write permission to the resolved destination.

...[truncated 549 chars]

Remediation
View remediation

Remediation Suggestions

  1. Convert the topic into a strict filename slug using an allowlist, such as ASCII letters, digits, underscores, and hyphens.
  2. Reject absolute paths, path separators, .. components, empty slugs, and reserved filenames.
  3. Resolve both the output directory and candidate destination with pathlib.Path.resolve(), then verify that the destination remains beneath the resolved output directory.
  4. Reject existing symbolic-link destinations and consider using os.open() with O_NOFOLLOW on supported platforms.
  5. Use exclusive creation mode (x) when overwriting existing output is not required. Otherwise, require explicit overwrite authorization.
  6. Add tests covering ../, absolute paths, nested separators, encoded or alternate separators, and symlink destinations.

Example hardening approach:

python
from pathlib import Path
import re

safe_topic = re.sub(r"[^A-Za-z0-9_-]+", "_", topic).strip("_")
if not safe_topic:
    raise ValueError("Topic does not produce a valid filename")

output_root = Path(output_dir).resolve()
output_root.mkdir(parents=True, exist_ok=True)

destination = (output_root / f"{safe_topic}_{platform}.md").resolve()
if destination.parent != output_root:
    raise ValueError("Output path escapes the configured directory")
if destination.is_symlink():
    raise ValueError("Symbolic-link destinations are not permitted")

with destination.open("x", encoding="utf-8") as f:
    f.write(content)
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs saving output as a Markdown file and explicitly asks users to provide file paths, which implies file read/write behavior, but it declares no tool permissions or allowed-tools scope. Missing explicit scoping weakens least-privilege controls and can let an agent use broader filesystem capabilities than reviewers or users would expect.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user-facing prompt in Step 1 is written entirely in Chinese, which imposes a specific language on the interaction without any opt-in or alternative. The file does not state that the skill is region-specific or provide a choice of language, so this is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill asks users to paste full source content or provide a file path, but gives no warning not to include secrets, internal documents, customer data, or other sensitive material. Because this skill is designed for broad content transformation and redistribution, users may accidentally expose confidential information and the model may propagate it into multiple outputs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code hard-codes Chinese-language output for specific platforms, as shown by the function purpose strings and Chinese text templates. The policy requires avoiding forced language or locale constraints unless the user is given a choice or the constraint is clearly justified; here, no such opt-in or justification is present in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The supported platforms table specifies that wechat and xiaohongshu outputs are 'Chinese', which imposes a language requirement in the skill description. Because the README does not mention that users can choose another language or opt into this locale constraint, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.