Back to skill

Security audit

pms-worklog

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims, but it can automatically submit company worklog records and leave sensitive PMS screenshots behind without enough user control.

Install only if you are comfortable with a script logging into your PMS account and submitting worklog entries automatically. Review and edit the date, work item, hours, and description before every run, avoid running it with privileged OS permissions, remove --no-sandbox if possible, prefer a pinned local Playwright dependency, and delete or disable screenshots if they may contain company data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Global Playwright Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 28-29
Vulnerability Type: Unpinned, globally installed third-party dependency
Risk Level: Medium

Vulnerable code:

bash
npm install -g playwright
playwright install chromium

Technical Analysis

The installation instructions retrieve the latest available Playwright package from the configured npm registry without specifying a reviewed version or providing a lockfile. The package is also installed globally, increasing its potential effect on the user environment and allowing the same mutable installation to be shared by unrelated projects.

npm installation may execute package lifecycle scripts. Consequently, compromise of the package, one of its transitive dependencies, the registry account, or the registry configuration could result in attacker-controlled code executing with the privileges of the user performing the installation. The subsequent browser installation also downloads executable browser components without project-level version controls documented by this Skill.

This finding does not establish that the current Playwright package is malicious. The vulnerability is the unsafe dependency acquisition and installation practice.

Attack Path

  1. An attacker compromises a relevant npm package release, maintainer account, transitive dependency, or registry used by the operator.
  2. The operator follows the Skill documentation and runs npm install -g playwright without a pinned version.
  3. npm resolves and downloads the attacker-controlled mutable release.
  4. Malicious package contents or lifecycle scripts execute during installation under the operator's account.
  5. The attacker may access data available to that account, alter globally installed tooling, or place additional malicious files within writable locations.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running ...[truncated 507 chars]

Remediation
View remediation

Remediation Suggestions

  • Create a project-local package.json and pin Playwright to a specifically reviewed version.
  • Commit a generated lockfile and use npm ci so installations follow the locked dependency graph.
  • Avoid global package installation; invoke the project-local dependency from the Skill.
  • Configure npm to use a trusted registry and retain package-integrity verification.
  • Review dependency updates before changing the pinned version, and use automated dependency and vulnerability scanning.
  • Document a reproducible browser installation process tied to the pinned Playwright release.
  • Avoid running package installation with administrative privileges.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/fill_worklog.js:5
Finding

Chromium Process Is Launched with Its Security Sandbox Disabled

Content
View full analysis

Vulnerability Details

File Location: scripts/fill_worklog.js, lines 5-8
Vulnerability Type: Disabled browser process isolation
Risk Level: Medium

Vulnerable code:

javascript
const browser = await chromium.launch({
    channel: 'chrome',
    headless: false,
    args: ['--disable-gpu', '--no-sandbox', '--disable-dev-shm-usage']
});

Technical Analysis

The script explicitly supplies Chrome's --no-sandbox argument. This disables a principal Chromium defense-in-depth boundary intended to isolate browser renderers and other processes from the host operating system.

The browser navigates to and processes remote PMS web content while operating in an authenticated session. If that site, one of its loaded resources, or an upstream dependency is compromised, malicious content could attempt to exploit a browser vulnerability. With sandboxing disabled, a successful browser exploit may require fewer additional steps to access resources available to the Node.js process and its operating-system user.

Disabling the sandbox does not itself provide immediate code execution, and exploitation still requires malicious web content and a suitable browser vulnerability. It nevertheless substantially weakens containment without being necessary for the documented desktop workflow.

Attack Path

  1. An attacker compromises the PMS application, a resource loaded by it, or a network endpoint trusted by the application.
  2. The automation opens the affected content in Chrome with --no-sandbox.
  3. The content triggers a compatible Chromium renderer or browser vulnerability.
  4. Because Chromium sandbox isolation is disabled, the exploit gains broader access under the browser process user's operating-system privileges.
  5. The attacker may read or modify user-accessible files, inspect process-accessible data, interfere with the automated authenticated session, or execute additional commands subject to the user's ...[truncated 650 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove --no-sandbox and launch Chrome with its default sandbox protections enabled:
    javascript
    const browser = await chromium.launch({
        channel: 'chrome',
        headless: false,
        args: ['--disable-gpu', '--disable-dev-shm-usage']
    });
    
  • Fail closed if the environment cannot initialize the Chromium sandbox instead of silently weakening browser isolation.
  • Keep Chrome and Playwright updated to reviewed security-patched versions.
  • Run the automation under a dedicated, least-privileged operating-system account.
  • If sandbox disabling is unavoidable in a specialized environment, execute the entire Skill inside a hardened, non-privileged container or virtual machine with a read-only filesystem, restricted mounts, dropped capabilities, and narrowly limited network access.
  • Do not run this automation as root or an administrator.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a local Node/Playwright script and explicitly documents reading credentials from environment variables, but it declares no tool scope or permission boundaries. In an agent setting, that means the skill can access sensitive local environment data without clear disclosure or least-privilege controls, increasing the risk of credential exposure or unintended execution context abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code reads sensitive credentials from environment variables and falls back to literal placeholder username/password values, then submits them to a remote PMS site. While there are status logs for login progress, there is no explicit warning to the user that the script accesses and transmits account credentials during execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The automation captures screenshots of login-failure states and authenticated PMS pages, which may contain account identifiers, work items, business data, and other sensitive enterprise information. Because screenshots are written to disk in a user workspace, they create persistent artifacts that can be accessed later or exfiltrated outside the minimum functionality of worklog submission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script performs a remote write to the PMS system by clicking the final confirmation button without any explicit user confirmation, dry-run mode, or pre-submit review. In this context, that can create incorrect or unauthorized worklog records at scale, especially because the script is designed for batch multi-day entry.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description and the entire README-style instructions are written only in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to Chinese-speaking users. Under the policy, a forced language/locale without user opt-in can be a natural-language policy violation unless clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

All console output and interaction assumptions are written in Chinese, which imposes a specific language/locale on users without any opt-in or alternative. This can violate organizational language-choice policies when skills are expected to accommodate user preference.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script enumerates button text and logs broad UI details from an authenticated PMS page that are not strictly necessary to fill a worklog. In an enterprise system, this can expose internal workflow names, controls, or page structure into logs, expanding data disclosure beyond the declared automation purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

Keeping the authenticated PMS session open for two minutes after completion unnecessarily increases the window in which a local attacker, shoulder surfer, or other process could interact with the live session. This is especially risky because the browser is launched non-headless and remains usable after the write action has finished.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.