Back to skill

Security audit

Bundle

Security checks for vulnerabilities and agentic risk

Overview

This bundle skill mostly matches its stated purpose, but its script has unsafe argument handling that can cause unintended file operations, including destructive behavior.

Review this skill before installing. It does not show exfiltration or hidden persistence, but it should not be used on important directories or untrusted archives until the argument handling is fixed and extraction validates archive paths.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:96
Finding

Destructive find Expression Injection Through Off-by-One Argument Handling

Content
View full analysis
" find "$2" -type f -exec sha256sum {} \; 2>/dev/null } ``` The relevant command dispatcher is: ```bash main() { local cmd="${1:-help}" case "$cmd" in create) shift; cmd_create "$@" ;; manifest) shift; cmd_manifest "$@" ;; verify) shift; cmd_verify "$@" ;; size) shift; cmd_size "$@" ;; list) shift; cmd_list "$@" ;; extract) shift; cmd_extract "$@" ;; help) cmd_help ;; version) cmd_version ;; *) die "Unknown command: $cmd (try help)" ;; esac } ``` ### Technical Analysis The dispatcher removes the command name with `shift` before forwarding the remaining arguments to `cmd_manifest`. Therefore, the directory supplied using the documented command syntax is available as `$1`. However, `cmd_manifest` incorrectly reads `$2`. This causes the documented invocation to fail and allows a second, attacker-controlled argument to be passed as the first effective operand to `find`. Because the script does not use end-of-options handling or otherwise validate the value, an option-like value can be interpreted as a `find` expression rather than as a directory. In particular, `-delete` is a destructive GNU `find` action. An invocation such as: ```bash scripts/script.sh manifest ignored -delete ``` results in `cmd_manifest` evaluating: ```bash find "-delete" -type f -exec sha256sum {} \; ``` On implementations that default to the current directory when no explicit starting path is present, `-delete` is interpreted as an expression. This can recursively delete entries beneath the current working directory. The precise behavior may vary between `find` implementatio ...[truncated 1837 chars]
Remediation
View remediation
" local dir="$1" [ -d "$dir" ] || die "Directory does not exist: $dir" find -- "$dir" -type f -exec sha256sum -- {} \; } ``` Apply the same argument-index correction to every handler: - Single-argument commands should consume `$1`. - Two-argument commands should consume `$1` and `$2`. - Commands should validate the exact number of arguments before operating. - Commands should use their validated local variables rather than accessing positional parameters again. - External utilities should receive `--` before attacker-controlled path operands when the utility supports it. - Option-like paths should be rejected or normalized for utilities that do not support `--`. - Automated tests should cover documented invocations, missing and extra arguments, paths containing spaces, and paths beginning with `-`. - Extraction and archive operations should also validate source and destination paths before modifying the filesystem. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

create

bash
scripts/script.sh create <dir output>

manifest

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 9)May include surrounding context.

sh
DATA_DIR="$HOME/.local/share/bundle"
mkdir -p "$DATA_DIR"

# bundle — Package directories into distributable bundles with manifest
# bundle — Package directories into distributable bundles with manifest
# bundle — Package directories into distributable bundles with manifest
# bundle — Package directories into distributable bundles with manifest

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description focuses on creating distributable bundles, verifying contents, and generating checksums. The extract command performs archive unpacking and writes arbitrary archive contents into a target directory, which is a materially broader file-manipulation capability than packaging or verification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The extract command unpacks arbitrary tar contents directly to a target directory without any warning, validation, or safety checks. If a user extracts an untrusted archive, malicious entries such as ../ paths, absolute paths, or symlink-based payloads could overwrite files outside the intended destination or place dangerous content on disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes an extract command and states that data is stored in ~/.local/share/bundle/, both of which affect the user's filesystem. Under the markdown-specific warning rule, the skill description should disclose behaviors that may impact user data or system state, but no caution or note is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.