Back to skill

Security audit

Court Prep

Security checks for vulnerabilities and agentic risk

Overview

This court-preparation skill appears purpose-aligned, but one bundled script stores potentially sensitive legal entries and command history on disk without clear disclosure or controls.

Review this before installing if you may enter real case details, names, financial amounts, or legal strategy. Prefer using it only with non-sensitive placeholders unless the publisher documents where data is stored, how to disable logging, and how to delete retained records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Undisclosed Persistent Storage of Potentially Sensitive Legal Data

Content
View full analysis
> "$DATA_DIR/history.log"; } ``` ```bash cmd_add() { echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo " Added: $*" _log "add" "${1:-}" } ``` ### Technical Analysis The script creates a persistent application data directory on every invocation. The `add` command appends the complete user-supplied entry to `data.log`, while `_log` records command activity and, for `add`, the first user-supplied argument in `history.log`. Court-preparation input may contain party names, dispute descriptions, financial amounts, dates, or other confidential legal information. This storage behavior is not disclosed in `SKILL.md`, which describes command output as being returned through standard output. The script also does not request consent before retaining data, implement a retention policy, redact sensitive values, or provide effective deletion functionality. The directory and files rely on the process umask rather than explicitly enforcing restrictive permissions. Under a permissive or unusual umask, other local users may be able to read retained information. Backups and filesystem snapshots may also preserve the data beyond the user's expected session. This is a confidentiality and privacy weakness. It does not establish remote code execution, privilege escalation, or system-level persistence. ### Attack Path 1. A user invokes the tool with sensitive case information, for example through `court-prep add`. 2. `cmd_add` expands `$*` and appends the complete entry in plaintext to `$DATA_DIR/data.log`. 3. `_log` also appen ...[truncated 1021 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
74% confidence
Finding

The description prominently includes Chinese-language instructional text and keywords, but does not state that language is selectable or user-driven. This may create a language or locale policy issue if the skill defaults to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This shell skill presents its title, generated legal templates, guidance text, and disclaimer primarily in Chinese, which effectively forces a specific language/locale on users. The file does not offer an opt-in language selection or state that it is intentionally limited to a Chinese legal context as a documented policy exception.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L210 calls run_python with arguments, suggesting the selected command and user input will control behavior. However, the function at L005-L208 invokes python3 << 'PYEOF' without forwarding shell arguments, so the Python code falls back to its default help path at L010-L011 instead of executing the requested subcommand. This is an intent/implementation contradiction in the script structure itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script persistently logs user-supplied arguments to a history file without notice, and several commands accept arbitrary free-form input that may contain sensitive legal, personal, or case-related information. In the context of a 'court-prep' tool, this is more dangerous because users are especially likely to enter confidential notes, names, dates, or strategy details that become silently retained on disk.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest says 'Use when you need court prep capabilities' and includes broad related terms like '诉讼、法院、起诉' without clearly distinguishing exact trigger phrases from general topical keywords. This can make invocation conditions ambiguous and increase the chance of unintended matching in ordinary legal discussions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The 'When to Use' section says to use the skill 'when you need quick court prep' or 'to automate court tasks,' which describes a broad class of situations rather than a specific invocation boundary. Without exclusions or narrower context, the trigger scope remains ambiguous.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The inline documentation and help output should communicate the tool's actual intent, but here they describe it in overly generic terms while the binary name strongly suggests a court-preparation-specific function. This is not just incomplete documentation: it materially diverges from the apparent intended use conveyed by the script identity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.