Back to skill

Security audit

Data Visualizer

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its data-visualization purpose, but its HTML and SVG export paths can preserve unsafe markup from untrusted CSV files in generated reports.

Review before installing if you plan to process CSV files from other people or automated sources. Terminal-only charting and local CSV/JSON summaries are proportionate, but avoid opening generated HTML or SVG reports from untrusted data until the exporter escapes HTML/XML content and warns before overwriting existing files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:511
Finding

Stored HTML Injection Through Unescaped CSV Content

Content
View full analysis

$(basename "$file")

" >> "$outfile" local first=true while IFS= read -r line; do if $first; then echo "$(echo "$line" | sed 's/,/<\/th>" >> "$outfile" first=false else echo "$(echo "$line" | sed 's/,/<\/td>" >> "$outfile" fi done < "$file" ``` ### Technical Analysis The `to-html` command inserts the input filename and every line of the CSV file directly into an HTML document. The `sed` expressions only replace commas and add table tags; they do not encode HTML-sensitive characters such as `<`, `>`, `&`, `"`, or `'`. Consequently, an attacker-controlled CSV cell can terminate the generated `
/g; s/^//; s/$/<\/th>/')
/g; s/^//; s/$/<\/td>/')
` or `` element and introduce arbitrary HTML. Depending on the browser and payload, injected content can include scripts, event handlers, misleading forms, iframes, or elements that initiate external network requests. The implementation also does not use a standards-compliant CSV parser. Quoted fields, embedded commas, and multiline fields may therefore be processed incorrectly in addition to the security issue. ### Attack Path 1. An attacker creates or modifies a CSV file that contains an HTML payload in a header or data cell, such as an element with an event handler. 2. The attacker convinces a user to process the file with: ```bash scripts/script.sh to-html attacker.csv ``` 3. The command copies the malicious cell into `attacker.html` without HTML encoding. 4. The user opens the generated report in a web browser. 5. The browser interprets the injected value as active markup rather than text. 6. The payload can modify the report, display deceptive content, execute browser-side code ...[truncated 792 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:491
Finding

Stored SVG/XML Markup Injection Through Unescaped Chart Labels

Content
View full analysis
{}'.format( x + bar_w//2, h - 5, lbl[:8])) ``` ### Technical Analysis The `to-svg` command obtains labels from the first column of an input CSV file and interpolates them directly into an SVG `` element. XML-sensitive characters such as `<`, `>`, and `&` are not escaped. An attacker-controlled label can therefore alter the XML structure instead of being represented as literal text. The eight-character truncation does not constitute output encoding or a reliable security boundary: short XML fragments can terminate elements or produce attacker-controlled markup behavior, while malformed fragments can corrupt the generated document. The resulting risk depends on how the SVG is parsed, opened, or embedded. ### Attack Path 1. An attacker creates a CSV file whose first-column labels contain XML or SVG metacharacters and crafted markup fragments. 2. The user processes the file with: ```bash scripts/script.sh to-svg attacker.csv ``` 3. The command inserts each truncated label into an SVG `` element without XML escaping. 4. The generated `attacker.svg` contains attacker-controlled XML syntax or malformed element boundaries. 5. When the file is opened or embedded, the SVG parser interprets the injected characters as markup rather than chart-label text. 6. The attacker can at minimum corrupt or manipulate the rendered chart. Depending on the accepted payload, viewer, and embedding context, injected SVG content may introduce active or externally loaded content. ### Impact Assessment The direct and reliable impact is loss of integrity and trustworthiness of the generated SVG output. An attacker can ...[truncated 505 chars]
Remediation
View remediation
`, `&`, closing tags, entity syntax, quotation marks, and malformed XML fragments. - Verify that these characters are serialized as XML entities and displayed only as literal label text. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises executable capabilities that can read environment data and write files, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens user and platform visibility into what the skill may access or modify, increasing the chance of unintended file writes or exposure of sensitive environment-derived data during execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that history is logged persistently to ~/.local/share/data-visualizer/history.log, but it does not clearly warn users that command usage and potentially sensitive filenames, labels, or data-derived arguments may be stored on disk. In a data-processing skill, this is risky because users may pass business metrics, dataset names, or other sensitive inputs that then remain recoverable from local storage.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description focuses on creating terminal ASCII charts from CSV or JSON data, which implies in-terminal visualization. The code adds non-terminal export functionality by generating .svg and .html files on disk, expanding behavior beyond the stated terminal-only scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The code initializes a persistent data directory under the user's home/XDG data path and defines a history log writer. Persistent local state and logging are not justified by a terminal chart rendering toolkit description, which suggests ephemeral local processing of provided data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The to-svg command creates and writes an SVG file derived from the input filename, which is a file-write operation in a code file. The code only reports success after the write completes and does not provide a prior warning, confirmation prompt, or explanatory comment describing this behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs repeated writes to an output HTML file, which is a safety-relevant file modification operation for a code file. Although it prints a completion message afterward, there is no prior disclosure, confirmation, or explanatory comment/docstring warning that the command will create or overwrite a local file.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.