Back to skill

Security audit

Maintenance

Security checks for vulnerabilities and agentic risk

Overview

This is a local home-maintenance logging skill with disclosed local storage, but users should be aware that saved household details are plaintext and exports are not safely encoded.

Install only if you are comfortable with maintenance notes, schedules, costs, and inventory being stored as plaintext under ~/.local/share/maintenance. Avoid putting secrets or highly sensitive household details into entries, and treat CSV/JSON exports cautiously until escaping and file-permission handling are improved.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:57
Finding

Unescaped User Input Produces Unsafe JSON and CSV Exports

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 57-79
Vulnerability Type: Improper output encoding and spreadsheet formula injection
Risk Level: Medium

Vulnerable Code

bash
case "$fmt" in
    json)
        echo "[" > "$out"
        local first=1
        for f in "$DATA_DIR"/*.log; do
            [ -f "$f" ] || continue
            local name=$(basename "$f" .log)
            while IFS='|' read -r ts val; do
                [ $first -eq 1 ] && first=0 || echo "," >> "$out"
                printf '  {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out"
            done < "$f"
        done
        echo "\n]" >> "$out"
        ;;
    csv)
        echo "type,time,value" > "$out"
        for f in "$DATA_DIR"/*.log; do
            [ -f "$f" ] || continue
            local name=$(basename "$f" .log)
            while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f"
        done
        ;;

Technical Analysis

Maintenance entry values originate from command-line input and are stored without validation. The export implementation subsequently inserts these values directly into JSON and CSV output.

The JSON exporter does not escape quotation marks, backslashes, control characters, or embedded newlines. A value containing characters such as " can terminate the intended JSON string and inject additional JSON properties or otherwise make the export invalid.

The CSV exporter does not apply RFC 4180 quoting. Commas and newlines can create additional cells or records. A value beginning with spreadsheet formula indicators such as =, +, -, or @ may be interpreted as a formula when the resulting CSV file is opened in spreadsheet software.

Attack Path

  1. An attacker supplies or persuades the user to record a crafted maintenance entry containing JSON metacharacters or a spreadsheet formula.
  2. The ...[truncated 1130 chars]
Remediation
View remediation

Remediation Suggestions

  • Generate JSON with a dedicated serializer rather than string interpolation. For example, use jq -n --arg for each field so quotation marks, backslashes, and control characters are escaped correctly.
  • Generate CSV using an implementation that applies RFC 4180 encoding: enclose every field in double quotes and replace each embedded double quote with two double quotes.
  • If exports are expected to be opened in spreadsheet applications, neutralize formula-leading cells according to the target application's guidance, such as prefixing dangerous values with an apostrophe after documenting this transformation.
  • Add regression tests covering quotation marks, commas, backslashes, CR/LF characters, Unicode, and values beginning with =, +, -, or @.
  • Validate generated JSON with a parser and generated CSV with a standards-compliant CSV reader before reporting a successful export.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:6
Finding

Maintenance Data Is Created Without Explicit Owner-Only Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 6-9; representative data write at lines 129-135
Vulnerability Type: Insecure permissions for plaintext sensitive data
Risk Level: Low

Vulnerable Code

bash
DATA_DIR="${HOME}/.local/share/maintenance"
mkdir -p "$DATA_DIR"

_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

Representative creation of a category log:

bash
local input="$*"
local ts=$(date '+%Y-%m-%d %H:%M')
echo "$ts|$input" >> "$DATA_DIR/add.log"
local total=$(wc -l < "$DATA_DIR/add.log")
echo "  [Maintenance] add: $input"
echo "  Saved. Total add entries: $total"
_log "add" "$input"

Technical Analysis

The tool stores household inventory, schedules, costs, reminders, and activity history in predictable plaintext files under ~/.local/share/maintenance. Neither the directory nor the files are assigned explicit owner-only permissions.

Consequently, permissions are inherited from the invoking process's umask. With a commonly used 022 umask, a newly created directory can be mode 0755 and files can be mode 0644. Whether another local account can reach the files also depends on permissions of the parent directories, but the script does not independently enforce its intended privacy boundary.

Existing files with permissive permissions are also reused without correction.

Attack Path

  1. The victim runs the tool with a permissive umask, or the target directory and files already have permissive modes.
  2. The script creates plaintext logs containing maintenance schedules, inventory details, costs, reminders, or other household information.
  3. Another unprivileged local account checks the predictable path under the victim's home directory.
  4. If parent-directory traversal and file-read permissions allow access, that account reads or copies the logs and exported files.

Impact Assessment

This issue ...[truncated 486 chars]

Remediation
View remediation

Remediation Suggestions

  • Set umask 077 before creating the data directory or any files.
  • Create the directory with owner-only permissions, for example:
    bash
    umask 077
    mkdir -p -m 700 "$DATA_DIR"
    chmod 700 "$DATA_DIR"
    
  • Create and retain data files with mode 0600.
  • Correct permissions on existing category logs, history files, and exports with a narrowly scoped command such as:
    bash
    find "$DATA_DIR" -maxdepth 1 -type f -exec chmod 600 {} +
    
  • Refuse to use the data path if it is a symbolic link or is not owned by the current user.
  • Document that the data may contain sensitive household information and is stored locally in plaintext.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill for general activities like 'scheduling repairs, tracking appliance upkeep, inventorying,' which are common user intents and not a specific trigger list. It does not define boundaries, exclusions, or negative examples, so the skill could be invoked in overly broad household or planning contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script silently creates a persistent data directory and logs all user-provided maintenance entries to plaintext files in the user's home directory without any upfront disclosure, consent, retention notice, or access guidance. Because the tool encourages free-form input, users may store sensitive household details, costs, schedules, inventory, or repair history that remain on disk and may later be exposed to other local users, backups, or support processes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a home maintenance tracker for tasks, reminders, repair history, and inventory. The command surface goes materially beyond that scope by adding broad note-taking/reporting categories that are not clearly part of the stated purpose, turning the skill into a more general household logging tool.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

L017 says the skill works entirely offline and that data never leaves the machine. However, the documentation also directs users to external URLs in L006-L007 and L098, which contradicts the absolute offline claim at the documentation level, even though no executable code is shown here.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill states that it performs automatic history and activity logging, but does not prominently warn users up front that their inputs will be persistently stored locally. This can expose sensitive household, appliance, schedule, and inventory information to other local users, backups, or forensic recovery if users assume interactions are ephemeral.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

A maintenance skill can reasonably log repairs, schedules, reminders, inventory, and upkeep history, but arbitrary 'report' and 'tips' logging is not an obvious requirement of that purpose. These commands expand the tool into a generic information store without manifest justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.