Back to skill

Security audit

Orders

Security checks for vulnerabilities and agentic risk

Overview

This skill coherently manages local order records, with some local data-handling cautions but no hidden, remote, or deceptive behavior found.

Use this only if you are comfortable storing order, customer, pricing, notes, and cancellation data locally in ~/.orders/orders.json. Keep your account and home directory permissions restrictive, consider protecting that file with owner-only permissions, and be careful opening CSV exports in spreadsheet software if order fields can contain untrusted text.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:8
Finding

Order Data Is Created Without Restrictive Filesystem Permissions

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 8–14
Vulnerability Type: Insecure permissions on locally stored sensitive data
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${HOME}/.orders"
ORDERS_FILE="${DATA_DIR}/orders.json"

ensure_data_dir() {
  mkdir -p "${DATA_DIR}"
  if [[ ! -f "${ORDERS_FILE}" ]]; then
    echo '[]' > "${ORDERS_FILE}"
  fi
}

Technical Analysis

The order directory and JSON database are created using the process's ambient umask. The implementation does not explicitly require mode 0700 for the directory or 0600 for the file.

Under a common 022 umask, the resulting directory and file may be readable by other local users, subject to the permissions on parent directories. The database can contain customer names, purchased items, quantities, prices, notes, order status, and cancellation reasons.

The issue does not grant remote access or elevated privileges by itself. Exploitation requires access to another local account or process that can traverse the user's home directory and read the resulting database.

Attack Path

  1. A user invokes any order command, causing ensure_data_dir to create ~/.orders/orders.json.
  2. The process runs with a permissive umask, such as 022.
  3. The directory or database is created with permissions that allow unintended local users to read it.
  4. Another local user or process accesses the file and obtains stored customer and order information.

Impact Assessment

Successful exploitation can disclose all records in the affected user's local order database. The confidentiality impact includes customer identities, purchasing information, prices, free-form notes, status history, and cancellation reasons.

No additional operating-system privileges are obtained. The scope is limited to data available through the affected file's actual permissions and parent-directory traversal settings.

Remediation
View remediation

Remediation Suggestions

Explicitly enforce owner-only permissions instead of relying on the caller's umask:

bash
ensure_data_dir() {
  mkdir -p -m 700 "${DATA_DIR}"
  chmod 700 "${DATA_DIR}"

  if [[ ! -e "${ORDERS_FILE}" ]]; then
    (umask 077; printf '%s\n' '[]' > "${ORDERS_FILE}")
  fi

  chmod 600 "${ORDERS_FILE}"
}

Additional hardening should include:

  • Verify that the data directory and database are owned by the current user.
  • Reject symbolic links before opening or replacing the database.
  • Write updates to an owner-only temporary file in the same directory and atomically rename it.
  • Apply restrictive permissions to existing installations during startup or migration.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:124
Finding

Unescaped CSV Fields Permit Spreadsheet Formula Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 124–127
Vulnerability Type: CSV formula injection and malformed CSV generation
Risk Level: Medium

Vulnerable Code

python
elif fmt == 'csv':
    print('id,customer,item,quantity,unit_price,total,status,created_at')
    for o in orders:
        print(f"{o['id']},{o['customer']},{o['item']},{o['quantity']},{o['unit_price']},{o['total']},{o['status']},{o['created_at']}")

Technical Analysis

User-controlled values, particularly customer and item, are concatenated directly into CSV rows. The implementation does not quote or escape commas, quotation marks, carriage returns, or line feeds, so crafted values can alter the exported row and column structure.

In addition, spreadsheet applications may interpret text beginning with =, +, -, or @ as a formula. An attacker who can influence an order field can therefore place a spreadsheet formula in the exported CSV. Python's string interpolation does not execute that formula; execution occurs later when a victim opens the output in formula-evaluating spreadsheet software.

Exploitability depends on an attacker being able to provide order data and a user subsequently exporting and opening the CSV. The exact effect also depends on the spreadsheet application's security controls and support for external links or other formula functionality.

Attack Path

  1. An attacker supplies a crafted customer or item value when an order is created, such as a value beginning with a spreadsheet formula marker.
  2. The value is stored unchanged in ~/.orders/orders.json.
  3. A user runs scripts/script.sh list --format csv and saves the output as a CSV file.
  4. The exporter writes the attacker-controlled value without CSV escaping or formula neutralization.
  5. The user opens the CSV in spreadsheet software.
  6. If the spreadsheet evaluates the field as a formula, attacker-controlled spreadshee ...[truncated 553 chars]
Remediation
View remediation

Remediation Suggestions

Generate CSV with Python's standard csv module so delimiters, quotation marks, and line breaks are encoded correctly:

python
import csv
import sys

writer = csv.writer(sys.stdout)
writer.writerow([
    'id', 'customer', 'item', 'quantity',
    'unit_price', 'total', 'status', 'created_at'
])

for o in orders:
    writer.writerow([
        o['id'],
        o['customer'],
        o['item'],
        o['quantity'],
        o['unit_price'],
        o['total'],
        o['status'],
        o['created_at'],
    ])

Before writing text intended for spreadsheet consumption, neutralize fields whose first non-whitespace character is =, +, -, or @. A documented policy can prefix such values with an apostrophe or otherwise force them to be treated as text. Apply the policy consistently to every attacker-controlled textual field and add tests covering formula markers, commas, quotation marks, and embedded newlines.

Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
bash scripts/script.sh create <customer> <item> <quantity> <unit_price> [--note <text>]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
bash scripts/script.sh create <customer> <item> <quantity> <unit_price> [--note <text>]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
bash scripts/script.sh create <customer> <item> <quantity> <unit_price> [--note <text>]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
bash scripts/script.sh create <customer> <item> <quantity> <unit_price> [--note <text>]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
bash scripts/script.sh create <customer> <item> <quantity> <unit_price> [--note <text>]

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
bash scripts/script.sh create <customer> <item> <quantity> <unit_price> [--note <text>]

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill advertises commands that write persistent order data to ~/.orders/orders.json, but it declares no permissions or allowed-tools scope. That mismatch reduces transparency about filesystem access and can cause an agent or user to invoke a skill with broader side effects than expected. In this context the behavior appears consistent with the skill’s stated purpose, so the issue is under-declared capability rather than overtly malicious behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The cancel command changes persisted order data by marking an order as cancelled and writing the update to disk. Although it prints a message after completion, there is no pre-action confirmation prompt or user warning in the help text that cancellation is a destructive operation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill stores order records in a persistent file under the user’s home directory, but the description does not clearly warn users about this data retention behavior. This can expose potentially sensitive business or customer information to unexpected local persistence, backups, or other local processes, especially if users assume the operation is transient.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.