Back to skill

Security audit

Resignation Letter

Security checks for vulnerabilities and agentic risk

Overview

This skill generates resignation-related text locally and shows no evidence of hidden execution, exfiltration, or privileged behavior.

Install only if you are comfortable with a local resignation-document helper that includes broader Chinese-language offboarding guidance; review generated text before using it, especially legal, benefits, timing, and account-handover sections.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Note
Location
scripts/resign.sh:3
Finding

Unquoted Shell Expansion Enables Word Splitting and Pathname Disclosure

Content
View full analysis
/dev/null || true; INPUT="$*" python3 -c ' import sys from datetime import datetime,timedelta cmd=sys.argv[1] if len(sys.argv)>1 else "help" inp=" ".join(sys.argv[2:]) # ... ' "$CMD" $INPUT ``` The complete vulnerable operation is the final command invocation: ```bash ' "$CMD" $INPUT ``` ### Technical Analysis The script initially stores command-line input in `INPUT` using `"$*"`, but later expands `$INPUT` without quotation marks. Bash consequently applies word splitting and pathname expansion to the value before passing it to Python. Input containing wildcard characters such as `*`, `?`, or bracket expressions may therefore be replaced by matching filenames from the script's current working directory. Input boundaries are also lost, so quoted multiword values are reconstructed and split again. Shell operators embedded in the variable are not reparsed as shell syntax, so this issue does not directly provide arbitrary command execution. However, it can disclose local filenames through generated output, alter argument semantics, and produce unexpected failures. ### Attack Path 1. An attacker controls or influences an argument passed to `scripts/resign.sh`. 2. The attacker includes a pathname expansion pattern, for example: ```bash scripts/resign.sh generate '*' ExampleCorp 2 ``` 3. `INPUT` contains the literal supplied arguments. 4. At line 45, unquoted `$INPUT` is subject to pathname expansion in the current directory. 5. Matching local filenames are passed to the embedded Python program. 6. The Python program joins and parses those expanded values, potentially including local filenames in the generated resignation letter or causing values to be assigned to unintended fields. ### Impact Assessment The issue executes with the ...[truncated 559 chars]
Remediation
View remediation
/dev/null || true python3 -c ' import sys from datetime import datetime, timedelta cmd = sys.argv[1] if len(sys.argv) > 1 else "help" inp = " ".join(sys.argv[2:]) # ... ' "$CMD" "$@" ``` Additional hardening measures: 1. Validate the expected argument count separately for every command. 2. Parse `weeks` using explicit validation and return a controlled error for nonnumeric input. 3. Avoid converting structured command arguments into a single whitespace-delimited string. 4. Add tests using spaces and wildcard characters such as `*`, `?`, and `[a-z]`. 5. Run ShellCheck and address warnings such as SC2086 for unquoted expansions. ]]>

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:85
Finding

Unquoted Positional Parameters Permit Pathname Expansion in Letter Generation

Content
View full analysis
" printf 'Dear Manager,\n\nI, %s, hereby resign from my position at %s.\nMy last day will be %s.\n\nSincerely,\n%s\n' $2 $3 $4 $2 } cmd_formal() { local name="${2:-}" local company="${3:-}" [ -z "$name" ] && die "Usage: $SCRIPT_NAME formal " cmd_create $2 $3 TBD } ``` The vulnerable expansions are: ```bash printf '...' $2 $3 $4 $2 cmd_create $2 $3 TBD ``` ### Technical Analysis The positional parameters supplied to `printf` and `cmd_create` are expanded without quotation marks. Bash therefore performs word splitting and pathname expansion on attacker-influenced values. For example, an argument containing `*` can expand into every matching entry in the current directory. This can cause local filenames to become additional `printf` arguments or additional function parameters. Because the format string is fixed, this is not a format-string injection vulnerability, and shell metacharacters produced by variable expansion are not reinterpreted as executable shell syntax. The functions also incorrectly begin reading arguments at `$2` even though `main` shifts the command name before dispatch: ```bash create) shift; cmd_create "$@" ;; formal) shift; cmd_formal "$@" ;; ``` This positional mismatch causes the first supplied value to be skipped and makes the documented interface unreliable. Combined with unquoted expansion, it increases the likelihood of malformed output and unpredictable parameter assignment. ### Attack Path 1. An attacker controls a name, company, or date supplied to the documented `create` or `formal` command. 2. The attacker supplies a value contain ...[truncated 1372 chars]
Remediation
View remediation
" printf 'Dear Manager,\n\nI, %s, hereby resign from my position at %s.\nMy last day will be %s.\n\nSincerely,\n%s\n' \ "$name" "$company" "$last_day" "$name" } cmd_formal() { local name="${1:-}" local company="${2:-}" [ -n "$name" ] && [ -n "$company" ] || die "Usage: $SCRIPT_NAME formal " cmd_create "$name" "$company" "TBD" } ``` Apply the same rules throughout the script: 1. Use named local variables instead of repeatedly accessing positional parameters. 2. Quote every variable used as a command argument unless splitting is explicitly required. 3. Validate every mandatory parameter, not only the first checked value. 4. Replace single-quoted output that unintentionally prints literal variables, such as the timeline and casual command output, with safe `printf` calls. 5. Add regression tests for names and companies containing spaces, wildcard characters, and leading hyphens. 6. Run ShellCheck in continuous integration and treat unquoted-expansion warnings as failures. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description covers only professional resignation letter generation from templates. While the code does include that functionality, its actual scope is materially broader: it also generates handover documentation, interview prep content, offboarding checklists, farewell notes, and strategic timing/advice for resigning. These are substantive user-facing capabilities beyond a supporting implementation detail, so the description understates the skill's true behavior. Declared permissions being empty is consistent with the code, which only formats and prints text locally.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

create

bash
scripts/script.sh create <name company last_day>

template

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code file contains user-facing natural-language output and descriptions exclusively in Chinese, starting with the module docstring. The skill does not offer users an opt-in language/locale choice or explain that it is intentionally limited to a Chinese-speaking or region-specific context, which can violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description is narrowly scoped to generating professional resignation letters from templates. However, the implementation includes several additional resignation-support functions beyond letter generation, substantially expanding the behavior into broader career-transition guidance and document generation.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
80% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 9)May include surrounding context.

sh
DATA_DIR="$HOME/.local/share/resignation-letter"
mkdir -p "$DATA_DIR"

#
#
#
#

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file is natural-language guidance, and all headings and instructions are presented only in Chinese. Under the policy rule, forcing a specific language without user opt-in is a language/locale policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation advertises operational capabilities well beyond the skill's declared purpose of generating resignation letters, including timing analysis, interview prep, handover generation, checklists, and farewell messages. This scope mismatch can mislead users and downstream agents about what the skill is authorized or expected to do, increasing the risk of unintended invocation patterns, unsafe delegation, or hidden functionality being introduced without clear review boundaries.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.