Back to skill

Security audit

Syscheck

Security checks for vulnerabilities and agentic risk

Overview

SysCheck is advertised as a live system diagnostics tool, but the inspected script mainly stores, searches, and exports user-supplied text in local logs.

Review this skill carefully before installing. It should not be treated as a trustworthy system health checker in its current form: it appears to retain whatever text is passed to many commands and can export that history. Avoid entering secrets, host details, incident notes, tokens, or other sensitive operational data unless the skill is rewritten to match its stated purpose, disclose storage and retention, harden file permissions, and safely encode exports.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Persistent plaintext logging without explicit access restrictions

Content
View full analysis
> "$DATA_DIR/history.log"; } ``` User input is subsequently written to both a command-specific log and the central history log: ```bash else local input="$*" local ts=$(date '+%Y-%m-%d %H:%M') echo "$ts|$input" >> "$DATA_DIR/scan.log" local total=$(wc -l < "$DATA_DIR/scan.log") echo " [Syscheck] scan: $input" echo " Saved. Total scan entries: $total" _log "scan" "$input" fi ``` Equivalent persistent writes appear in the `monitor`, `report`, `alert`, `top`, `usage`, `check`, `fix`, `cleanup`, `backup`, `restore`, `log`, `benchmark`, and `compare` command handlers. ### Technical Analysis The script persistently stores arbitrary command-line arguments under `~/.local/share/syscheck`. It does not set a restrictive `umask`, explicitly create the data directory with mode `0700`, or create log files with mode `0600`. Consequently, effective permissions depend on the invoking process's environment and current `umask`. Under a permissive `umask`, the directory or generated log files may be readable by other local users. The same input is also duplicated into a command-specific log and `history.log`, increasing the number of locations from which sensitive content must be removed. This persistence is especially relevant because `SKILL.md` describes output as being returned to standard output but does not disclose that supplied arguments are retained in plaintext. ### Attack Path 1. A user invokes a command with sensitive text, for example diagnostic information, internal host details, tokens, or other confidential data. ...[truncated 1037 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:64
Finding

Unescaped user-controlled data in JSON and CSV exports

Content
View full analysis
> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" ``` The CSV exporter writes the same values without CSV quoting or spreadsheet-formula neutralization: ```bash local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out" done < "$f" ``` ### Technical Analysis Values stored in the log files originate from user-controlled command arguments. The JSON exporter does not escape quotation marks, backslashes, control characters, or embedded newlines. Crafted input can therefore produce malformed JSON or inject additional JSON properties or records into the exported document. The CSV exporter does not implement RFC 4180 quoting. Commas, quotation marks, carriage returns, and newlines can alter the exported row and column structure. In addition, a value beginning with a spreadsheet formula marker such as `=`, `+`, `-`, or `@` remains executable data when the CSV is opened in formula-evaluating spreadsheet software. Shell command injection is not present in these snippets because the variables are shell-quoted and are not passed to `eval`. The relevant risks are export corruption, data spoofing, and downstream spreadsheet formula execution. ### Attack Path #### CSV formula injection 1. An attacker or untrusted data source causes a user to record a value beginning with a spreadsheet formula marker. 2. The value is persisted in a Syscheck log. 3. The user runs `syscheck expor ...[truncated 1371 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill metadata presents SysCheck as a live system diagnostics tool, but the finding indicates the implemented behavior instead stores arbitrary user input, supports searching/exporting historical logs, and exposes commands that imply system actions without actually performing them. This mismatch is dangerous because users may trust it with sensitive operational data or automation workflows, causing unintended data retention in local files and misleading operators into believing health checks or remediation occurred when they did not.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is presented as a live system health and diagnostics tool, but the implementation only records and replays arbitrary user-supplied text. This mismatch can mislead users or downstream agents into trusting fabricated 'health' output as if it were gathered from the host, enabling deceptive reporting and unsafe operational decisions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The 'When to Use' section uses broad phrases like 'when you need quick syscheck' and 'to automate syscheck tasks in your workflow' without clearly defining activation boundaries or exclusions. For a markdown skill description, this can make invocation conditions feel open-ended rather than tied to specific commands or contexts.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Commands such as 'status', 'backup', 'restore', 'fix', and 'Health check' imply privileged or meaningful system operations, but the code merely appends attacker-controlled input to log files. In an agent setting, this semantic deception is dangerous because an orchestrator or user may believe actions were performed when nothing actually happened.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script accumulates historical user inputs and provides search/export/recent features that expand it into a local data store unrelated to the advertised health-check purpose. That broadens exposure of previously entered potentially sensitive text by making aggregation, retrieval, and copying easy without strong purpose limitation or disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The export function aggregates all stored logs and writes them to export files in JSON, CSV, or TXT formats without warning that sensitive historical inputs may be duplicated into new artifacts. This increases the chance of accidental disclosure, broader file access, backup propagation, or sharing of data users did not realize had been retained.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

User-supplied command arguments are persistently written into per-command logs and a shared history log under the user's home directory, but the interface does not clearly warn about retention. Users may provide hostnames, tokens, incident details, or operational notes expecting ephemeral processing, creating unintended local sensitive-data storage.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.