Back to skill

Security audit

system-monitor-tool

Security checks for vulnerabilities and agentic risk

Overview

This local system-monitoring skill is mostly coherent, but it has an argument-handling bug that can allow unintended command execution and it exposes more local host details than users may expect.

Review before installing. Use only in environments where local system telemetry and process details are acceptable to expose, and fix the process argument validation before allowing user-controlled values such as --top counts.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/monitor.sh:153
Finding

Arbitrary Command Execution Through Unvalidated Arithmetic Expression

Content
View full analysis
Remediation
View remediation
&2 return 2 fi if [[ ! $3 =~ ^[0-9]+$ ]]; then echo "Error: --top must be a positive integer" >&2 return 2 fi top=$3 if (( 10#$top < 1 || 10#$top > 100 )); then echo "Error: --top must be between 1 and 100" >&2 return 2 fi fi echo "📊 Top $top Processes by CPU" echo "" case "$(get_os)" in macos|linux) ps aux --sort=-%cpu | head -n "$((10#$top + 1))" ;; esac } ``` Additional hardening measures: 1. Treat every command-line argument as untrusted input. 2. Validate values before placing them in arithmetic, test, or shell-evaluation contexts. 3. Use an explicit option parser rather than relying on positional assumptions. 4. Bound the process count to prevent excessive output or resource consumption. 5. Add regression tests containing malformed arithmetic expressions, command substitutions, negative values, very large values, and the documented `--top` syntax. 6. Run the skill under a least-privileged account so any future command-execution defect has reduced impact. ]]>
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger phrase "system status" / "how's the system" is broad conversational language that can match ordinary user requests not explicitly asking to invoke this skill. In an agent routing context, ambiguous triggers can cause unintended execution of local monitoring commands and disclosure of sensitive host telemetry such as uptime, network state, or process information.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Multiple phrases like "disk space," "network status," "connection info," and especially "what's using CPU" are underspecified and overlap with common support or conceptual questions. This increases the chance the agent will invoke shell commands on the host when the user may have meant a remote system, an application, or a general explanation, leading to unintended data exposure about processes, storage, and network environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The disk command does more than report disk usage: du -sh ~/* | sort -hr | head -5 enumerates the largest folders in the home directory, which can disclose private directory names and aspects of a user's files or activities. That exceeds the declared 'disk space/resource usage' purpose and creates unnecessary data exposure in a monitoring skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The processes command exposes a full process list (ps aux) including command lines and owning users, which goes beyond the stated purpose of resource monitoring and can reveal sensitive operational details such as running apps, internal tooling, file paths, and arguments. In an agent skill context, this broad host introspection increases privacy and reconnaissance risk because a user asking for 'system status' could obtain unrelated process information from the machine hosting the agent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.