Back to skill

Security audit

Davos

Security checks for vulnerabilities and agentic risk

Overview

The skill is for making HTML posters, but its preview workflow can expose the user's entire Desktop over an unauthenticated local web server.

Install only if you are comfortable with an agent creating files on your Desktop and starting a local web server. Prefer changing the workflow to use a temporary folder containing only the poster, bind the server to 127.0.0.1, stop the exact server process after screenshotting, and avoid storing sensitive files on the served Desktop while it runs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:20
Finding

Unauthenticated Network Exposure of the Desktop Directory

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20-23 and 67-70
Vulnerability Type: Unrestricted local file serving and excessive directory exposure
Risk Level: Medium

Vulnerable Code

bash
cd ~/Desktop
python3 -m http.server 9999

The same unsafe operation is repeated in the quick command:

bash
# Start the server
cd ~/Desktop && python3 -m http.server 9999

# Stop the server
pkill -f "python3 -m http.server 9999"

Technical Analysis

The instructions start Python's basic HTTP server with the entire ~/Desktop directory as its document root. By default, python3 -m http.server 9999 listens on all available network interfaces rather than restricting access to the loopback interface.

Python's basic HTTP server does not provide authentication or authorization. It can also generate directory listings when an index file is absent. Consequently, any host capable of reaching port 9999 may enumerate and download readable files stored on the Desktop, including files unrelated to the generated poster.

Serving the entire Desktop violates least-exposure principles because the workflow only requires access to one generated HTML file from a browser running on the same machine. The exposure may last longer than intended if the user omits cleanup, the agent is interrupted, or the broad pkill command fails to identify the relevant process.

Attack Path

  1. The agent creates a poster file under ~/Desktop.
  2. The agent changes the working directory to ~/Desktop.
  3. It runs python3 -m http.server 9999, which listens on reachable interfaces and exposes the current directory without authentication.
  4. An attacker on the same network, or another system with access to the host and port, connects to http://<target-host>:9999/.
  5. The server returns a directory listing if no index file suppresses it.
  6. The attacker identifies and requests unrelated Desktop ...[truncated 793 chars]
Remediation
View remediation

Remediation Suggestions

  1. Create a dedicated temporary directory containing only the generated poster rather than serving ~/Desktop.
  2. Bind the preview server explicitly to the loopback interface:
    bash
    preview_dir="$(mktemp -d)"
    cp "/path/to/poster.html" "$preview_dir/poster.html"
    python3 -m http.server 9999 --bind 127.0.0.1 --directory "$preview_dir"
    
  3. Store and terminate the exact server process ID instead of using the broad pattern-based command pkill -f, which can affect unrelated matching processes:
    bash
    python3 -m http.server 9999 --bind 127.0.0.1 --directory "$preview_dir" &
    server_pid=$!
    
  4. Use a shell cleanup trap or equivalent guaranteed-finalization mechanism to terminate the server and remove the temporary directory:
    bash
    cleanup() {
      kill "$server_pid" 2>/dev/null || true
      rm -rf -- "$preview_dir"
    }
    trap cleanup EXIT INT TERM
    
  5. Keep the server active only for the minimum time needed to capture the screenshot.
  6. Where feasible, open the generated file directly through a local file:// URL or use a browser mechanism that does not require an HTTP listener.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation criteria are broad enough to match generic user requests like 'make a poster,' which can cause the skill to run in situations where the user did not explicitly consent to local file creation, server startup, and screenshot-based workflows. In this context, overbroad triggering increases the chance of unnecessary system actions and unexpected exposure of local content via a localhost web server.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to create files on the Desktop and launch a local HTTP server without an explicit warning or consent gate, which can modify the user's environment and expose local files over localhost. While intended for convenience, these actions create avoidable risk if triggered automatically, especially because serving the Desktop can unintentionally make unrelated files accessible to local processes or browser requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.