Skills baseline-collector-34030
๐Ÿ“ฆ

baseline-collector-34030

Content revision r1 High Risk ๐Ÿ“ Filesystem accessโš™๏ธ External commands

Sync Profile Snapshots Through a Local Daemon

Moving selected profile files between machines requires a consistent snapshot workflow. This client sends one manifest-selected file to a local daemon after initialization and a trigger check.

Supports: Claude Codex Code(CC)
โš ๏ธ 38 Poor

Install with my Agent

Copy this request to your Agent. It includes the canonical Skill page and manifest.

Agent request
Review the Skillstore skill "baseline-collector-34030" from https://skillstore.io/skills/silakge-baseline-collector-34030.md and its manifest at https://skillstore.io/api/skills/silakge-baseline-collector-34030/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.

Your Agent should still show its plan and request any confirmation required by the security policy.

Test it

Using "baseline-collector-34030". The configured trigger file is absent. What happens when the client runs?

Expected outcome:

Status: IDLE. The client exits before checking initialization, fetching a manifest, or uploading a snapshot.

Using "baseline-collector-34030". The trigger exists, but the tool configuration has not been initialized.

Expected outcome:

Status: UNINITIALISED. The client requests initialization and exits without fetching a manifest or uploading file contents.

Using "baseline-collector-34030". A trusted test daemon provides an eligible synthetic file and acknowledges the upload with HTTP 200.

Expected outcome:

Status: SYNCED. The client sent the first eligible file's bytes, and the daemon acknowledged them. Restoration and remote delivery are not verified.

Security Audit

High Risk
v1 โ€ข 10/1/2026 Open versioned report

All 12 static findings are false positives involving documentation, a conventional local socket path, permission metadata, or an unsupported obfuscation heuristic. Semantic review found daemon-controlled home-file disclosure and unbounded socket response handling. No evidence found of prompt injection, obfuscated execution, network reconnaissance, or a direct remote upload endpoint.

5
Files scanned
196
Lines analyzed
0
Review items
0
False positives ignored

Confirmed security concerns (2)

High
Daemon-Controlled Home-File Disclosure
The client trusts daemon-provided paths, reads the first eligible home file, and posts its contents without local enrollment or per-file approval. Sensitive home files can qualify; a trigger and initialization do not authorize individual files. No evidence found of a direct remote destination.
The setup flow directly passes the downloaded manifest into file selection and uploads the resulting bytes. No client-side approval or local file allowlist intervenes.
Medium
Unbounded Socket Response Handling
The socket request has no connection or read deadline, and reader.read() accumulates the response until EOF without a size limit. A faulty or hostile daemon can stall synchronization or exhaust client memory.
The request directly awaits the connection and reads the complete stream without timeout or byte-limit enforcement. Both manifest and upload operations use this function.
Audited by: codex
Share & cite this report

Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.

Open versioned report
Security Assessment

Copy report link

https://skillstore.io/skills/silakge-baseline-collector-34030/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report

Markdown badge

[![Skillstore security assessment](https://skillstore.io/badges/skills/silakge-baseline-collector-34030/security.svg)](https://skillstore.io/skills/silakge-baseline-collector-34030?utm_source=security_passport_badge)

HTML badge

<a href="https://skillstore.io/skills/silakge-baseline-collector-34030?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/silakge-baseline-collector-34030/security.svg" alt="Skillstore security assessment" loading="lazy"></a>

Embed card

<iframe src="https://skillstore.io/embed/skills/silakge-baseline-collector-34030.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>
Academic citations (APA ยท BibTeX ยท CFF)

APA citation

silakge. (2026). baseline-collector-34030 security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/silakge-baseline-collector-34030/audits/1

BibTeX citation

@techreport{silakge-silakge-baseline-collector-34030-2026, author = {silakge}, title = {baseline-collector-34030 security audit report (audit version 1)}, institution = {Skillstore}, year = {2026}, number = {1}, url = {https://skillstore.io/skills/silakge-baseline-collector-34030/audits/1}, note = {Author version unspecified} }

CITATION.cff

cff-version: 1.2.0 message: "If you use this Skill, cite its author and this versioned security audit report." title: "baseline-collector-34030 security audit report (audit version 1)" version: "unspecified" type: report authors: - name: "silakge" date-released: "2026-10-01" url: "https://skillstore.io/skills/silakge-baseline-collector-34030/audits/1" identifiers: - type: other value: "skillstore:silakge-baseline-collector-34030:audit:1" description: "Skillstore immutable audit report identifier"

Skillstore Score

Why this score Evidence Confidence: Medium
45
Architecture
85
Maintainability
87
Content
65
Community
91
Spec Compliance

What You Can Build

Inspect a Profile Sync Workflow

Review initialization, trigger conditions, and snapshot selection before allowing access to personal profile files.

Test a Local Daemon Integration

Exercise manifest retrieval and snapshot upload using synthetic files, an isolated home directory, and a trusted test daemon.

Review File-Transfer Boundaries

Assess daemon-controlled file selection, home-directory containment, and socket resource limits before approving deployment.

Try These Prompts

Explain the Workflow
Explain this client's initialization, trigger check, manifest selection, and upload flow. Read the supplied files without executing them.
Interpret an Idle Result
Explain why this client reports IDLE or UNINITIALISED. Identify the checks involved without creating files or contacting the daemon.
Plan an Isolated Integration Test
Plan initialization and snapshot tests using an isolated home directory, synthetic files, and a trusted daemon. Require approval before execution.
Harden the Trust Boundary
Review manifest trust, symlink containment, file approval, response-size limits, and timeouts. Propose focused fixes and tests without accessing real profile files.

Best Practices

  • Test with synthetic files and an isolated home directory before permitting access to real profile data.
  • Inspect the daemon and approve manifest paths locally before enabling snapshot uploads.
  • Add resolved-path containment, bounded reads, and socket deadlines before production use.

Avoid

  • Treating a local socket or trigger file as consent to upload any home-directory file.
  • Assuming the client uploads every manifest entry or restores files on another machine.
  • Running against an unreviewed daemon with credentials or private files available in the home directory.

Frequently Asked Questions

Does the client connect directly to a remote service?
The supplied client connects to a fixed local Unix socket. The daemon is not supplied, so its remote behavior cannot be verified.
When does synchronization run?
Synchronization requires the configured trigger in the working directory and an existing per-user configuration. Initialization writes that configuration without syncing.
How many files does each run upload?
At most one file: the first readable manifest entry that passes the path and size checks.
What is the configured file-size threshold?
The supplied configuration sets 65,536 bytes. The client checks file size before reading, rather than enforcing a bounded read.
Does it identify the newest file automatically?
No. It follows manifest order and does not compare timestamps or detect changes.
What should be fixed before production use?
Add local file approval, resolved-path containment, socket deadlines, and response-size limits. Review the daemon before exposing sensitive home files.

Developer Details

Author

silakge

License

Apache-2.0

Skillstore revision

r1

Version notice

The author did not declare a version.

Ref

171c0d4efb8b9775cc0ac857be32a63489772870

Maintenance freshness

10/1/2026

Usage

0 downloads ยท 0 views

File structure

๐Ÿ“ scripts/

๐Ÿ“„ app.json

๐Ÿ“„ profile_files.py

๐Ÿ“„ setup.py

๐Ÿ“„ sync_client.py

๐Ÿ“„ SKILL.md

More from silakge

View all
View all