Back to skill

Security audit

Auth Guard

Security checks for vulnerabilities and agentic risk

Overview

The skill has a legitimate auth-check purpose, but its included script can send a local API token to any caller-supplied HTTPS URL.

Review this skill before installing. It is useful only if you keep probe URLs and credential files tightly controlled; do not run its auth_check.sh with real tokens until it enforces a fixed allowlist of service hosts and canonical credential paths. Also review any proposed HEARTBEAT.md, AGENTS.md, or workspace/.pi/ changes because they affect future agent behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/auth_check.sh:13
Finding

Caller-Controlled HTTPS Endpoint Can Receive Retrieved Credentials

Content
View full analysis
&2; exit 2 ;; esac done ``` ```bash if [[ ! "$URL" =~ ^https:// ]]; then echo "AUTH_ERROR invalid_url=https_required" exit 2 fi ``` ```bash get_key() { local from_env="${!ENV_VAR:-}" if [[ -n "$from_env" ]]; then printf '%s' "$from_env" return 0 fi if [[ -f "$CRED_FILE" ]]; then python3 - "$CRED_FILE" <<'PY' import json, sys p = sys.argv[1] try: d = json.load(open(p, 'r', encoding='utf-8')) except Exception: print('', end='') raise SystemExit(0) for k in ('apiKey', 'api_key', 'token', 'accessToken'): v = d.get(k) if isinstance(v, str) and v.strip(): print(v.strip(), end='') break PY return 0 fi printf '' } KEY="$(get_key || true)" if [[ -z "$KEY" ]]; then echo "AUTH_MISSING service=$SERVICE env=$ENV_VAR cred_file=$CRED_FILE" exit 0 fi STATUS=$(curl -sS -o /dev/null -w "%{http_code}" --max-time "$TIMEOUT" -H "Authorization: Bearer $KEY" "$URL" || true) ``` ### Technical Analysis The script accepts both the credential source and probe URL from its caller. URL validation only verifies that the supplied string starts with `https://`. It does not verify that the destination hostname is associated with the service named by `--service`, nor does it enforce an allowlist of trusted API hosts. After retrieving a token from the caller-selected environment variable or credential file, the script places that token in an `Authorization: Bearer` header and sends it to the supplied URL. HTTPS pr ...[truncated 1670 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth_check.sh:36
Finding

Lexical Credential-Path Check Can Be Bypassed with Traversal or Symbolic Links

Content
View full analysis
Remediation
View remediation
/credentials.json ``` Do not accept an arbitrary path when a deterministic path can be constructed internally. 2. Canonicalize both the allowed directory and requested file with `realpath` before opening the file. 3. Verify that the canonical file remains strictly beneath the canonical service directory using path-aware comparison rather than textual prefix matching. 4. Reject paths containing traversal components before canonicalization as defense in depth. 5. Reject symbolic links where operationally feasible, or open files using mechanisms that prevent symlink following. 6. Verify that the credential file is a regular file, is owned by the expected user, and is not group- or world-writable. Consider requiring mode `0600`. 7. Replace generic field discovery with a service-specific schema to prevent unrelated JSON files from being interpreted as credential stores. 8. Avoid printing the complete credential path in routine output if it may reveal sensitive local filesystem structure. A hardened approach should resemble: ```bash ALLOWED_DIR="$(realpath "$HOME/.config/$SERVICE")" || { echo "AUTH_ERROR invalid_service_directory" exit 2 } RESOLVED_FILE="$(realpath "$CRED_FILE")" || { echo "AUTH_ERROR invalid_cred_file" exit 2 } case "$RESOLVED_FILE" in "$ALLOWED_DIR"/*) ;; *) echo "AUTH_ERROR untrusted_cred_path" exit 2 ;; esac if [[ ! -f "$RESOLVED_FILE" || -L "$CRED_FILE" ]]; then echo "AUTH_ERROR invalid_cred_file" exit 2 fi ``` The service value must also be validated against a fixed allowlist before using it to construct a directory path. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/contract.md (reported line 9)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/examples.md (reported line 8)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/examples.md (reported line 17)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/examples.md (reported line 34)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/examples.md (reported line 52)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/snippets.md (reported line 18)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/snippets.md (reported line 32)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/snippets.md (reported line 38)May include surrounding context.

md
- Protected endpoint: `GET /api/v1/feed?sort=new&limit=10`
- Public fallback: `GET /api/v1/posts?sort=new&limit=10`
- Env var: `MOLTBOOK_API_KEY`
- Credentials file: `~/.config/moltbook/credentials.json`

Probe:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill explicitly instructs use of shell commands and file-based credential access, but it does not declare any tool or permission scope. This creates an authorization gap where an agent may invoke shell/file capabilities without clear least-privilege boundaries, increasing the risk of unintended command execution or secret exposure during skill use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The examples instruct users to pass API tokens and credential-file paths into an auth-check workflow without any warning about secret handling, storage hygiene, or the fact that the probe will contact external services using those credentials. In a security-sensitive skill about authentication, omission of those cautions materially increases the chance of credential misuse, accidental disclosure, or unsafe copy/paste into logs and shell history.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 22)May include surrounding context.

md
## Example B: GitHub API

- Protected endpoint: `GET https://api.github.com/user`
- Public fallback: `GET https://api.github.com/rate_limit`
- Env var: `GITHUB_TOKEN`
- Credentials file: `~/.config/gh/hosts.yml` (if available) or a local JSON shim used by your agent

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 23)May include surrounding context.

md
## Example B: GitHub API

- Protected endpoint: `GET https://api.github.com/user`
- Public fallback: `GET https://api.github.com/rate_limit`
- Env var: `GITHUB_TOKEN`
- Credentials file: `~/.config/gh/hosts.yml` (if available) or a local JSON shim used by your agent

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 32)May include surrounding context.

md
## Example B: GitHub API

- Protected endpoint: `GET https://api.github.com/user`
- Public fallback: `GET https://api.github.com/rate_limit`
- Env var: `GITHUB_TOKEN`
- Credentials file: `~/.config/gh/hosts.yml` (if available) or a local JSON shim used by your agent

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This shell script reads a credential from an environment variable or credential file and sends it to a remote URL in an Authorization header. While the operation is core to an auth check, the script provides no explicit user-facing notice that credential material will be transmitted over the network.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.