Back to skill

Security audit

Nia

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a legitimate Nia integration, but it needs review because it can upload broad local code folders and database connection details to Nia and uses an unpinned setup command.

Install only if you trust Nia with the repositories, local files, manifests, saved contexts, and any database material you choose to send. Review folder contents before indexing, avoid uploading secrets, use read-only short-lived database credentials, set restrictive permissions on `~/.config/nia/api_key`, and prefer a pinned or verified setup package instead of `npx ...@latest`.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Remote Package Execution During Setup

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/folders.sh:151
Finding

Reusable Database Credentials Are Transmitted to a Third-Party API

Content
View full analysis
" echo " Env: TABLE, DB_TYPE, COLUMNS" return 1 fi DATA=$(jq -n \ --arg name "$1" --arg conn "$2" --arg query "$3" \ --arg table "${TABLE:-}" --arg dbtype "${DB_TYPE:-}" --arg cols "${COLUMNS:-}" \ '{folder_name: $name, connection_string: $conn, query: $query} + (if $table != "" then {table: $table} else {} end) + (if $dbtype != "" then {db_type: $dbtype} else {} end) + (if $cols != "" then {columns: ($cols | split(","))} else {} end)') nia_post "$BASE_URL/local-folders/from-database" "$DATA" } cmd_preview_db() { if [ -z "$2" ]; then echo "Usage: folders.sh preview-db " echo " Env: TABLE, DB_TYPE, COLUMNS, LIMIT" return 1 fi DATA=$(jq -n \ --arg conn "$1" --arg query "$2" \ --arg table "${TABLE:-}" --arg dbtype "${DB_TYPE:-}" --arg cols "${COLUMNS:-}" \ --arg limit "${LIMIT:-5}" \ '{connection_string: $conn, query: $query, limit: ($limit | tonumber)} + (if $table != "" then {table: $table} else {} end) + (if $dbtype != "" then {db_type: $dbtype} else {} end) + (if $cols != "" then {columns: ($cols | split(","))} else {} end)') nia_post "$BASE_URL/local-folders/preview-db" "$DATA" } ``` The shared client sends these bodies to the Nia API: ```bash BASE_URL="https://apigcp.trynia.ai/v2" nia_post() { nia_curl POST "$1" "$2" | jq '.'; } ``` ### Technical Analysis Database connection strings commonly include reusable usernames, passwords, access tokens, database names, internal hostnames, ports, and TLS parameters. Both database commands place the complete connection string and a caller-con ...[truncated 1669 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/folders.sh:8
Finding

Local Files Are Uploaded Without Secret Filtering or Explicit Content Confirmation

Content
View full analysis
/dev/null || echo "") if [ -n "$content" ]; then files_json=$(echo "$files_json" | jq --arg p "$rel" --arg c "$content" '. + [{path: $p, content: $c}]') fi fi done < <(find "$folder_path" -type f -not -path '*/\.*' -not -name '*.pyc' -not -name '*.o' -not -name '*.so' -print0 2>/dev/null) echo "$files_json" } cmd_create() { if [ -z "$1" ]; then echo "Usage: folders.sh create /path/to/folder [display_name]"; return 1; fi if [ ! -d "$1" ]; then echo "Error: Directory not found: $1"; return 1; fi local name="${2:-$(basename "$1")}" local files_json files_json=$(_scan_folder "$1") local count count=$(echo "$files_json" | jq 'length') echo "Found $count text files to index" if [ "$count" -eq 0 ]; then echo "Error: No indexable files"; return 1; fi DATA=$(jq -n --arg name "$name" --arg path "$1" --argjson files "$files_json" \ '{folder_name: $name, folder_path: $path, files: $files}') nia_post "$BASE_URL/local-folders" "$DATA" } ``` The synchronization path repeats the same behavior: ```bash cmd_sync() { if [ -z "$1" ] || [ -z "$2" ]; then echo "Usage: folders.sh sync /path/to/folder"; return 1; fi if [ ! -d "$2" ]; then echo "Error: Directory not found: $2"; return 1; fi local files_json files_json=$(_scan_folder "$2") local count count=$(echo "$files_json" | jq 'length') echo "Syncing $count text files" DATA=$(jq -n --arg path "$2" ...[truncated 2875 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:22
Finding

API Key Setup Does Not Enforce Restrictive File Permissions

Content
View full analysis
~/.config/nia/api_key ``` The shared authentication code later reads and exports that bearer token: ```bash nia_auth() { NIA_KEY=$(cat ~/.config/nia/api_key 2>/dev/null || echo "") if [ -z "$NIA_KEY" ]; then echo "Error: No API key found. Run: echo 'your-key' > ~/.config/nia/api_key" exit 1 fi export NIA_KEY } ``` ### Technical Analysis The documented setup creates the configuration directory and API key file without explicitly setting permissions. Their resulting modes depend on the user's current `umask`. Under a permissive configuration, the directory and token file can become readable by other local accounts. The authentication function verifies only that the token is present; it does not reject unsafe ownership, symbolic links, or group/world-readable permissions. The use of `echo "token" ...` also encourages placing the secret directly in shell history. ### Attack Path 1. A user follows the documented setup while operating under a permissive `umask`. 2. `~/.config/nia/api_key` is created with group- or world-readable permissions. 3. Another local user or process enumerates and reads the file. 4. The attacker copies the bearer token. 5. The attacker authenticates to the Nia API as the victim until the token is revoked or expires. ### Impact Assessment Exploitation requires local read access to the victim's filesystem namespace and permissive file permissions. A stolen bearer token may allow consumption of the victim's API quota and access to operations, indexed sources, saved contexts, or other account data permitted by that token. This issue does not itself grant operating-system privilege escalation. ]]>
Remediation
View remediation
"$HOME/.config/nia/api_key" unset NIA_KEY ``` Additionally: - Avoid placing the token directly in command-line arguments or shell history. - In `nia_auth`, verify that the file is owned by the current user and is not group- or world-readable. - Reject symbolic links and unexpected file types before reading the key. - Prefer an operating-system credential store where available. - Document token rotation and immediate revocation procedures. - Avoid exporting the token to child processes unless required; keep it scoped to the API client where possible. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Memory PoisoningPersistent Context Injection, Context Window Stuffing, Memory Manipulation
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (51)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill includes account/usage visibility not mentioned in the description. While lower risk than data upload or deletion, undocumented access to usage/account metadata can still expose operational information unexpectedly.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 70)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 71)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 74)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 78)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
1. **Check indexed sources first**: `./scripts/sources.sh list` or `./scripts/repos.sh list`

Memory Manipulation

High
Category
Memory Poisoning
Confidence
90% confidence
Finding

The skill exposes commands to create, update, and delete shared context/memory records. In an agent ecosystem, this can be abused to tamper with long-lived memory, erase audit-relevant context, or poison future agent behavior through manipulated stored knowledge.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

./scripts/contexts.sh semantic-search [limit] # Vector search ./scripts/contexts.sh get <context_id> # Get by ID ./scripts/contexts.sh update [title] [summary] [content] # Update context ./scripts/contexts.sh delete <context_id> # Delete context

text

Save env: `TAGS` (csv), `MEMORY_TYPE` (scratchpad|episodic|fact|procedural), `TTL_SECONDS`, `WORKSPACE`

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This command packages a database connection string and query and sends them to a remote endpoint, which can expose credentials, internal hostnames, and sensitive query results or enable remote access patterns users may not expect. In the context of a repository/document indexing skill, adding DB ingestion materially raises the data-exfiltration risk because users may assume operations are local or limited to files.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Even for preview, the script sends database connection details and an arbitrary query to a remote service without a clear warning. That can disclose credentials and sensitive schema/data while encouraging users to treat preview as low risk, despite it crossing the same trust boundary as full ingestion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run npx nia-wizard@latest, which fetches and executes the latest package version at install time without pinning. That creates a supply-chain risk: if the package is compromised or a breaking/malicious version is published, users may execute unreviewed code during setup.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.