Back to skill

Security audit

xCloud Docker Deploy

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed xCloud deployment helper, but its generated workflow templates can publish images and trigger deployments with weaker safeguards than the safety text suggests.

Install only if you want an agent to prepare xCloud deployment files. Before applying generated GitHub Actions workflows, pin external actions to reviewed commit SHAs, pass webhook secrets through environment variables rather than direct shell interpolation, use protected GitHub environments or manual approvals for production deploys, verify backups before migrations, and provide an xCloud API token only for a named live operation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
assets/github-actions-build.yml:19
Finding

GitHub Actions Dependencies Are Referenced by Mutable Version Tags

Content
View full analysis
Remediation
View remediation
- uses: docker/setup-buildx-action@ - uses: docker/login-action@ - uses: docker/metadata-action@ - uses: docker/build-push-action@ ``` 2. Retain the human-readable release version in a comment: ```yaml - uses: actions/checkout@ # v4.x ``` 3. Apply the same pinning to all workflows embedded in examples and reference documents so generated files do not reintroduce mutable dependencies. 4. Configure Dependabot or Renovate to propose SHA updates through pull requests. Require review of release notes and commit differences before merging updates. 5. Preserve minimal job permissions and split image publication from untrusted build operations where practical. 6. Consider artifact signing and provenance generation for published images, and configure deployment systems to verify signatures or attestations before deployment. 7. Prefer immutable image references, such as digests or commit-derived tags, over `latest` for production deployment. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
assets/github-actions-build.yml:52
Finding

Webhook Secret Is Directly Interpolated into Shell Source

Content
View full analysis
Remediation
View remediation
&2; exit 1 ;; esac ``` 4. Put the deployment call in a separate job with minimal permissions: ```yaml permissions: contents: none packages: none ``` Grant only permissions actually required by the deployment job. 5. Protect deployment environments with GitHub Environment approval rules, especially for production. Store production webhook credentials in a protected environment rather than as an unrestricted repository secret. 6. Keep the documented final-confirmation, backup, and staging gates, but enforce them technically through protected environments and required reviewers rather than relying solely on comments. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (14)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · SECURITY.md (reported line 27)May include surrounding context.

md
|---|---|---|---|
| `SKILL.md` | Agent instructions | Guides project inspection and file generation | Requires user confirmation before inspection, edits, token handling, or live API routing |
| `README.md` | Human documentation | Documents deployment flows | Includes confirmation, backup, staging, and token safety guidance |
| `DETECT.md` | Stack detection reference | Read-only fingerprint rules | No execution |
| `references/*.md` | Scenario/reference docs | May show deploy commands or webhook patterns | Examples only; user must approve before use |
| `dockerfiles/*.Dockerfile` | Dockerfile templates | Build instructions for generated images | Templates only; not executed by install |
| `compose-templates/*.yml` | Compose templates | Deployment configuration templates | Templates only; users review before applying |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · examples/laravel-app.md (reported line 32)May include surrounding context.

Step 2 — Add to .gitignore

text
.env
/vendor
/node_modules
/public/storage

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · examples/laravel-app.md (reported line 43)May include surrounding context.

bash
git init && git add . && git commit -m "Initial commit"
git remote add origin https://github.com/OWNER/REPO.git
git push -u origin main

Step 4 — Deploy in xCloud

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README frames the skill around a very natural request ('I want to deploy it on xCloud'), which overlaps heavily with ordinary user intent and makes accidental or overly broad invocation more likely. In an agent ecosystem, broad triggers can cause the skill to activate in contexts the user did not specifically intend, increasing the chance of unplanned repo inspection, file generation, or escalation into token-gated deployment workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Usage section encourages activation from common deployment-style prompts without distinguishing between ordinary assistance and deliberate skill invocation. That ambiguity can cause an agent to route normal project help requests into this skill automatically, which is risky because the skill can progress from analysis into file generation and eventually live xCloud operations after follow-on confirmations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SECURITY.md (reported line 70)May include surrounding context.

md
- Does not execute Docker, GitHub Actions, webhooks, or xCloud API calls by itself.
- Does not collect telemetry.
- Does not persist credentials.
- Does not automatically modify user files.

## Generated Output Security

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · README.md (reported line 151)May include surrounding context.

md
| Official skill | Owns |
|---|---|
| `xcloud:servers` | Servers, PHP, databases, cron, firewall/fail2ban, sudo users, WordPress provisioning |
| `xcloud:sites` | Site lifecycle, status, backups, domains, cache, SSH, site cron, git |
| `xcloud:wordpress` | WordPress plugins, themes, updates, debug, magic login, vulnerabilities, PageSpeed |
| `xcloud:ssl` | SSL certificates: view, install, renew, status, delete |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
| Official skill | Owns |
|---|---|
| `xcloud:servers` | Servers, PHP, databases, cron, firewall/fail2ban, sudo users, WordPress provisioning |
| `xcloud:sites` | Site lifecycle, status, backups, domains, cache, SSH, site cron, git |
| `xcloud:wordpress` | WordPress plugins, themes, updates, debug, magic login, vulnerabilities, PageSpeed |
| `xcloud:ssl` | SSL certificates: view, install, renew, status, delete |

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
| Official skill | Owns |
|---|---|
| `xcloud:servers` | Servers, PHP, databases, cron, firewall/fail2ban, sudo users, WordPress provisioning |
| `xcloud:sites` | Site lifecycle, status, backups, domains, cache, SSH, site cron, git |
| `xcloud:wordpress` | WordPress plugins, themes, updates, debug, magic login, vulnerabilities, PageSpeed |
| `xcloud:ssl` | SSL certificates: view, install, renew, status, delete |

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · assets/github-actions-build.yml (reported line 59)May include surrounding context.

yaml
- name: Trigger xCloud deploy
        if: ${{ secrets.XCLOUD_DEPLOY_WEBHOOK != '' }}
        run: |
          curl -s -X POST "${{ secrets.XCLOUD_DEPLOY_WEBHOOK }}" \
            -H "Content-Type: application/json" \
            -d '{"ref": "${{ github.sha }}"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The deployment instructions run php artisan migrate --force, which suppresses interactive safety checks and can apply schema changes automatically in production. While this is common in CI/CD, presenting it without warning or guidance on backups, migration review, and rollout risk can lead to service disruption or destructive database changes if a migration is unsafe.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/scenario-build-source.md (reported line 66)May include surrounding context.

md
Or configure in `docker-build.yml` using `packages: write` permission (already in template).

## Step 4 — xCloud Webhook for Auto-Deploy

Production safety gate: add this webhook only after the user confirms the target site, confirms staging vs production, and confirms that a current backup exists for production data.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The safety comment claims a production confirmation gate, but comments do not create security controls and the workflow will still execute the webhook whenever the secret exists. This mismatch can mislead users into believing deployment is consent-gated when in practice a push to main is sufficient to trigger a live deploy path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented workflow includes a live deployment webhook call, which goes beyond a purely file-generation/reference skill and can trigger real infrastructure changes if the secret is present. Although the comment says deployment should happen only after confirmation, the YAML does not enforce any approval, token-consent, or environment protection gate before issuing the POST request.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.