T09 Β· Insecure Skill Coding Practices
- Location
modules/exchange/connection.py:83- Finding
Exchange Credentials Can Be Transmitted to an Unvalidated Plaintext Endpoint
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
NexLink appears to be a real enterprise connector, but it needs Review because its mail and file integrations use powerful credentials with incomplete safety checks around endpoints, sharing, and local file writes.
Install only after reviewing the connector's access in your own environment. Use dedicated least-privilege Exchange and Nextcloud accounts, require HTTPS endpoints, avoid untrusted local config files, be careful with public share links, and avoid running attachment downloads or destructive file/contact/task operations without checking the exact target.
modules/exchange/connection.py:83Exchange Credentials Can Be Transmitted to an Unvalidated Plaintext Endpoint
modules/nextcloud/nextcloud.py:181Nextcloud Basic Authentication Credentials Can Be Sent over Plaintext HTTP
modules/exchange/mail.py:430Untrusted Exchange Attachment Names Can Overwrite Arbitrary Local Files
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| Delete contact | `nexlink contacts delete --uid CONTACT_UID --source nextcloud` |
| Search contacts | `nexlink contacts search --source nextcloud --query "Jane"` |
| Create public links | `nexlink files share-create /Contracts/offer.pdf` |
| Delete file / folder | `nexlink files delete /Documents/old` |
| Extract text | `nexlink files extract-text /Clients/contract.docx` |
| Summarize a file | `nexlink files summarize /Clients/contract.docx` |
| Ask a file | `nexlink files ask-file /Clients/contract.docx "When is the renewal due?"` |
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
Undeclared public share-link management is security-relevant because creating, listing, or revoking share links can directly change external access to files. When such externally visible access-control operations are not clearly disclosed and no confirmation/least-privilege evidence is provided, users may unintentionally expose sensitive documents.
The documented delete command accepts a raw path and performs a destructive operation, which creates a tool-parameter abuse risk if an agent passes attacker-influenced or ambiguous input directly into it. In this skill's context, the danger is elevated because the module is designed for remote file management on enterprise Nextcloud data, so misuse can cause irreversible deletion or business disruption.
Delete a file or directory on Nextcloud.
python3 -m modules.nextcloud delete /path/to/delete
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
*$py.class
# Environment variables (NEVER commit these!)
.env
.env.local
config.yaml
credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Environment variables (NEVER commit these!)
.env
.env.local
config.yaml
credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.env
.env.local
config.yaml
credentials.json
# IDE
.idea/
The file pins lxml to 6.0.2, which is flagged for XXE-related issues in parser defaults such as iterparse() and ETCompatXMLParser(). Because this skill handles enterprise connectors, document understanding, transcripts, and file management, XML input may come from untrusted remote services or uploaded files, making parser-level XXE flaws particularly relevant for file disclosure, SSRF, or denial of service.
The skill advertises cross-system data movement and outbound communication features such as sending email, downloading attachments, uploading files, sharing content, and moving data between Exchange and Nextcloud, but the documentation does not warn users about privacy, authorization, or operational consequences. In an enterprise connector handling mail, files, tasks, and documents, omission of these warnings can lead to unintended disclosure, accidental exfiltration, or user actions that exceed organizational expectations.
The document states branding is disabled by default and only enabled via an explicit environment/config opt-in. Later, the checklist says any new public output must verify that the brand line is present, which contradicts the earlier opt-in-only rule and could pressure implementations to include branding even when it should be off.
The manifest describes NexLink as an enterprise connector for Nextcloud, Exchange, and YouTube, but this branding file defines the headline as 'Exchange, Nextcloud, GitHub β one assistant' and says those are the three main integrations. This is an active documentation-level contradiction about the skill's intended scope and integrations.
The line states 'RO pentru utilatori romΓ’ni, EN pentru documentaΘie tehnicΔ,' which sets a language policy based on user demographic rather than explicit preference. Under the policy criteria, forcing a specific language without user opt-in is a natural-language policy violation unless clearly documented as a justified regional constraint.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Security (ClawScan Findings β All Phases)
**Phase 1 β Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β `--yes` / `-y` is now strictly **per-command**
- `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
- `--yes` must be appended to each individual command; there is no env bypass
- Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Security (ClawScan Findings β All Phases)
**Phase 1 β Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β `--yes` / `-y` is now strictly **per-command**
- `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
- `--yes` must be appended to each individual command; there is no env bypass
- Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Security (ClawScan Findings β All Phases)
**Phase 1 β Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β `--yes` / `-y` is now strictly **per-command**
- `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
- `--yes` must be appended to each individual command; there is no env bypass
- Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Security (ClawScan Findings β All Phases)
**Phase 1 β Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β `--yes` / `-y` is now strictly **per-command**
- `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
- `--yes` must be appended to each individual command; there is no env bypass
- Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
### Security (ClawScan Findings β All Phases)
**Phase 1 β Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β `--yes` / `-y` is now strictly **per-command**
- `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
- `--yes` must be appended to each individual command; there is no env bypass
- Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
**Phase 1 β Per-command --yes only + Pinned dependencies**
- **Removed session-wide `NEXLINK_AUTO_APPROVE`** β `--yes` / `-y` is now strictly **per-command**
- `utils.confirm_or_die()` no longer checks env var; uses `auto_approved` kwarg only
- `--yes` must be appended to each individual command; there is no env bypass
- Nextcloud `run_cli()` uses module-level `_AUTO_APPROVED` instead of env
- Exit code changed from 1 β 2 on non-confirmation
No suspicious patterns detected.