Back to skill

Security audit

Secure Workspace

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plausible secrets-encryption helper, but it recommends loading decrypted secrets by executing them as shell code and uses an over-specific root key path.

Install only if you are comfortable auditing and changing the workflow first. Do not source decrypted files from repositories or shared workspaces; decrypt only trusted files, validate simple key-value assignments before loading them, avoid running this as root, and reconcile the `/root/.age/key.txt` versus `$HOME/.age/key.txt` inconsistency.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:24
Finding

Arbitrary Shell Command Execution Through Sourcing Untrusted Decrypted Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented primarily as an encryption utility, but its documented behavior also includes decrypting secrets, reading a private key from /root/.age/key.txt, and emitting plaintext secrets to stdout for shell sourcing. That mismatch is dangerous because users may approve it as a storage-protection tool without realizing it also performs secret recovery and disclosure operations.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
bash scripts/secure/setup.sh

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
bash scripts/secure/setup.sh

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
bash scripts/secure/setup.sh

# 2. Encrypt a secret
echo 'export API_KEY=*** | bash scripts/secure/encrypt.sh scripts/secure/secrets.env.age

# 3. Decrypt on the fly
source <(bash scripts/secure/decrypt.sh scripts/secure/secrets.env.age)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/secure/setup.sh (reported line 52)May include surrounding context.

sh
bash scripts/secure/setup.sh

# 2. Encrypt a secret
echo 'export API_KEY=*** | bash scripts/secure/encrypt.sh scripts/secure/secrets.env.age

# 3. Decrypt on the fly
source <(bash scripts/secure/decrypt.sh scripts/secure/secrets.env.age)

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The documented decryption flow outputs plaintext secrets and immediately sources them into the shell, which constitutes active credential exposure in memory and process output paths. In agent or shared environments, this can disclose secrets to logs, command tracing, shell introspection, or malicious content embedded in the encrypted file.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

echo 'export API_KEY=*** | bash scripts/secure/encrypt.sh scripts/secure/secrets.env.age

3. Decrypt on the fly

source <(bash scripts/secure/decrypt.sh scripts/secure/secrets.env.age)

text

## Files

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/secure/setup.sh (reported line 53)May include surrounding context.

sh
echo ""
echo "[*] AHORA: cifra tus secrets manualmente:"
echo "    echo 'export API_KEY=xxx' | $SCRIPTS_DIR/encrypt.sh $SCRIPTS_DIR/secrets.env.age"
echo "    rm -f /ruta/al/archivo.original"
echo ""
echo "[*] Para descifrar:"
echo "    source <($SCRIPTS_DIR/decrypt.sh $SCRIPTS_DIR/secrets.env.age)"

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The script instructs users to load decrypted content directly into the current shell with source <(decrypt.sh ...). If the encrypted file is modified by an attacker or contains unexpected shell code, this executes arbitrary commands in the user's session rather than merely reading environment variables, turning secret handling into code execution.

Content

Scanner excerpt · scripts/secure/setup.sh (reported line 56)May include surrounding context.

sh
echo "    rm -f /ruta/al/archivo.original"
echo ""
echo "[*] Para descifrar:"
echo "    source <($SCRIPTS_DIR/decrypt.sh $SCRIPTS_DIR/secrets.env.age)"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill invokes shell commands and external executables (bash, age) but does not declare any tool scope or permissions boundary. In an agent environment, this creates hidden execution capability and prevents users or orchestrators from understanding or constraining what the skill can run.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The instructions recommend source <(bash scripts/secure/decrypt.sh ...), which executes decrypted content directly in the current shell without warning. If the encrypted file contains unexpected shell code instead of simple environment assignments, decryption becomes code execution in the user's session and may expose secrets via shell history, process inspection, or follow-on commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script states that the private key must be present at /root/.age/key.txt and then uses it directly to decrypt data. There is no confirmation prompt, user-facing warning beyond the usage note, or explanatory disclosure about handling sensitive credentials in this code file.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/secure/setup.sh (reported line 12)May include surrounding context.

sh
# 1. Generar par de llaves
AGE_DIR="$HOME/.age"
mkdir -p "$AGE_DIR"
chmod 700 "$AGE_DIR"

if [ ! -f "$AGE_DIR/key.txt" ]; then
    age-keygen -o "$AGE_DIR/key.txt"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The file's descriptive comments and usage guidance are written only in Spanish, which imposes a specific language without any opt-in or indication that the skill is region-specific. Under the stated policy, language constraints should either be optional for the user or explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

This code performs a file write by redirecting encryption output into the path provided by the caller. While writing the output file is central to the script's purpose, the script does not include any explicit disclosure that an existing file may be overwritten or replaced, which is a safety-relevant side effect for code files.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.