Back to skill

Security audit

Auth0 Quickstart

Security checks for vulnerabilities and agentic risk

Overview

This Auth0 quickstart skill is mostly coherent documentation, but it includes high-impact Auth0 tenant administration commands without enough guardrails.

Review before installing if you will connect it to a real Auth0 tenant. Prefer the Homebrew CLI install, avoid entering real passwords directly in command lines, and do not run delete or tenant-admin commands unless you have verified the tenant and resource IDs and understand the impact.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T03 · Remote Payload Retrieval and Execution

Warning
Location
references/cli.md:18
Finding

Unpinned Remote Installation Script Can Execute Mutable External Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/cli.md:155
Finding

User Password Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
` rather than a realistic password literal. 5. Add a warning that real passwords must not be entered directly into shell commands, scripts, CI variables expanded into commands, or terminal sessions that are being recorded. 6. Prefer invitation, password-reset, or passwordless enrollment flows where users establish their own credentials without exposing them to the administrator. 7. Require MFA and least-privileged roles to limit the impact of any initial-credential disclosure. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (14)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cli.md (reported line 21)May include surrounding context.

curl -sSfL https://raw.githubusercontent.com/auth0/auth0-cli/main/install.sh -o /tmp/auth0-install.sh

Review the script before running: cat /tmp/auth0-install.sh

sh /tmp/auth0-install.sh rm /tmp/auth0-install.sh

text

### Windows

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli.md (reported line 203)May include surrounding context.

md
| Token | Purpose | Lifespan | Where Stored |
|-------|---------|----------|--------------|
| **Access Token** | API authorization | Short (hours) | Client or server |
| **ID Token** | User identity info (JWT) | Short (hours) | Client or server |
| **Refresh Token** | Get new access tokens | Long (days/months) | Secure storage only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/concepts.md (reported line 72)May include surrounding context.

md
| Token | Purpose | Lifespan | Where Stored |
|-------|---------|----------|--------------|
| **Access Token** | API authorization | Short (hours) | Client or server |
| **ID Token** | User identity info (JWT) | Short (hours) | Client or server |
| **Refresh Token** | Get new access tokens | Long (days/months) | Secure storage only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/concepts.md (reported line 285)May include surrounding context.

md
| Token | Purpose | Lifespan | Where Stored |
|-------|---------|----------|--------------|
| **Access Token** | API authorization | Short (hours) | Client or server |
| **ID Token** | User identity info (JWT) | Short (hours) | Client or server |
| **Refresh Token** | Get new access tokens | Long (days/months) | Secure storage only |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/concepts.md (reported line 74)May include surrounding context.

md
|-------|---------|----------|--------------|
| **Access Token** | API authorization | Short (hours) | Client or server |
| **ID Token** | User identity info (JWT) | Short (hours) | Client or server |
| **Refresh Token** | Get new access tokens | Long (days/months) | Secure storage only |

### OAuth/OIDC Terms

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli.md (reported line 206)May include surrounding context.

md
**How it works:**
1. Service authenticates with client ID + secret
2. Receives access token
3. Uses token to call APIs

**Security:** No user involved, service-to-service only

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli.md (reported line 295)May include surrounding context.

md
**How it works:**
1. Service authenticates with client ID + secret
2. Receives access token
3. Uses token to call APIs

**Security:** No user involved, service-to-service only

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/concepts.md (reported line 120)May include surrounding context.

md
**How it works:**
1. Service authenticates with client ID + secret
2. Receives access token
3. Uses token to call APIs

**Security:** No user involved, service-to-service only

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/environments.md (reported line 348)May include surrounding context.

md
1. **Restart dev server** after changing `.env`
2. **Check variable prefix** (VITE_, REACT_APP_, etc.)
3. **Verify file name** (.env vs .env.local)
4. **Check file location** (must be in project root)
5. **Load dotenv** for Node.js: `require('dotenv').config()`

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says this skill detects those stacks, sets up an Auth0 account if needed, and routes to the correct SDK setup workflow. In the body, dedicated detection guidance and routing are provided for several frameworks, but FastAPI, ASP.NET Core, Android, and Swift appear only as Tier 2 docs links or related skills references rather than actual setup workflow coverage in this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation includes an application deletion command with no warning that the action is irreversible and can break authentication flows for dependent environments. In an agent skill context, terse destructive commands increase the chance that a user or agent invokes them casually during troubleshooting or cleanup.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest describes a skill for adding authentication/login to an app, detecting the stack, and routing to the appropriate SDK setup workflow. This reference file documents unrelated administrative capabilities such as creating/deleting users, listing log streams, and creating/managing APIs, which are not obviously required for basic app authentication setup.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The user deletion command is documented without warning about permanent account removal and potential loss of auditability or access for real users. In a skill that may guide setup and debugging, presenting delete operations without guardrails raises the risk of accidental destructive administration.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The section is presented as a way to 'identify your framework,' yet the sample commands only grep package.json and list a handful of files such as angular.json, next.config, app.json, Package.swift, and build.gradle. This contradicts the broader detection claim for stacks like FastAPI and ASP.NET Core, which are not actually covered by the shown detection commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.