Back to skill

Security audit

Express Oauth2 Jwt Bearer

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a legitimate Auth0 JWT setup skill, but its automatic setup path can install mutable npm code and create Auth0 tenant resources using the user's existing CLI login.

Install only if you are comfortable with the automatic setup using your Auth0 CLI login to create an API resource and edit the target project's .env file. Prefer manual setup, or review the bootstrap change plan carefully, pin or lock npm dependencies, avoid curl-to-sh installers, and never paste production client secrets directly into shell commands.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/utils/validation.mjs:21
Finding

Unpinned Remote Installation Script Piped Directly to a Shell

Content
View full analysis
Remediation
View remediation
/install.sh" printf '%s %s\n' '' 'auth0-install.sh' | sha256sum --check - less auth0-install.sh sh auth0-install.sh ``` ]]>

T08 · Insecure Dependencies

Warning
Location
references/setup.md:24
Finding

Bootstrap Installation Uses Mutable, Unlocked npm Dependencies

Content
View full analysis
/scripts && npm install && node bootstrap.mjs ``` `scripts/package.json:9-12`: ```json "dependencies": { "execa": "^9.0.0", "ora": "^8.0.0" } ``` The Skill also instructs the Agent to retrieve and use the latest SDK release in `SKILL.md:17-21`: ```bash gh api repos/auth0/node-oauth2-jwt-bearer/releases/latest --jq '.tag_name' ``` ### Technical Analysis The automatic setup path runs `npm install` in a directory that has no committed lockfile. Its dependencies use caret ranges, allowing npm to resolve versions other than those originally reviewed, including mutable transitive dependency graphs. npm installation may execute lifecycle scripts from resolved packages before `bootstrap.mjs` runs. Consequently, the code executed during setup is not limited to the JavaScript files included in this project. The instruction to retrieve and use the latest SDK version similarly bypasses a fixed, reviewed dependency baseline. The named packages are legitimate packages, and the reviewed project does not contain evidence that they are intentionally malicious. The vulnerability is the absence of deterministic resolution and installation hardening, which increases exposure to registry-account compromise, malicious transitive releases, and unexpected upstream changes. ### Attack Path 1. The user selects automatic setup. 2. The Agent runs `npm install` as instructed. 3. npm resolves the caret-ranged direct dependencies and their current transitive dependencies from the registry. 4. A compromised or unexpectedly modified package version is selected because no reviewed lockfile fixes the dependency graph. 5. A dependency lifecycle script executes during i ...[truncated 928 chars]
Remediation
View remediation
``` 6. If lifecycle scripts are required, document and audit each required script before enabling it. 7. Use automated dependency scanning, provenance verification, and lockfile review in the release process. 8. Avoid automatically selecting the latest SDK version. Maintain a reviewed supported version and update it through an explicit security and compatibility review. 9. Consider packaging the bootstrap with vendored or bundled reviewed dependencies to avoid resolving new code at runtime. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/api.md:180
Finding

M2M Client Secret Embedded in Interactive Shell Commands

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (33)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 15)May include surrounding context.

md
# Node OAuth2 JWT Bearer Integration

The `express-oauth2-jwt-bearer` package provides Express middleware for validating Auth0 JWT Bearer access tokens. It handles token extraction, signature verification, audience and issuer validation, and expiry checks per RFC 6750 — letting you focus on business logic rather than JWT parsing.

> **Agent instruction:** Before providing SDK setup instructions, fetch the latest release version by running:
> ```bash

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api.md (reported line 213)May include surrounding context.

md
- **CORS before auth.** Always register `cors()` before `auth()`. Auth middleware rejects OPTIONS preflight requests with 401 if CORS isn't set first.
- **Audience validation is critical.** Without a matching `audience`, your API would accept tokens issued for other services.
- **Issuer validation.** The `issuerBaseURL` is used to fetch the JWKS and validate the `iss` claim. Never disable issuer validation in production.
- **RBAC via `permissions` claim.** Auth0 RBAC stores user permissions in the `permissions` JWT claim (not `scope`). Enable "Add Permissions in the Access Token" on your Auth0 API settings.
- **DPoP.** For APIs requiring sender-constrained tokens, enable DPoP with `dpop: { enabled: true, required: true }`. This prevents token theft — stolen tokens cannot be replayed without the original private key.
- **Helmet.** Pair with `helmet` for security headers: `npm install helmet` + `app.use(helmet())`.
- **Production secrets.** Never commit `.env` to source control. Use environment variables in production (Railway, Heroku, Fly.io, etc.).

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/integration.md (reported line 7)May include surrounding context.

text
Client → API
  1. Client obtains access token from Auth0 (via /oauth/token)
  2. Client sends request with "Authorization: Bearer <token>" header
  3. express-oauth2-jwt-bearer middleware:
     a. Extracts bearer token from Authorization header

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 93)May include surrounding context.

text
Client → API
  1. Client obtains access token from Auth0 (via /oauth/token)
  2. Client sends request with "Authorization: Bearer <token>" header
  3. express-oauth2-jwt-bearer middleware:
     a. Extracts bearer token from Authorization header

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/integration.md (reported line 76)May include surrounding context.

RBAC — Scope-Based Authorization

Use requiredScopes() to enforce scopes on access tokens:

javascript
import { auth, requiredScopes } from 'express-oauth2-jwt-bearer';

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 7)May include surrounding context.

md
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 44)May include surrounding context.

md
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 127)May include surrounding context.

md
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 130)May include surrounding context.

md
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/evals.json (reported line 17)May include surrounding context.

json
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/evals.json (reported line 18)May include surrounding context.

json
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/graders.json (reported line 11)May include surrounding context.

json
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/graders.json (reported line 12)May include surrounding context.

json
> **Agent instruction:**
>
> **Check if credentials are already provided in the user's prompt:** If the user's prompt already includes Auth0 Domain and API Audience (e.g. `your-tenant.us.auth0.com` and `https://api.example.com`), use them directly — skip to "Write the .env file" below. Do NOT call `AskUserQuestion` to re-confirm provided credentials, and do NOT run the bootstrap script.
>
> If credentials are NOT provided, offer setup choices:
>

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 80)May include surrounding context.

md
1. Go to Auth0 Dashboard → APIs → your API → Settings
2. Enable **"Enable RBAC"**
3. Enable **"Add Permissions in the Access Token"**
4. Add permissions under the **Permissions** tab
5. Assign permissions to roles, and roles to users via Auth0 Dashboard

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file performs Auth0 tenant provisioning by invoking auth0 apis create, which is materially different from the declared purpose of adding JWT validation to an Express/Node.js API. In an agent-skill context, this expands capabilities from local code integration to external administrative changes against a tenant, creating risk of unauthorized resource creation, configuration drift, or abuse if the skill is triggered in environments with privileged Auth0 CLI credentials.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 148)May include surrounding context.

md
import ora from "ora"

export async function writeEnvFile(config, envFilePath) {
  const spinner = ora("Writing .env").start()

  try {
    let content = ""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/bootstrap.mjs (reported line 48)May include surrounding context.

js
import ora from "ora"

export async function writeEnvFile(config, envFilePath) {
  const spinner = ora("Writing .env").start()

  try {
    let content = ""

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/utils/env-writer.mjs (reported line 5)May include surrounding context.

js
import ora from "ora"

export async function writeEnvFile(config, envFilePath) {
  const spinner = ora("Writing .env").start()

  try {
    let content = ""

Credential Access

High
Category
Privilege Escalation
Confidence
65% confidence
Finding

Writing arbitrary config entries to an attacker-controlled envFilePath can overwrite sensitive files or place secrets into unintended locations if the path or keys/values are not validated. In the context of an auth-related skill, miswriting environment configuration can disable authentication, alter issuer/audience settings, or expose operational secrets through misconfiguration.

Content

Scanner excerpt · scripts/utils/env-writer.mjs (reported line 25)May include surrounding context.

js
fs.writeFileSync(envFilePath, content)
    spinner.succeed(`Updated ${envFilePath}`)
  } catch (e) {
    spinner.fail("Failed to write .env")
    throw e
  }
}

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill explicitly instructs the agent to run a shell command (gh api ...) and references environment-variable based configuration, but it declares no permissions or allowed-tools scope. That mismatch weakens least-privilege controls because a host system may allow tool use that the skill never transparently declares, increasing the chance of unintended shell or environment access during execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 169)May include surrounding context.

md
## Testing Checklist

- [ ] **Public endpoint** returns `200` without a token: `curl http://localhost:3000/api/public`
- [ ] **Protected endpoint** returns `401` without a token: `curl http://localhost:3000/api/private`
- [ ] **Protected endpoint** returns `200` with valid M2M token: `curl -H "Authorization: Bearer <token>" http://localhost:3000/api/private`
- [ ] **Scoped endpoint** returns `403` with token missing required scope

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/integration.md (reported line 259)May include surrounding context.

Testing Patterns

Manual testing with curl

bash
# 1. Get a test token (from Auth0 Dashboard → APIs → Test, or via M2M credentials)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation includes a live token acquisition example that embeds a client_secret in a curl request without any warning about secret handling, storage, or the risks of using production credentials in local shells and logs. While this is instructional rather than directly executable by the skill itself, it can lead users to copy sensitive credentials into terminal history, CI logs, screenshots, or shared docs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The setup guide instructs an automatic bootstrap flow that installs dependencies and runs a script which creates remote Auth0 resources and writes a local .env file, but it does not require an explicit warning or confirmation immediately before those side effects. In an agent-executed context, this can lead to unintended project modification and cloud-side changes if the user does not fully understand what will be changed.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.