Back to skill

Security audit

Pi-hole Control

Security checks for vulnerabilities and agentic risk

Overview

This Pi-hole control skill is mostly purpose-aligned, but it has real security-control and credential-handling problems users should review before installing.

Review before installing. Use only an explicitly configured Pi-hole URL, prefer HTTPS with a valid certificate, avoid insecure mode unless the network is tightly controlled, and verify Pi-hole status after any disable command. The script should be fixed so timed disables remain timed and credentials are not exposed through process arguments or plaintext transport.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
pihole.sh:91
Finding

Pi-hole API Password Exposed Through Process Arguments

Content
View full analysis
/dev/null) ``` ### Technical Analysis The API password is read from an environment variable or configuration file, but the shell interpolates it into curl's `-d` argument. Consequently, the expanded JSON document containing the password becomes part of curl's process argument vector while authentication is in progress. Depending on operating-system process visibility controls, another process running under the same account—or a privileged local process—may inspect the curl command line and recover the credential. Passing a secret through an environment variable initially does not prevent this exposure after the shell expands it into a command-line argument. This behavior contradicts the claims in `SKILL.md` and `SECURITY_AUDIT.md` that the token is not visible in the process list. ### Attack Path 1. A user invokes a Pi-hole command that requires an authenticated API request. 2. `get_session` expands `PIHOLE_API_TOKEN` into the JSON supplied through curl's `-d` option. 3. Curl runs with the expanded password in its process argument vector. 4. A local process with sufficient process-inspection access reads the curl command line during this interval. 5. The attacker extracts the Pi-hole app password. 6. The attacker authenticates directly to the Pi-hole API and performs operations allowed by that credential. ### Impact Assessment An attacker who obtains the credential may acquire the API privileges assigned to the Pi-hole app password. Based on the Skill's documented capabilities, this can include: - Inspecting Pi-hole status and statistics. - Accessin ...[truncated 383 chars]
Remediation
View remediation
/dev/null ) unset auth_payload ``` Use a Bash array for curl options instead of a space-delimited string to preserve argument boundaries safely. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
pihole.sh:7
Finding

API Credentials May Be Transmitted Without Authenticated TLS

Content
View full analysis
/dev/null) ``` ### Technical Analysis The script permits two insecure transport configurations: 1. Its fallback API URL uses plaintext HTTP. 2. Setting `PIHOLE_INSECURE=true` adds curl's `-k` option, disabling TLS certificate verification. The script does not validate the configured URL scheme before transmitting the Pi-hole app password. Over HTTP, the password is sent without transport encryption. With `-k`, traffic is encrypted but the server's identity is not authenticated, allowing a man-in-the-middle endpoint to present an untrusted certificate and receive the credential. Sending authentication information to the user-configured Pi-hole is necessary for the Skill's declared functionality and no hidden external recipient was identified. However, allowing unauthenticated transport is not the minimum secure privilege or exposure required for that functionality. The default path `/admin/api.php` is also inconsistent with the declared Pi-hole v6 `/api` interface, increasing the possibility of an unintended endpoint being contacted. ### Attack Path 1. The user retains the plaintext HTTP fallback, configures an HTTP API URL, or enables insecure TLS verification. 2. A command causes `get_session` to send the app password to the configured `/auth` endpoint. 3. A ...[truncated 1032 chars]
Remediation
View remediation
&2 exit 1 fi ``` ]]>

T09 · Insecure Skill Coding Practices

Error
Location
pihole.sh:171
Finding

Timed Disable Command Unintentionally Disables Pi-hole Indefinitely

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill documents commands that disable Pi-hole protection but does not explicitly warn that this reduces or removes DNS-based ad/malware blocking for the network during the disabled period. Because this is an administrative control skill, a user may invoke it casually without understanding the security impact, increasing the chance of accidental exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends an insecure mode that bypasses TLS certificate validation, but it does not clearly warn that this enables man-in-the-middle interception or spoofing of the Pi-hole API endpoint. Since the API uses an authentication secret and performs administrative actions, disabling certificate verification materially weakens transport security and can expose credentials or allow unauthorized control.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
83% confidence
Finding

The script allows TLS certificate verification to be disabled via PIHOLE_INSECURE=true, which weakens transport security for authentication and API traffic. If used over HTTPS on an untrusted network, a man-in-the-middle attacker could intercept or tamper with requests, including the Pi-hole API token/session flow.

Content

Scanner excerpt · pihole.sh (reported line 36)May include surrounding context.

sh
exit 1
fi

# Build curl flags based on insecure setting
CURL_FLAGS="-s --fail --max-time 30"
if [[ "$PIHOLE_INSECURE" == "true" ]]; then
    CURL_FLAGS="$CURL_FLAGS -k"

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

This code sends authenticated requests and session headers to a configurable external endpoint. Because PIHOLE_API_URL can come from environment or local config and defaults to plain HTTP, the script may transmit credentials or session material to an unintended or intercepted host, especially in misconfigured deployments.

Content

Scanner excerpt · pihole.sh (reported line 104)May include surrounding context.

sh
session=$(get_session) || exit 1

    if [[ -n "$data" ]]; then
        curl $CURL_FLAGS \
            -H "sid: $session" \
            -H "Content-Type: application/json" \
            -X "$method" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
87% confidence
Finding

The insecure toggle directly alters curl security behavior by appending -k, disabling certificate validation. In a security-control skill that can enable/disable DNS blocking, this is more dangerous than in a read-only utility because an attacker positioned on the network could spoof the API endpoint and induce unauthorized state changes while capturing authentication material.

Content

Scanner excerpt · pihole.sh (reported line 36)May include surrounding context.

sh
exit 1
fi

# Build curl flags based on insecure setting
CURL_FLAGS="-s --fail --max-time 30"
if [[ "$PIHOLE_INSECURE" == "true" ]]; then
    CURL_FLAGS="$CURL_FLAGS -k"

Static analysis

No suspicious patterns detected.