Back to skill

Security audit

aws-ecs-monitor

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its ECS monitoring purpose, but its scripts contain unsafe input handling that could let crafted configuration or arguments run commands in the user's AWS-enabled environment.

Review before installing. Use only with trusted configuration and command arguments, run it with least-privilege AWS read permissions, and keep output paths in a protected directory. The unsafe Python interpolation, arithmetic parsing, and temporary-file handling should be fixed before use in shared, automated, or user-facing agent environments.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ecs-health.sh:225
Finding

Python Code Injection Through Interpolated Environment Configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cloudwatch-logs.sh:348
Finding

Python Code Injection Through the Configurable Health-State Path

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cloudwatch-logs.sh:87
Finding

Shell Command Execution Through Unvalidated Arithmetic Input

Content
View full analysis
&2; exit 2 ;; *) [[ -z "$SERVICE" ]] && SERVICE="$1"; shift ;; esac done [[ -z "$SERVICE" ]] && SERVICE="all" } pull_service_logs() { local svc="$1" log_group="${LOG_GROUPS[$1]}" local start_ms=$(( ($(date +%s) - MINUTES * 60) * 1000 )) local end_ms=$(( $(date +%s) * 1000 )) ``` ### Technical Analysis The `--minutes` argument is stored without verifying that it is a decimal integer. It is subsequently referenced by name inside a Bash arithmetic expansion. Bash recursively interprets variable contents used in arithmetic expressions. Crafted arithmetic syntax can therefore cause additional expansions, including command substitution in constructs such as malicious array-subscript expressions. This is not equivalent to parsing a safe integer. `--limit` is also accepted without validation. Although it is passed as an argument to AWS rather than directly evaluated by the shell in the shown path, it should be validated to prevent malformed requests and resource-abuse conditions. ### Attack Path 1. An attacker influences arguments passed by the Agent to `cloudwatch-logs.sh`. 2. The attacker supplies a crafted, nonnumeric value to `--minutes`. 3. Argument parsing stores the text in `MINUTES` without validation. 4. A command such as `pull`, `errors`, or `restarts` reaches `pull_service_logs`. 5. Bash recursively evaluates the contents of ...[truncated 559 chars]
Remediation
View remediation
10080 )); then echo "ERROR: --minutes must be an integer between 1 and 10080" >&2 exit 2 fi if [[ ! "$LIMIT" =~ ^[0-9]+$ ]] || (( LIMIT < 1 || LIMIT > 10000 )); then echo "ERROR: --limit must be an integer between 1 and 10000" >&2 exit 2 fi ``` Further hardening should include: - Reject missing option values instead of silently applying defaults. - Use a dedicated argument parser or strict parsing helper. - Impose upper bounds to prevent excessive CloudWatch queries and local processing. - Add tests with whitespace, signs, hexadecimal values, arithmetic operators, array syntax, and command-substitution syntax. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cloudwatch-logs.sh:394
Finding

Predictable Temporary File Enables Symlink-Based File Overwrite

Content
View full analysis
&1 1>/tmp/ecs-ad-svcs.$$) # Print the header/issues (stderr was redirected to stdout above) echo "$failing_svcs" # Read the services list local svc_list svc_list=$(cat /tmp/ecs-ad-svcs.$$ 2>/dev/null) rm -f /tmp/ecs-ad-svcs.$$ ``` ### Technical Analysis The script constructs a temporary filename from the process ID and opens it using ordinary shell redirection. The path is predictable, is not created atomically, and is not checked for symbolic links. A local attacker can predict or observe the relevant process ID and create `/tmp/ecs-ad-svcs.` as a symbolic link before the redirection occurs. The shell follows that link when opening the destination. Because output redirection normally opens the target with truncation, this can overwrite a file writable by the Skill process. The final `rm` removes the temporary pathname rather than undoing modifications to the symlink target. ### Attack Path 1. A local attacker predicts or observes the PID of a process that will run `auto-diagnose`. 2. Before line 394 executes, the attacker creates `/tmp/ecs-ad-svcs.` as a symbolic link to a file writable by the Agent account. 3. The script performs output redirection to the predictable path. 4. The operating system follows the symbolic link and truncates or replaces content in the target file with the generated service list. 5. The script reads the redirected file and removes only the `/tmp` link. ### Impact Assessment The attacker can corrupt or truncate files writable by the Agent account. Potential targets include state files, configuration files, shell initialization files, or application data, depending on filesystem permissions. This does not by itself allow overwriting files that the Skill account cannot write, but corruption of exe ...[truncated 109 chars]
Remediation
View remediation
"$svc_file" svc_list=$(cat -- "$svc_file") ``` Prefer eliminating the temporary file entirely by separating machine-readable output from diagnostic output and capturing each stream through a safe mechanism. Also: - Do not use PID-only temporary names. - Set a restrictive `umask`, such as `umask 077`, before creating state files. - Quote temporary paths and use `rm -f --`. - Ensure cleanup occurs on errors and signals. ]]>

T05 · Unauthorized Access and Privilege Escalation

Note
Location
scripts/ecs-health.sh:225
Finding

Health Check Enumerates Unrelated Regional ALB Target Groups

Content
View full analysis
0 else ('empty' if total == 0 else 'unhealthy') result['target_groups'][name] = { 'healthy': healthy_count, 'draining': draining, 'unhealthy': len(unhealthy), 'total': total, 'status': tg_status } if unhealthy: for u in unhealthy: target_id = u['Target']['Id'] state = u['TargetHealth'][ ...[truncated 2019 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
### `scripts/cloudwatch-logs.sh` — Log Analyzer

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/cloudwatch-logs.sh (reported line 402)May include surrounding context.

sh
# Read the services list
  local svc_list
  svc_list=$(cat /tmp/ecs-ad-svcs.$$ 2>/dev/null)
  rm -f /tmp/ecs-ad-svcs.$$

  if [[ -z "$svc_list" ]]; then
    return 0

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/ecs-health.sh (reported line 61)May include surrounding context.

sh
mkdir -p "$OUTDIR"

# Dependencies check
for cmd in curl aws python3; do
  if ! command -v "$cmd" &>/dev/null; then
    echo "Missing dependency: $cmd" >&2
    exit 2

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and documents shell execution plus environment, file read, and file write capabilities, but it does not declare any explicit tool scope such as permissions or allowed-tools. That mismatch weakens containment and review because a host may grant broader execution than operators expect, enabling AWS CLI access, network probes, and local file writes without clear policy declaration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script creates an output directory and later reads and manages health/log-related files under that path, which means service log data may be persisted locally. Although the header documents the output directory variables, it does not clearly warn users that potentially sensitive CloudWatch log contents may be stored on disk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest centers this skill on ECS/ALB/SSL health monitoring and CloudWatch log analysis, but this script's primary purpose is log pulling/analyzing. The auto-diagnose path adds a filesystem-based capability that parses an external health snapshot file and uses it to decide what services to inspect, which is not directly part of log analysis itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script writes service information to a predictable temporary file path in /tmp using only the process ID, which is not a secure temporary-file pattern. On a multi-user system, another local user could race, pre-create, or replace that path with a symlink or file to influence behavior, expose service data, or interfere with file deletion.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.