Back to skill

Security audit

Htpasswd

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it handles real authentication files and passwords with unsafe defaults that users should review carefully before installing.

Install only if you are comfortable letting the agent modify htpasswd files you explicitly name. Avoid using it with production authentication files until usernames are handled literally, destructive operations require confirmation, and passwords can be supplied without command-line exposure. Prefer setting HTPASSWD_ALGO=sha512 if you use it, and consider rotating any passwords already entered through command examples or shell history.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:96
Finding

Username Regex and sed Injection Can Modify Unintended Accounts

Content
View full analysis
/dev/null } # Validate username (no colons, no whitespace) validate_username() { local user="$1" if [[ -z "$user" ]]; then die "Username cannot be empty" fi if [[ "$user" =~ : ]]; then die "Username cannot contain ':' character" fi if [[ "$user" =~ [[:space:]] ]]; then die "Username cannot contain whitespace" fi if [[ "${#user}" -gt 255 ]]; then die "Username too long (max 255 characters)" fi } ``` ```bash if user_exists "$file" "$user"; then # Update existing user local tmp tmp="$(mktemp)" sed "s|^${user}:.*|${user}:${hash}|" "$file" > "$tmp" mv "$tmp" "$file" ``` ```bash if ! user_exists "$file" "$user"; then die "User '${user}' not found in '${file}'" fi local tmp tmp="$(mktemp)" grep -v "^${user}:" "$file" > "$tmp" || true mv "$tmp" "$file" ``` ```bash local stored_hash stored_hash="$(grep "^${user}:" "$file" | head -1 | cut -d: -f2-)" ``` ### Technical Analysis The username is directly interpolated into Basic Regular Expressions interpreted by `grep` and `sed`. The validation function only rejects empty usernames, colons, whitespace, and values longer than 255 characters. It does not reject or escape metacharacters such as `.`, `*`, `[`, `]`, `^`, `$`, `\`, `&`, or `|`. Consequently, the supplied username is not treated as a literal htpasswd field. For example, `.*` produces the pattern `^.*:`, which matches every valid account record. In the update path, the same value is also inserted into the sed replacement string, where characters such as `&`, `\`, and the selected `|` delimiter h ...[truncated 1914 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
<user> <password> htpasswd add <file> <user> <password> htpasswd verify <file> <user> <password> ``` The script then passes the password as an argument to OpenSSL: ```bash generate_hash() { local password="$1" local algo="${HTPASSWD_ALGO:-apr1}" case "$algo" in apr1) openssl passwd -apr1 "$password" ;; sha256) # Use SHA-256 with salt local salt salt="$(openssl rand -hex 8)" openssl passwd -5 -salt "$salt" "$password" ;; sha512) # Use SHA-5 ...[truncated 2623 chars]:67
Finding

Plaintext Passwords Are Exposed Through Process Arguments and Shell History

Content
View full analysis
htpasswd add htpasswd verify ``` The script then passes the password as an argument to OpenSSL: ```bash generate_hash() { local password="$1" local algo="${HTPASSWD_ALGO:-apr1}" case "$algo" in apr1) openssl passwd -apr1 "$password" ;; sha256) # Use SHA-256 with salt local salt salt="$(openssl rand -hex 8)" openssl passwd -5 -salt "$salt" "$password" ;; sha512) # Use SHA-512 with salt local salt salt="$(openssl rand -hex 8)" openssl passwd -6 -salt "$salt" "$password" ;; *) die "Unknown algorithm: '${algo}'. Supported: apr1, sha256, sha512" ;; esac } ``` The same command-line design is used by verification: ```bash cmd_verify() { local file="${1:-}" local user="${2:-}" local password="${3:-}" [[ -z "$file" || -z "$user" || -z "$password" ]] && \ die "Usage: ${SCRIPT_NAME} verify " ``` ### Technical Analysis Command-line arguments are not an appropriate transport for plaintext credentials. Passwords entered according to the documented interface can be retained in shell history, terminal session records, audit logs, process-monitoring systems, orchestration logs, or command telemetry. While processing a request, the plaintext password also appears in the argument vector of the Skill process. The script subsequently places it in the argument vector of an `openssl ...[truncated 1515 chars]
Remediation
View remediation
&2 ``` 3. For automation, accept credentials through a protected file descriptor, standard input, or a narrowly permissioned secret file rather than argv or environment variables. 4. Use OpenSSL's supported stdin input mode, where available, so the plaintext is not passed as an argument. Ensure input is provided without adding unintended newline characters. 5. Avoid environment variables for password transport because they may also be visible through process inspection and diagnostic dumps. 6. Update every example and usage message in `SKILL.md` and `script.sh` so users are not encouraged to place passwords in shell commands. 7. Document safe non-interactive integration with secret managers and ensure CI/CD systems mask any unavoidable secret-bearing output. 8. Advise users to rotate passwords that may already have been recorded in shell histories or logs. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:66
Finding

Weak APR1/MD5 Password Hashing Is Enabled by Default

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
86% confidence
Finding

The skill exposes a destructive delete operation against user-supplied file paths without any documented guardrails, path restrictions, or confirmation requirements. In an agent setting, this can be abused through prompt or parameter manipulation to target sensitive authentication files, remove legitimate users, or alter access control unexpectedly.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

htpasswd verify /etc/nginx/.htpasswd admin MySecretPass

Delete a user

htpasswd delete /etc/nginx/.htpasswd editor

text

### Example Output

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/script.sh (reported line 46)May include surrounding context.

sh
echo "Examples:"
  echo "  ${SCRIPT_NAME} create /etc/nginx/.htpasswd admin secret123"
  echo "  ${SCRIPT_NAME} add /etc/nginx/.htpasswd newuser pass456"
  echo "  ${SCRIPT_NAME} delete /etc/nginx/.htpasswd olduser"
  echo "  ${SCRIPT_NAME} verify /etc/nginx/.htpasswd admin secret123"
  echo "  ${SCRIPT_NAME} list /etc/nginx/.htpasswd"
  echo ""

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill advertises shell-capable behavior but does not declare any explicit tool scope or allowed-tools restrictions. In an agent environment, this increases the chance the skill will invoke shell operations on arbitrary files or paths without policy-level constraints, which weakens containment and reviewability.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

md
## When to Use

1. **Setting up basic auth** — `htpasswd create /etc/nginx/.htpasswd admin secret` to create a new file
2. **Managing users** — `htpasswd add` to add users, `htpasswd delete` to remove them
3. **Password verification** — `htpasswd verify` to check if a password is correct
4. **Security audits** — `htpasswd list` shows all users and their hash types

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The examples repeatedly place plaintext passwords directly on the command line, which can leak through shell history, process listings, audit logs, terminal recordings, and agent transcripts. Because this is a credential-management skill, normalizing unsafe secret handling is especially risky and may expose real authentication material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script requires passwords as positional command-line arguments for create, add, and verify, and its help text demonstrates this usage. On multi-user systems or in CI/job runners, command-line arguments can be exposed through process listings, shell history, audit logs, and orchestration metadata, causing plaintext credential disclosure.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/script.sh (reported line 143)May include surrounding context.

sh
local hash
  hash="$(generate_hash "$password")"
  echo "${user}:${hash}" > "$file"
  chmod 640 "$file"

  echo "┌──────────────────────────────────────────────────┐"
  echo "│  htpasswd File Created                           │"

Static analysis

No suspicious patterns detected.