Back to skill

Security audit

Env Config

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches an environment-file helper, but it also ships a generic command script that quietly stores user arguments in persistent plaintext logs.

Review this before installing if you may pass real secrets, tokens, passwords, or private paths as command arguments. The main env helper is purpose-aligned, but the bundled generic script can leave sensitive arguments behind in local plaintext files, so avoid using those generic add/run/search commands with secret material unless you first remove or contain that logging behavior.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:5
Finding

Persistent Plaintext Storage of Potentially Sensitive Command Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh, lines 5–7 and 32–78
Vulnerability Type: Persistent plaintext logging of user-supplied arguments
Risk Level: Medium

Vulnerable Code

bash
DATA_DIR="${ENV_CONFIG_DIR:-${XDG_DATA_HOME:-$HOME/.local/share}/env-config}"
DB="$DATA_DIR/data.log"
mkdir -p "$DATA_DIR"
bash
_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

cmd_run() {
    echo "  Running: $1"
    _log "run" "${1:-}"
}

cmd_config() {
    echo "  Config: $DATA_DIR/config.json"
    _log "config" "${1:-}"
}

cmd_status() {
    echo "  Status: ready"
    _log "status" "${1:-}"
}

cmd_init() {
    echo "  Initialized in $DATA_DIR"
    _log "init" "${1:-}"
}

cmd_list() {
    [ -f "$DB" ] && cat "$DB" || echo "  (empty)"
    _log "list" "${1:-}"
}

cmd_add() {
    echo "$(date +%Y-%m-%d) $*" >> "$DB"; echo "  Added: $*"
    _log "add" "${1:-}"
}

cmd_remove() {
    echo "  Removed: $1"
    _log "remove" "${1:-}"
}

cmd_search() {
    grep -i "$1" "$DB" 2>/dev/null || echo "  Not found: $1"
    _log "search" "${1:-}"
}

cmd_export() {
    [ -f "$DB" ] && cat "$DB" || echo "No data"
    _log "export" "${1:-}"
}

cmd_info() {
    echo "  Version: $VERSION | Data: $DATA_DIR"
    _log "info" "${1:-}"
}

Technical Analysis

The script creates a persistent data directory before command dispatch and records command arguments in predictable plaintext files. Most commands append their first argument to history.log, while cmd_add also appends the complete argument list to data.log.

The project is presented as an environment-configuration manager, where arguments may reasonably contain environment values, tokens, credentials, configuration strings, or sensitive filesystem paths. The logging implementation performs no secret redaction, input classification, consent check, ...[truncated 2104 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove persistent argument logging unless it is necessary for the documented functionality.

  2. Make telemetry or command-history storage explicitly opt-in and document its location, contents, retention period, and security implications.

  3. Never record raw secret-bearing arguments. Redact values matching sensitive names such as PASSWORD, SECRET, TOKEN, KEY, and credential-bearing URLs.

  4. Establish private permissions before creating storage:

    bash
    umask 077
    mkdir -p -- "$DATA_DIR"
    chmod 700 -- "$DATA_DIR"
    touch -- "$DATA_DIR/history.log" "$DB"
    chmod 600 -- "$DATA_DIR/history.log" "$DB"
    
  5. Reject or normalize carriage returns and newline characters before writing user-controlled data to logs.

  6. Use printf instead of echo for predictable data handling:

    bash
    safe_value=${2//$'\n'/ }
    safe_value=${safe_value//$'\r'/ }
    printf '%s %s: %s\n' "$(date '+%m-%d %H:%M')" "$1" "$safe_value" >> "$DATA_DIR/history.log"
    
  7. Avoid creating persistent state for read-only operations such as help, version, status, and info.

  8. Add automated tests verifying that sensitive arguments are not persisted, generated files are private, and multiline input cannot forge additional log entries.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (37)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 10)May include surrounding context.

sh
CMD="${1:-help}"; shift 2>/dev/null || true

# Parse flags
PROJECT="node" FILE=".env" OUTPUT="" KEY="" VALUE=""
while [[ $# -gt 0 ]]; do
    case "$1" in
        --project)  PROJECT="$2"; shift 2 ;;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 385)May include surrounding context.

sh
CMD="${1:-help}"; shift 2>/dev/null || true

# Parse flags
PROJECT="node" FILE=".env" OUTPUT="" KEY="" VALUE=""
while [[ $# -gt 0 ]]; do
    case "$1" in
        --project)  PROJECT="$2"; shift 2 ;;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 388)May include surrounding context.

sh
CMD="${1:-help}"; shift 2>/dev/null || true

# Parse flags
PROJECT="node" FILE=".env" OUTPUT="" KEY="" VALUE=""
while [[ $# -gt 0 ]]; do
    case "$1" in
        --project)  PROJECT="$2"; shift 2 ;;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 269)May include surrounding context.

sh
cat <<'GITIGNORE'
# ---- 环境变量文件 ----
.env
.env.local
.env.*.local
.env.development
.env.production

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 271)May include surrounding context.

sh
.env
.env.local
.env.*.local
.env.development
.env.production
.env.staging

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 272)May include surrounding context.

sh
.env.local
.env.*.local
.env.development
.env.production
.env.staging

# 保留示例文件

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 33)May include surrounding context.

md
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 2)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 28)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 89)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 268)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 294)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 382)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 397)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 403)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 425)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 429)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 434)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 437)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 445)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 451)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/env.sh (reported line 452)May include surrounding context.

sh
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tips.md (reported line 2)May include surrounding context.

md
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tips.md (reported line 7)May include surrounding context.

md
# Env Config Manager — tips.md
## .env 最佳实践
1. 每个项目都有 `.env.example`(不含真实值)
2. `.env` 加入 `.gitignore`
3. 变量名全大写下划线分隔: `DATABASE_URL`

Static analysis

No suspicious patterns detected.