Back to skill

Security audit

Password

Security checks for vulnerabilities and agentic risk

Overview

This is a plausible password utility, but it handles real passwords in unsafe command-line arguments and under-discloses breach-check network behavior and unsupported storage/rotation claims.

Review before installing. Avoid entering real passwords as command-line arguments with this skill; use only generated test values unless the tool is updated to read secrets from a hidden prompt or standard input. Treat breach checking as an external network operation to Have I Been Pwned, and do not rely on the advertised storage or rotation features because they are not implemented in the inspected artifact.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/script.sh:136
Finding

Passwords Exposed Through Command-Line Arguments

Content
View full analysis
" ``` ```bash cmd_entropy() { local pw="${1:-}" [[ -z "$pw" ]] && die "Usage: password entropy " ``` ```bash cmd_check_leak() { local pw="${1:-}" [[ -z "$pw" ]] && die "Usage: password check-leak " ``` ```bash case "$cmd" in generate) cmd_generate "$@" ;; strength) cmd_strength "$@" ;; entropy) cmd_entropy "$@" ;; batch) cmd_batch "$@" ;; check-leak) cmd_check_leak "$@" ;; ``` ### Technical Analysis The `strength`, `entropy`, and `check-leak` operations receive passwords as positional command-line arguments. Command-line arguments are not an appropriate transport mechanism for secrets because they may be: - Recorded in interactive shell history. - Exposed through process inspection facilities while the command is running. - Captured by process accounting, diagnostic tools, audit systems, wrappers, or terminal logging. - Retained in automation logs when the command is executed by another program. Although the breach-checking implementation sends only the first five characters of a SHA-1 hash to the Have I Been Pwned API, that privacy measure does not protect the password before it reaches the script. The local command invocation still exposes the original plaintext password. ### Attack Path 1. A user invokes a command such as: ```bash scripts/script.sh check-leak 'SecretPassword123!' ``` 2. The plaintext password becomes part of the process argument vector and may also be written to the user's shell-history file. 3. A local user or monitoring process wit ...[truncated 719 chars]
Remediation
View remediation
&2 ``` - Support standard input for non-interactive use, with documentation warning users to avoid plaintext command-line arguments. - Prefer reading from `/dev/tty` for interactive prompts so redirected output does not expose the password. - Clear the variable after use where practical: ```bash unset pw ``` - Update `SKILL.md` and command usage messages so examples never place passwords directly on the command line. - If backward compatibility requires positional arguments temporarily, emit a prominent warning and deprecate that interface. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:47
Finding

Modulo Bias Weakens Generated Passwords, PINs, Shuffles, and Passphrases

Content
View full analysis
0; i-- )); do local j=$(( rand_vals[idx] % (i + 1) )) ((idx++)) || true local tmp="${arr[$i]}" arr[$i]="${arr[$j]}" arr[$j]="$tmp" done ``` ```bash while IFS= read -r val; do [[ $idx -ge $word_count ]] && break local word_idx=$(( val % dict_size )) passphrase+=("${words[$word_idx]}") ((idx++)) done <<< "$rand_bytes" ``` ### Technical Analysis The script obtains random values from `/dev/urandom`, but maps those values into smaller ranges with the modulo operator. Modulo mapping is uniform only when the size of the source range is exactly divisible by the destination range. For character generation, the source consists of 256 possible byte values. If a character set has a size that does not divide 256, some characters receive more source values than others and therefore occur more frequently. For example, a 62-character alphanumeric set gives some characters five corresponding byte values while others receive only four. The same principle affects Fisher-Yates shuffle indexes and Diceware word selection. The bias from a 32-bit source is smaller in those cases, but the implementation still does not provide mathematically uniform sampling. Consequently, the generated outputs have lower effect ...[truncated 1187 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/script.sh:51
Finding

Post-Increment Operations Can Terminate Credential Generation Under errexit

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior does not match the apparent implementation and capability profile: the description claims password storage, secret rotation, and breach checking, while those functions are either unimplemented or imply external network access without declared permissions. This mismatch is dangerous because users and orchestrators may trust the metadata, unknowingly exposing secrets to network services or relying on security-sensitive features that do not actually exist.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises shell-backed commands but declares no tool scope such as permissions or allowed-tools. In an agent environment, this can lead to overly broad or implicit shell execution authority, making it harder to constrain what the skill may run and increasing the risk of command misuse or abuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

A password-management skill handles highly sensitive data, yet the description provides no warning about the privacy and security implications of storing passwords or sending password-derived data to breach-checking services. In this context, missing warnings increase the chance that users input real secrets without understanding retention, transmission, or exposure risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest describes a broader password-management skill including storage and rotating secrets, but the implemented commands shown in the CLI help cover generation, strength/entropy analysis, breach checking, diceware, and PIN generation only. This is a semantic mismatch between the declared skill scope and the actual behavior exposed by the code.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The check-leak command transmits derived password material to an external service (api.pwnedpasswords.com). Although it uses the HIBP k-anonymity design and does not send the raw password, it still discloses a SHA-1 prefix correlated to the secret and creates network metadata exposure; in a password-management context, any outbound secret-related transmission increases sensitivity.

Content

Scanner excerpt · scripts/script.sh (reported line 314)May include surrounding context.

sh
echo ""

    local response
    response=$(curl -sS "https://api.pwnedpasswords.com/range/${prefix}" 2>&1) || {
        die "Failed to reach HIBP API. Check your internet connection."
    }

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The inline documentation describes an in-place shuffle, but Bash strings are immutable here and the function copies characters into an array, shuffles that array, and emits a new string. This is a documentation-to-code contradiction, albeit with limited security impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.