Back to skill

Security audit

Kubera

Security checks for vulnerabilities and agentic risk

Overview

This Kubera skill is coherent and not malicious, but it handles sensitive financial data and account updates with broad activation and some under-scoped credential guidance.

Install only if you intend agents to access your Kubera financial data. Use read-only Kubera API credentials by default, avoid passing secrets with --api-key or --secret, and require explicit user confirmation before using update operations or any write-enabled API key.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/kubera.py:19
Finding

API Credentials Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/kubera.py:19-20 and scripts/kubera.py:206-207
Vulnerability Type: Command-line credential exposure
Risk Level: Medium

Vulnerable Code

python
def get_config(args):
    api_key = getattr(args, 'api_key', None) or os.environ.get('KUBERA_API_KEY')
    secret = getattr(args, 'secret', None) or os.environ.get('KUBERA_SECRET')
    if not api_key or not secret:
        print("Error: Set KUBERA_API_KEY and KUBERA_SECRET env vars, or use --api-key/--secret", file=sys.stderr)
        sys.exit(1)
    return api_key, secret
python
parser.add_argument('--api-key', help='Kubera API key')
parser.add_argument('--secret', help='Kubera API secret')

Technical Analysis

The program permits users to provide the Kubera API key and API secret directly through --api-key and --secret. Command-line arguments are not an appropriate secret transport mechanism because they can be recorded in shell history and may be exposed through operating-system process inspection facilities while the program is running.

Possession of both credentials enables an attacker to construct valid HMAC-SHA256 signatures for Kubera API requests. Although the API secret is not transmitted to Kubera, exposing it locally alongside the API key defeats the authentication scheme.

The environment-variable configuration described in SKILL.md is safer than command-line arguments, but the insecure command-line alternative remains explicitly supported and encouraged by the program's error message.

Attack Path

  1. A user invokes the program with credentials on the command line, for example:
    bash
    python3 scripts/kubera.py --api-key API_KEY --secret API_SECRET summary
    
  2. The command and credentials are retained in shell history or temporarily exposed through process argument inspection.
  3. A local attacker or another process with sufficient process-inspe ...[truncated 1096 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the --api-key and --secret command-line options so credentials cannot be supplied through process arguments.
  2. Obtain credentials from protected environment variables, an operating-system credential manager, or a configuration file restricted to the owning user.
  3. If interactive credential entry is needed, use Python's getpass.getpass() for the secret so it is not echoed or stored in shell history.
  4. Update the error message, module documentation, and usage instructions to stop recommending credential-bearing command-line options.
  5. Continue recommending read-only API credentials by default and require users to create a separate, narrowly scoped write-enabled key only when update functionality is necessary.
  6. Advise users who previously supplied credentials through command-line arguments to clear affected shell history securely and rotate the exposed API key and secret.
  7. Avoid logging authentication headers, signatures, command namespaces, or configuration objects that may contain credentials.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Tainted flow: 'req' from os.environ.get (line 33, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/kubera.py (reported line 45)May include surrounding context.

python
method=method
    )
    try:
        with urllib.request.urlopen(req) as resp:
            return json.loads(resp.read())
    except urllib.error.HTTPError as e:
        body = e.read().decode()

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes Python scripts that require environment variables and outbound API access, but it does not declare any explicit tool scope or permission boundaries. In agent environments, this can lead to overbroad execution privileges and unintended access to secrets or networked actions without clear user or platform controls.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill description is triggered by broad financial phrases like finances, investments, holdings, and net worth, which are common in many conversations and may cause the skill to activate in situations where the user did not intend API-backed access to sensitive portfolio data. Because the domain is highly sensitive personal financial information, overbroad activation increases the risk of unnecessary data exposure or unintended account modifications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.