Back to skill

Security audit

Provider Sync

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent provider-model sync tool, but it has a real credential-scope flaw that can send a stored provider API key to a caller-chosen endpoint.

Install only if you trust the publisher and can control how it is invoked. Do not combine stored provider credentials with custom endpoints; avoid --use-provider-config with an explicit --endpoint until origin and HTTPS validation are added. Run dry-run first, review agent alias deletions, and apply only in a private/admin context.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/provider_sync.py:378
Finding

Stored Provider API Key Can Be Forwarded to an Arbitrary Endpoint

Content
View full analysis
Tuple[str, Dict[str, str]]: """Resolve endpoint and Authorization header from config when possible. - If endpoint is empty, derive it from models.providers..baseUrl + '/models' - If Authorization header is missing and apiKey exists, add 'Authorization: Bearer ' NOTE: Do not print apiKey. """ provider_base = f"{provider_root}.{provider_id}" provider_obj = get_path(cfg, provider_base) or {} resolved_endpoint = (endpoint or "").strip() if not resolved_endpoint: base_url = (provider_obj.get("baseUrl") or "").strip() if not base_url: die(f"endpoint not provided and {provider_base}.baseUrl is missing") resolved_endpoint = base_url.rstrip("/") + "/models" # auth header api_key = provider_obj.get("apiKey") if isinstance(api_key, str) and api_key.strip(): if not get_header_case_insensitive(headers, "Authorization"): headers = dict(headers) headers["Authorization"] = f"Bearer {api_key.strip()}" return resolved_endpoint, headers ``` The resulting endpoint and headers are subsequently used in the outbound request: ```python headers = parse_headers(args.header) # Resolve endpoint + Authorization header from config when requested (or when endpoint omitted). if args.use_provider_config or not (args.endpoint or "").strip(): args.endpoint, headers = resolve_endpoint_and_auth_headers( cfg, args.provider_root, args.provider_id, args.endpoint, headers ) body = load_json(args.body_file) if args.bod ...[truncated 3287 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (22)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented purpose understates the skill's actual behavior: it not only syncs model lists, but also performs outbound probing, writes backups/cache, and prunes additional config state such as agents.defaults.models. This mismatch is dangerous because operators may authorize or invoke the skill expecting a limited preview/apply flow while it actually expands the attack surface, changes more data than expected, and interacts with remote endpoints in ways that could leak metadata or trigger unintended side effects.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

md
- `scripts/provider_sync.py`

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises operations that imply network access, shell execution, and local file read/write, but it does not declare any explicit tool scope or permission boundaries. That makes the effective privilege surface opaque to users and reviewers, increasing the chance of overbroad execution, unsafe deployment, or accidental misuse in environments that auto-grant capabilities.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructions switch into Chinese for the primary invocation and usage guidance, but do not indicate that users may choose another language or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy because it imposes a specific language on users without opt-in.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 10)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 22)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 34)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 45)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 56)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 67)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 80)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 92)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples.md (reported line 107)May include surrounding context.

bash
python3 scripts/provider_sync.py \
  --provider-id my-provider \
  --endpoint https://api.example.com/v1/models \
  --mapping-file references/mapping.openai-models.json \
  --normalize-models \
  --preserve-existing-model-fields \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The trigger examples are broad natural-language phrases that could cause the skill to activate in loosely related contexts without clear boundaries or prerequisite checks. In a skill that can sync remote data into configuration and potentially perform real writes after confirmation, overbroad triggering increases the chance of unintended operational changes.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file contains user-facing instructional content in a single forced language. The stated policy flags language or locale constraints when the skill does not offer the user a choice or document a justified region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This markdown file is written entirely in Chinese and does not offer an alternative language, opt-in, or explanation that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documentation is written in Chinese and provides operational instructions without offering a language choice or documenting a justified region-specific constraint. This can violate language/locale policy when users or maintainers are expected to consume the skill in another language by default.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The safety rules are written entirely in Chinese and instruct operators on required behavior, but the file does not indicate that Chinese is optional or that the skill is limited to a Chinese-speaking or region-specific context. This can violate language/locale policy guidance when users are not given a choice or opt-in.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill's stated purpose is syncing provider model lists, but it also mutates agents.defaults.models aliases and can prune existing entries by default. That broadens the blast radius from provider metadata sync to agent routing/config behavior, which can silently redirect or remove model selections and cause unintended operational changes beyond the advertised scope.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/provider_sync.py (reported line 1134)May include surrounding context.

python
base_argv.append(a)

            cmd = [sys.executable, os.path.abspath(__file__)] + base_argv + ["--provider-id", pid, "--output", "json"]
            proc = subprocess.run(cmd, capture_output=True, text=True)
            if proc.returncode != 0:
                # Bubble the underlying error.
                sys.stderr.write(proc.stderr or proc.stdout or "")

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains hard-coded natural-language output in Chinese ("有变化", "没变化", and "提示:如需写入...") for the multi-provider summary path. That forces a specific locale for some users without opt-in or an alternative, which matches the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

When multiple provider IDs are supplied, the script imports subprocess and re-executes itself for each provider. Spawning child processes is not part of the manifest's stated purpose of syncing provider model lists and is an extra execution capability beyond the obvious requirements of config synchronization.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.