Back to skill

Security audit

cargo-connection

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated Cargo connector-management purpose, but it handles credentials and mutable CLI installation in ways users should review carefully.

Review this skill before installing in production or shared agent environments. Prefer a pinned @cargo-ai/cli version, avoid pasting real tokens or connector API keys into command lines or chat, and treat connector list/get JSON as potentially sensitive because it may include credential config for non-credit connectors. Rotate any credentials accidentally exposed in logs or transcripts.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Cargo CLI Dependency Permits Unreviewed Supply-Chain Changes

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:36
Finding

Authentication Tokens and Connector API Keys Are Passed Through Command-Line Arguments

Content
View full analysis
(CI) cargo-ai whoami # confirm the active workspace before any write ``` `references/examples/connectors.md:45-49`: ```bash ## Update a connector cargo-ai connection connector update --uuid --name "Clearbit - Staging" cargo-ai connection connector update --uuid --config '{"apiKey":"new-key"}' ``` `references/troubleshooting.md:11`: ```markdown | `Unauthorized` or `Forbidden` | Bad or expired credentials | Re-run `cargo-ai login --oauth` (browser sign-in) or `cargo-ai login --token `; verify with `cargo-ai whoami` | ``` ### Technical Analysis The examples encourage users to substitute reusable secrets directly into command-line arguments. Depending on the operating system and execution environment, these values may be exposed through: - Shell history files. - Process inspection interfaces while the command is running. - Terminal session recording. - CI/CD command logs. - Agent tool-call transcripts and conversation history. - Debugging or telemetry systems that capture command lines. - Audit logs maintained by endpoint-management software. Quoting JSON does not protect the API key from these channels. Likewise, replacing `` with a real Cargo token places that token in the command line. The risk is amplified in an Agent context because tool invocations and outputs may b ...[truncated 1339 chars]
Remediation
View remediation
\ --config-file /secure/path/connector-config.json ``` 4. Ensure credential files have restrictive permissions and are securely deleted when no longer required. 5. Integrate with operating-system keychains or dedicated secret managers where practical. 6. Explicitly warn users never to paste real tokens or API keys into chat, Agent prompts, command examples, or logs. 7. Configure CI systems to mask secret values and disable command echoing around authentication operations. 8. Document immediate revocation and rotation procedures for any credential accidentally exposed through command history or logs. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
references/response-shapes.md:5
Finding

Connector Enumeration May Expose Stored Integration Credentials in Standard Output

Content
View full analysis
# → Returns the full connector object (same shape as an item from connector list) ``` ### Technical Analysis The documented response model states that `connector list` and `connector get` return full connector objects, and that the `config` field contains integration-specific credentials when `useCredits` is false. The skill also states that commands print JSON to standard output. Consequently, routine discovery commands may place credential-bearing configuration into terminal output, redirected files, CI logs, Agen ...[truncated 1900 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill instructs users to run npx @cargo-ai/cli, which resolves and executes the latest package version at runtime rather than a pinned, reviewed release. That creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious update is published, users may execute untrusted code during connector setup and authentication flows.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example shows credential material being passed directly on the command line in JSON (for example, an apiKey in --config) without any warning about secret exposure. Command-line arguments are commonly captured in shell history, process listings, logs, and support transcripts, so users may unintentionally leak live connector credentials while following the documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 15)May include surrounding context.

md
## Connectors

| Symptom                                 | Cause                                            | Fix                                                                                              |
| --------------------------------------- | ------------------------------------------------ | ------------------------------------------------------------------------------------------------ |
| `connector get` returns not found       | Wrong UUID                                       | Re-run `connector list` to get the correct UUID                                                  |
| `connector create` fails                | Integration slug doesn't exist                   | Run `integration list` to find valid `integrationSlug` values                                    |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 25)May include surrounding context.

md
## Connector autocomplete

| Symptom                                              | Cause                                                              | Fix                                                                                                                          |
| ---------------------------------------------------- | ------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------- |
| `connector autocomplete` returns empty results       | Wrong autocomplete slug or params                                  | Re-check the `uiSchema` from `integration get <slug>` — use the exact `ui:options.slug` and pass required `params`           |
| `Invalid autocomplete params` error                  | Missing or wrong params keys                                       | Check `ui:options.params` in the `uiSchema` — each key listed there must be provided in `--params` with an actual value       |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 31)May include surrounding context.

md
| `Invalid autocomplete params` error                  | Missing or wrong params keys                                       | Check `ui:options.params` in the `uiSchema` — each key listed there must be provided in `--params` with an actual value       |
| `connectorNotFound` reason                           | Wrong connector UUID                                               | Re-run `connector list` to get the correct UUID                                                                               |
| `failedToGetIntegration` reason                      | Integration doesn't support autocomplete for this slug             | Verify the autocomplete slug exists in the integration's `uiSchema` — not all fields use autocomplete                         |
| Stale or outdated autocomplete results               | Results are cached (default 30 minutes)                            | Pass `--refresh` to bypass the cache                                                                                          |
| Used a freeform value instead of autocomplete result  | Field requires a specific value from the autocomplete result set   | Always check `uiSchema` for `IntegrationAutocompleteWidget` — if present, fetch and use a `value` from the autocomplete results |

## Integrations

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The document states that when useCredits is false, config contains integration-specific credentials, but it does not include any caution about sensitive secret handling, storage, or exposure. Because this is a markdown file and it documents behavior affecting credentials, a brief user warning would improve disclosure of privacy and security impact.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.