Back to skill

Security audit

cargo-segmentation

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Cargo segmentation skill, but it should be reviewed carefully because it installs a mutable npm CLI and can access, export, and modify authenticated workspace audience data.

Before installing, pin and review the Cargo CLI version instead of using `latest`, run it in a least-privileged environment, prefer email or OAuth login for interactive use, protect any CI token outside command history and logs, confirm the active workspace before writes, and treat fetched records, signed download URLs, and troubleshooting transcripts as sensitive customer data.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned npm CLI Dependency Permits Mutable Supply-Chain Code Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:34
Finding

API Token Is Accepted Directly Through a Command-Line Argument

Content
View full analysis
(CI) ``` ### Technical Analysis The documentation presents `--token ` as a supported authentication method, particularly for CI. Supplying a secret directly as a command-line argument can expose it through several operating-system and automation surfaces: - Shell history files. - Process listings or process-inspection interfaces while the command is running. - CI job logs when command echoing or debug tracing is enabled. - Terminal recordings and audit logs. - Error reports or copied command transcripts. The actual degree of process-list exposure depends on the operating system and isolation configuration. Nevertheless, command-line arguments are not an appropriate general-purpose secret transport mechanism. The same Skill later asks users to include commands when filing reports, which increases the importance of explicitly redacting tokens from command transcripts. ### Attack Path 1. A user or CI operator authenticates by replacing the placeholder in `cargo-ai login --token ` with a real token. 2. The complete command is stored in shell history, displayed in CI output, captured by terminal or audit logging, or observed through process inspection. 3. A local user, log reader, CI collaborator, or other principal with access to that surface obtains the token. 4. The attacker submits the stolen token to Cargo services. 5. The attacker accesses or changes workspace resources within the scopes and lifetime granted to the ...[truncated 683 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description lists trigger phrases like "save this as a list" and "narrow this down to," which are common conversational phrases that could apply in many contexts beyond Cargo segmentation. Although some examples are domain-related, these broad phrases are not narrowly constrained enough to clearly limit when the skill should activate.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to run npx @cargo-ai/cli without pinning a version, which can fetch and execute the latest published package at runtime. That creates a supply-chain risk: a compromised or malicious upstream release could be executed immediately in the user's environment, and the bootstrap section explicitly involves authenticated CLI use against workspace data, increasing blast radius.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The skill documentation instructs users to sign in using email, OAuth, or API token and later describes downloading full datasets via signed URL, but it does not explicitly warn that these actions may involve sensitive workspace data or credential handling. Because this is a markdown file, user-facing safety disclosures about privacy-impacting behavior are expected when the skill can access or export user data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes a natural-language instruction that enforces a French spelling (conjonction) as the required key. Under the policy rule, forcing a specific language or locale without opt-in can be a violation unless the locale constraint is clearly justified; here it is presented as a requirement but not explicitly justified as an API compatibility constraint.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.