Back to skill

Security audit

cargo-storage

Security checks for vulnerabilities and agentic risk

Overview

This Cargo storage skill matches its purpose, but it needs review because it exposes token-bearing webhook URLs and can alter or delete workspace data.

Install only if you want an agent to administer Cargo workspace storage. Require confirmation before deletes, relationship replacements, exports, token creation, or webhook setup. Treat webhook URLs containing tokens as secrets, avoid placing them in chat, logs, files, or shell history, prefer header-based or secret-manager delivery, and rotate any token that may have been exposed.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill provides exact steps to derive and output a functioning webhook URL with embedded credentials from workspace token data. In an agent setting, this is especially dangerous because the agent may obediently reveal the URL back to the user or store it in tool logs, turning a documentation example into a credential disclosure vector.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This section expands from ordinary storage management into instructions for deriving a live ingest endpoint and obtaining an API token, which materially broadens the skill from schema/query operations into secret-handling and external write access. That increases the chance an agent will surface or operationalize sensitive connection details in contexts where the user only asked about storage structure or records.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The text directs the agent to hand out or derive webhook connection details for ingest models except in a narrow auto-ingest case. Even before the explicit token-printing example, this normalizes disclosure of sensitive integration endpoints and increases the likelihood of exposing connection material beyond least-privilege expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example explicitly retrieves a raw API token and prints a full ingest URL containing that token to stdout. Tokens embedded in command output, terminal history, logs, screenshots, shell tracing, or agent transcripts are easily leaked and can grant direct write access to the model ingest endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example shows a destructive column remove command without any warning about permanent data loss, downstream schema breakage, or the need to verify dependencies first. In a storage-management skill, users may copy commands directly, so omission of safety guidance materially increases the chance of accidental destructive changes.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/examples/columns.md (reported line 130)May include surrounding context.

md
## Column kinds reference

| Kind       | Use for                                                     | Required extra fields                                                                                    |
| ---------- | ----------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
| `custom`   | User-defined fields                                         | —                                                                                                        |
| `computed` | Values derived from an expression over other columns        | `expression`; optionally `columnsUsed`                                                                   |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · references/examples/columns.md (reported line 132)May include surrounding context.

md
| Kind       | Use for                                                     | Required extra fields                                                                                    |
| ---------- | ----------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- |
| `custom`   | User-defined fields                                         | —                                                                                                        |
| `computed` | Values derived from an expression over other columns        | `expression`; optionally `columnsUsed`                                                                   |
| `metric`   | Aggregated values from a related model                      | `relationshipUuid`, `aggregation.function`, `aggregation.columnSlug`; optionally `filter`                |
| `lookup`   | A single field value pulled from a related model via a join | `join.toModelUuid`, `join.fromColumnSlug`, `join.toColumnSlug`, `extractColumnSlug`; optionally `filter` |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example explicitly constructs a webhook URL containing a live API token in a shell command and echoes the full URL, but only warns not to write it to files or reports. It does not warn that embedding secrets in command lines can leak them through shell history, terminal scrollback, process listings, CI logs, or copied commands, which is a real secret-handling weakness in operational guidance.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/examples/ingest-webhook.md (reported line 91)May include surrounding context.

bash
# one record
curl -X POST "$BASE/v1/models/$MODEL_UUID/records/ingest?token=$TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"email":"ada@example.com","company":"example.com"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example documents a destructive model remove command with only a dependency-failure note, but it does not clearly warn that the operation deletes a model and may cause irreversible data loss or workflow breakage if used incorrectly. In a storage-management skill that directly manipulates business data models, omission of a prominent deletion warning increases the risk of accidental destructive actions by users or downstream agents.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This is a markdown file, so SQP-2 applies. The section explains how to download full result sets and notes that the response is a signed URL, but it provides no warning that exports may contain sensitive data or that signed URLs should be handled carefully because they grant access to the exported results.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The troubleshooting guide recommends running npx @cargo-ai/cli without pinning a specific version. That allows execution of whatever package version is current at install time, which can introduce supply-chain risk if a malicious or compromised release is published. In a skill that directly manages workspace models and executes storage queries, CLI compromise could expose or alter business data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The document explains that relationship set replaces the entire dataset relationship set and deletes any omitted entries, but it does so as routine troubleshooting guidance without an explicit warning or confirmation step. In this storage-management context, users may follow the advice and unintentionally delete relationship definitions, causing integrity loss or breaking dependent workflows.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.