Back to skill

Security audit

Zentao API Skills(禅道 API 技能)

Security checks for vulnerabilities and agentic risk

Overview

This ZenTao API skill is mostly purpose-aligned, but its credential handling and eval-based authentication flow create risks that users should review before installing.

Review this carefully before installing. Use it only with a trusted ZenTao server, prefer HTTPS-only URLs, avoid the documented eval flow unless it is fixed, and treat ~/.zentao-token.json as a sensitive credential file. Confirm every write or delete operation unless you deliberately want the agent to mutate live ZenTao records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/get-token.sh:14
Finding

Arbitrary Shell Command Execution Through Unsafe eval Output

Content
View full analysis
/tmp/eval-executed) ``` causes the script to emit: ```bash ZENTAO_TOKEN=$(id > /tmp/eval-executed) ``` The documented `eval` then executes the command substitution. ### Attack Path 1. An attacker controls or compromises a configured ZenTao endpoint, tampers with `~/.zentao-token.json`, or influences a relevant environment variable. 2. The attacker supplies a URL, token, or account value containing shell syntax such as command substitution or an injected newline followed by a command. 3. The user or Agent follows `SKILL.md` and runs: ```bash eval "$(bash scripts/get-token.sh)" ``` 4. `get-token.sh` prints the ma ...[truncated 634 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get-token.sh:61
Finding

Long-Lived API Token Cached Without Explicit Restrictive Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get-token.sh:72
Finding

Credentials and API Tokens Can Be Transmitted Over Unencrypted HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (13)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
- **PUT 编辑接口**:先 GET 详情获取当前完整数据,再将用户修改的字段覆盖进去一并提交
- **状态流转操作** (resolve/close/activate/start/finish/change) 通常有独立的必填字段,不需要先 GET 详情
- 写操作前向用户确认,用户明确要求不确认则直接执行
- 401 响应表示 token 已失效,执行 `rm ~/.zentao-token.json` 清除缓存后重新运行
- **字段名不一致注意**:POST builds 用 `executionID`,PUT builds 用 `execution`;PUT testcases 的模块字段为 `moudule`(规范中的拼写)

## 完整 API 参考

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · scripts/get-token.sh (reported line 71)May include surrounding context.

sh
exit 1
fi

RESPONSE=$(curl -s -X POST "${ZENTAO_URL}/api.php/v2/users/login" \
  -H "Content-Type: application/json" \
  -d "{\"account\": \"${ZENTAO_ACCOUNT}\", \"password\": \"${ZENTAO_PASSWORD}\"}")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill instructs use of shell commands such as eval "$(bash scripts/get-token.sh)", curl, and rm ~/.zentao-token.json, but it does not declare any explicit tool scope or allowed-tools restrictions. In a skill that can authenticate and perform write operations against a project-management system, undeclared shell capability increases the chance of overbroad execution and makes it harder for a host agent to enforce least privilege.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to match many ordinary project-management requests, causing the skill to activate in situations where the user may not have intended ZenTao API access. Because this skill supports create/update/delete and state transitions, accidental invocation can lead to unintended data changes or unnecessary credential handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly persists ZENTAO_URL, ZENTAO_TOKEN, and ZENTAO_ACCOUNT into ~/.zentao-token.json without any warning about local credential exposure, file permissions, token lifetime, or multi-user system risks. Storing active API tokens on disk can enable credential theft and long-lived unauthorized access if the host is compromised or shared.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

L048 指定“以清晰易读的格式向用户展示结果”,通篇文档仅以中文描述和示例引导,且未说明可根据用户语言偏好切换输出语言。若组织要求不得在未征得用户同意时强制特定语言,这种默认单一语言行为可能构成自然语言策略违规。

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

获取进行中的项目及其执行

bash
curl -s "$ZENTAO_URL/api.php/v2/projects?browseType=doing&recPerPage=100" -H "token: $ZENTAO_TOKEN"
curl -s "$ZENTAO_URL/api.php/v2/projects/{projectID}/executions?browseType=doing" -H "token: $ZENTAO_TOKEN"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation instructs clients to send a bearer-like token in headers but does not state that the token is a sensitive secret that must not be logged, exposed, embedded in prompts, or transmitted over insecure channels. In an agent skill context, missing handling guidance increases the chance of credential leakage through debugging, trace logs, chat transcripts, or misconfigured integrations, which could enable unauthorized API access across many destructive endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file describes creation, modification, and deletion operations such as creating users and deleting users, but it provides no warning that these endpoints change or permanently remove data. Under the markdown-specific SQP-2 criteria, documentation should disclose behaviors that can affect user data or system integrity when such actions are exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script persists a long-lived ZenTao API token to ~/.zentao-token.json without setting restrictive file permissions or warning the user that credentials are being stored locally. On multi-user systems, shared home directories, backups, or endpoint compromise, this cached token could be recovered and reused to access the ZenTao instance without needing the password.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/get-token.sh (reported line 71)May include surrounding context.

sh
exit 1
fi

RESPONSE=$(curl -s -X POST "${ZENTAO_URL}/api.php/v2/users/login" \
  -H "Content-Type: application/json" \
  -d "{\"account\": \"${ZENTAO_ACCOUNT}\", \"password\": \"${ZENTAO_PASSWORD}\"}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script sends ZENTAO_ACCOUNT and ZENTAO_PASSWORD in a POST request to the login endpoint, which is a sensitive network operation involving credential transmission. The code does not present a confirmation prompt or explicit disclosure at execution time that credentials are being sent to the configured server.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

All natural-language content in the file is presented only in Chinese, with no indication that this locale restriction is intentional, optional, or region-specific. The stated policy flags language/locale constraints when a skill forces a specific language without user opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.