Back to skill

Security audit

cmaiot-basic-general-kit

Security checks for vulnerabilities and agentic risk

Overview

This skill is a plausible CMAIoT management tool, but it stores powerful IoT access keys in plaintext and can change device state without built-in confirmation.

Install only if you are comfortable giving this skill credentials that can control your CMAIoT products and devices. Use least-privilege product keys if possible, rotate any key entered on shared systems, review shell history exposure, and manually confirm any create, set, call, enable, disable, or live-video request before allowing an agent to run it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cmaiot.js:8
Finding

Product Access Key Exposed Through Command-Line Arguments and Plaintext Storage

Content
View full analysis
p.productId === productId).accessKey; } function addProduct(productId, accessKey) { if (!productId || !accessKey) { showHelp(); return false; } const exist = config.products.find(p => p.productId === productId); if (exist) { return false; } config.products.push({ productId, accessKey }); fs.writeFileSync(config_file, JSON.stringify(config, null, 2)); return true; } ``` `scripts/cmaiot.js:119-131`: ```javascript async function main() { const cmd = process.argv[2]; const target = process.argv[3]; const jsonString = process.argv[4]; if (!cmd) { showHelp(); return; } config = readConfig(); ``` ### Technical Analysis The documented credential-enrollment interface requires users to place the product ID and access key directly in a command-line argument. Command-line secrets may be retained in shell history and can be exposed through process-inspection facilities to users or processes with sufficient local visibility. After parsing the argument, the script stores the access key unencrypted in `scripts/config.json`. The call to `fs.writeFileSync` does not specify a restrictive file mode. Consequently, effective permissions depend on the current process umask an ...[truncated 2573 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (20)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The documented behavior understates and inconsistently describes the skill's capabilities, while the underlying functionality appears to include credential persistence, device creation/control, video-related operations, and LwM2M management beyond the stated scope. This mismatch can mislead users and policy systems into authorizing a skill that has broader and more sensitive powers than advertised, increasing the risk of unauthorized device changes or exposure of sensitive endpoints such as live video URLs.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 18)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 64)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 65)May include surrounding context.

md
scripts/cmaiot.js add productId/accessKey

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a network-capable script against an external IoT platform but does not declare any tool scope such as allowed-tools or permissions. That weakens sandboxing and reviewability, making it easier for the skill to perform undeclared remote actions like querying device state, changing configuration, or controlling devices without explicit governance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script stores product access keys in a local config.json file in plaintext without warning, encryption, or permission hardening. If the local filesystem is accessible to other users, backups, or malware, these credentials can be recovered and used to query or control IoT products and devices on the CMAIoT platform.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The help text says cmaiot call productId/deviceName/serviceId jsonString invokes a device service, implying the third path segment is the service ID. In the implementation, the parsed third segment is stored as identifier, but the request body uses serviceId, which is never defined, so the documented behavior is contradicted by the actual code path.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The manifest says the skill can query/control products and devices and obtain video playback addresses. However, the code also implements video AI capability listing and device service endpoints (ability, algo, service) that go beyond querying/control and playback-address retrieval as described.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The tool performs state-changing operations such as device creation, property setting, service invocation, and enable/disable actions immediately with no confirmation, dry-run mode, or prominent warning. In an agent setting, malformed prompts, operator mistakes, or indirect instruction injection could trigger unintended changes to physical or logical device state.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

Multiple help and runtime messages are presented only in Chinese, and the script does not provide any language selection or indicate that it is intentionally limited to a Chinese-speaking audience. This is a natural-language locale policy concern because the skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.