Back to skill

Security audit

Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent LLM latency tester, but it needs review because it automatically reads stored API keys and uses them in shell network calls.

Review before installing if you store real provider keys under pass shared. Run it only when you intentionally want to spend a small amount of API quota, and consider changing the script to use explicit runtime confirmation and safer secret handling before using production or high-value keys.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ping.sh:13
Finding

API Credentials Exposed Through Process Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: scripts/ping.sh, lines 13–58
Vulnerability Type: API credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

bash
(ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
  -X POST "https://api.anthropic.com/v1/messages" \
  -H "x-api-key: $ANTHROPIC_KEY" -H "anthropic-version: 2023-06-01" -H "content-type: application/json" \
  -d '{"model":"claude-sonnet-4-20250514","max_tokens":1,"messages":[{"role":"user","content":"hi"}]}')
bash
(ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
  -X POST "https://api.anthropic.com/v1/messages" \
  -H "x-api-key: $ANTHROPIC_KEY" -H "anthropic-version: 2023-06-01" -H "content-type: application/json" \
  -d '{"model":"claude-opus-4-20250514","max_tokens":1,"messages":[{"role":"user","content":"hi"}]}')
bash
(ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
  -X POST "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash:generateContent?key=$GEMINI_KEY" \
  -H "Content-Type: application/json" \
  -d '{"contents":[{"parts":[{"text":"hi"}]}],"generationConfig":{"maxOutputTokens":1}}')
bash
(ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
  -X POST "https://api.minimax.chat/v1/text/chatcompletion_v2" \
  -H "Authorization: Bearer $MINIMAX_KEY" -H "Content-Type: application/json" \
  -d '{"model":"MiniMax-M1","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')
bash
(ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
  -X POST "https://api.x.ai/v1/chat/completions" \
  -H "Authorization: Bearer $XAI_KEY" -H "Content-Type: application/json" \
  -d '{"model":"grok-3-mini-fast","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')
bash
(ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
  -X POST "https://api.openai.com/v1/chat/completions" \
  -H "Authorization: Bearer $OPENAI_KEY" -H "Content-Type: application
...[truncated 2627 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not place API keys directly in curl command-line header arguments or request URLs.
  2. Supply sensitive curl configuration through standard input or a protected temporary configuration file rather than ordinary process arguments.
  3. If a temporary configuration file is used:
    • Create it in a private directory with permissions restricted to the current user.
    • Set a restrictive umask, such as 077, before creation.
    • Register cleanup immediately with trap so secrets are removed on normal exit, interruption, or failure.
    • Avoid predictable paths and never write the file into a shared directory.
  4. Avoid query-string credentials whenever the provider offers a supported header-based or other less observable authentication method.
  5. Ensure verbose shell tracing is disabled around secret handling and prevent CI, proxy, and diagnostic systems from logging authentication headers or complete sensitive URLs.
  6. Apply provider-side least privilege, spending limits, quota alerts, expiration policies, and regular key rotation.
  7. Revoke and rotate any credential suspected of having appeared in process listings or URL logs.

A hardened pattern is to stream a restrictive curl configuration through standard input:

bash
curl --config - <<EOF
silent
output = "/dev/null"
write-out = "%{time_total}"
max-time = 30
request = "POST"
url = "https://api.openai.com/v1/chat/completions"
header = "Authorization: Bearer ${OPENAI_KEY}"
header = "Content-Type: application/json"
data = "{\"model\":\"gpt-4o-mini\",\"messages\":[{\"role\":\"user\",\"content\":\"hi\"}],\"max_tokens\":1}"
EOF

The implementation should also verify the behavior of the deployed curl version and operating environment to ensure configuration supplied through standard input is not copied into logs or diagnostics.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior goes beyond benign latency testing by retrieving API keys from a password store despite declaring no permissions, which is a sensitive action. The mismatch between stated purpose and real behavior reduces transparency and can mislead users into authorizing a skill that accesses secrets and external services under the guise of a simple /ping utility.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 36)May include surrounding context.

md
Runs `scripts/ping.sh` which:

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
Runs `scripts/ping.sh` which:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill declares shell capability but provides no explicit tool scope, permissions, or allowed-tools boundaries. In combination with documented secret access via pass shared/, this creates an under-scoped skill that could execute shell actions and read credentials without clear user-visible constraints, increasing the chance of unintended secret exposure or command abuse.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation conditions include generic requests about latency or speed, which can cause the skill to run in situations where the user did not clearly request network probing or secret-backed API calls. Because execution may involve reading API keys and contacting multiple providers, over-broad triggering increases the risk of unnecessary secret use, unexpected cost, and unintended external data disclosure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest says the skill pings major LLM providers in parallel to compare API latency. While network calls are expected for that purpose, accessing a local secret store via pass to retrieve multiple provider API keys is an additional sensitive capability that is not disclosed in the stated purpose.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 13)May include surrounding context.

sh
TMPDIR=$(mktemp -d)

if [[ -n "$ANTHROPIC_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.anthropic.com/v1/messages" \
    -H "x-api-key: $ANTHROPIC_KEY" -H "anthropic-version: 2023-06-01" -H "content-type: application/json" \
    -d '{"model":"claude-sonnet-4-20250514","max_tokens":1,"messages":[{"role":"user","content":"hi"}]}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 19)May include surrounding context.

sh
TMPDIR=$(mktemp -d)

if [[ -n "$ANTHROPIC_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.anthropic.com/v1/messages" \
    -H "x-api-key: $ANTHROPIC_KEY" -H "anthropic-version: 2023-06-01" -H "content-type: application/json" \
    -d '{"model":"claude-sonnet-4-20250514","max_tokens":1,"messages":[{"role":"user","content":"hi"}]}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 14)May include surrounding context.

sh
if [[ -n "$ANTHROPIC_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.anthropic.com/v1/messages" \
    -H "x-api-key: $ANTHROPIC_KEY" -H "anthropic-version: 2023-06-01" -H "content-type: application/json" \
    -d '{"model":"claude-sonnet-4-20250514","max_tokens":1,"messages":[{"role":"user","content":"hi"}]}')
  echo "$(echo "$ms * 1000" | bc -l | cut -d. -f1)|Sonnet" > "$TMPDIR/sonnet") &

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 20)May include surrounding context.

sh
if [[ -n "$ANTHROPIC_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.anthropic.com/v1/messages" \
    -H "x-api-key: $ANTHROPIC_KEY" -H "anthropic-version: 2023-06-01" -H "content-type: application/json" \
    -d '{"model":"claude-sonnet-4-20250514","max_tokens":1,"messages":[{"role":"user","content":"hi"}]}')
  echo "$(echo "$ms * 1000" | bc -l | cut -d. -f1)|Sonnet" > "$TMPDIR/sonnet") &

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 27)May include surrounding context.

sh
fi

if [[ -n "$GEMINI_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://generativelanguage.googleapis.com/v1beta/models/gemini-2.5-flash:generateContent?key=$GEMINI_KEY" \
    -H "Content-Type: application/json" \
    -d '{"contents":[{"parts":[{"text":"hi"}]}],"generationConfig":{"maxOutputTokens":1}}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 35)May include surrounding context.

sh
fi

if [[ -n "$MINIMAX_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.minimax.chat/v1/text/chatcompletion_v2" \
    -H "Authorization: Bearer $MINIMAX_KEY" -H "Content-Type: application/json" \
    -d '{"model":"MiniMax-M1","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 36)May include surrounding context.

sh
if [[ -n "$MINIMAX_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.minimax.chat/v1/text/chatcompletion_v2" \
    -H "Authorization: Bearer $MINIMAX_KEY" -H "Content-Type: application/json" \
    -d '{"model":"MiniMax-M1","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')
  echo "$(echo "$ms * 1000" | bc -l | cut -d. -f1)|MiniMax" > "$TMPDIR/minimax") &

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 43)May include surrounding context.

sh
fi

if [[ -n "$XAI_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.x.ai/v1/chat/completions" \
    -H "Authorization: Bearer $XAI_KEY" -H "Content-Type: application/json" \
    -d '{"model":"grok-3-mini-fast","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 44)May include surrounding context.

sh
if [[ -n "$XAI_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.x.ai/v1/chat/completions" \
    -H "Authorization: Bearer $XAI_KEY" -H "Content-Type: application/json" \
    -d '{"model":"grok-3-mini-fast","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')
  echo "$(echo "$ms * 1000" | bc -l | cut -d. -f1)|Grok" > "$TMPDIR/grok") &

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 51)May include surrounding context.

sh
fi

if [[ -n "$OPENAI_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.openai.com/v1/chat/completions" \
    -H "Authorization: Bearer $OPENAI_KEY" -H "Content-Type: application/json" \
    -d '{"model":"gpt-4o-mini","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ping.sh (reported line 52)May include surrounding context.

sh
if [[ -n "$OPENAI_KEY" ]]; then
  (ms=$(curl -s -o /dev/null -w "%{time_total}" --max-time 30 \
    -X POST "https://api.openai.com/v1/chat/completions" \
    -H "Authorization: Bearer $OPENAI_KEY" -H "Content-Type: application/json" \
    -d '{"model":"gpt-4o-mini","messages":[{"role":"user","content":"hi"}],"max_tokens":1}')
  echo "$(echo "$ms * 1000" | bc -l | cut -d. -f1)|GPT-4o" > "$TMPDIR/gpt4o") &

Static analysis

No suspicious patterns detected.