T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/scan_secrets.py:136- Finding
Symbolic Links Can Escape the Requested Scan Root
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent secrets scanner, but it needs review because it can expose detected secrets in reports and can read outside the chosen folder through symlinks.
Install only if you are comfortable with a local scanner reading the full project you point it at. Avoid running it on untrusted repositories until symlink handling is fixed, treat its output files and CI logs as sensitive, and verify or pin any optional prevention tools before installing them.
scripts/scan_secrets.py:136Symbolic Links Can Escape the Requested Scan Root
scripts/scan_secrets.py:198Detected Credentials Are Exposed in Plaintext Reports
references/prevention-guide.md:10Installation Guidance Uses Unpinned Executable Dependencies
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: secrets-audit
description: Scan projects and codebases for exposed secrets, API keys, tokens, passwords, and sensitive credentials. Detects hardcoded secrets in source code, config files, environment files, and git history. Use when asked to audit a project for secrets, check for exposed credentials, scan for API keys, find hardcoded passwords, review security of a codebase, check for leaked tokens, audit .env files, or verify no secrets are committed. Triggers on "secrets audit", "scan for secrets", "find exposed keys", "check for credentials", "security scan", "leaked secrets", "hardcoded passwords", "API key exposure", "credential check".
---
# Secrets Audit
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: secrets-audit
description: Scan projects and codebases for exposed secrets, API keys, tokens, passwords, and sensitive credentials. Detects hardcoded secrets in source code, config files, environment files, and git history. Use when asked to audit a project for secrets, check for exposed credentials, scan for API keys, find hardcoded passwords, review security of a codebase, check for leaked tokens, audit .env files, or verify no secrets are committed. Triggers on "secrets audit", "scan for secrets", "find exposed keys", "check for credentials", "security scan", "leaked secrets", "hardcoded passwords", "API key exposure", "credential check".
---
# Secrets Audit
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
---
name: secrets-audit
description: Scan projects and codebases for exposed secrets, API keys, tokens, passwords, and sensitive credentials. Detects hardcoded secrets in source code, config files, environment files, and git history. Use when asked to audit a project for secrets, check for exposed credentials, scan for API keys, find hardcoded passwords, review security of a codebase, check for leaked tokens, audit .env files, or verify no secrets are committed. Triggers on "secrets audit", "scan for secrets", "find exposed keys", "check for credentials", "security scan", "leaked secrets", "hardcoded passwords", "API key exposure", "credential check".
---
# Secrets Audit
Referenced artifact was not completely inspected
python3 scripts/scan_secrets.py /path/to/project
Referenced artifact was not completely inspected
python3 scripts/scan_secrets.py /path/to/project
Referenced artifact was not completely inspected
python3 scripts/scan_secrets.py /path/to/project
Referenced artifact was not completely inspected
python3 scripts/scan_secrets.py /path/to/project
Referenced artifact was not completely inspected
python3 scripts/scan_secrets.py /path/to/project
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Environment files
.env
.env.local
.env.*.local
.env.production
.env.staging
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.env
.env.local
.env.*.local
.env.production
.env.staging
# Key files
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
*.jks
credentials.json service-account*.json *-credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
*.jks
credentials.json service-account*.json *-credentials.json
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
('Stripe Publishable Key', r'pk_live_[0-9a-zA-Z]{24,}', 'MEDIUM', 'Stripe live publishable key'),
# GitHub
('GitHub Token', r'gh[pousr]_[A-Za-z0-9_]{36,}', 'HIGH', 'GitHub personal access token'),
('GitHub OAuth', r'gho_[A-Za-z0-9]{36}', 'HIGH', 'GitHub OAuth token'),
# Generic tokens/keys
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
deleted_files = [f for f in result.stdout.split('\n') if f.strip()]
# Check for sensitive deleted files
sensitive_patterns = ['.env', 'credentials', 'secret', '.pem', '.key', 'id_rsa']
for f in deleted_files:
for pattern in sensitive_patterns:
if pattern in f.lower():
The skill instructs use of file access and shell execution (python3 scripts/scan_secrets.py, directory walking, git history scanning) but does not declare any explicit tool scope or permission boundaries. That creates unnecessary ambiguity about what the agent may read or execute, increasing the risk of overbroad filesystem access or command execution against unintended paths.
The trigger list includes broad phrases like security scan, check for credentials, and review security of a codebase, which can cause this skill to activate for general security requests outside narrow secret scanning. Overbroad activation is dangerous because the skill has shell and filesystem-oriented behavior, so it may be invoked in contexts where users did not intend a repo-wide scan or git-history inspection.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"""Scan git history for previously committed secrets."""
findings = []
try:
result = subprocess.run(
['git', '-C', project_path, 'log', '--diff-filter=D', '--name-only', '--pretty=format:'],
capture_output=True, text=True, timeout=30
)
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
break
# Check commit messages for secret-related keywords
result = subprocess.run(
['git', '-C', project_path, 'log', '--oneline', '-50', '--all'],
capture_output=True, text=True, timeout=30
)
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
files_scanned = 0
files_skipped = 0
# Walk the directory tree
for root, dirs, files in os.walk(project_path):
# Skip directories in-place
dirs[:] = [d for d in dirs if d not in SKIP_DIRS]
This code performs a file write via the --output path, which is a safety-relevant operation under the rule. Although the script's overall purpose is scanning, the argparse help only describes output path selection and the nearby code provides no prior warning, confirmation, or comment disclosing that user-specified files will be created or overwritten.
No suspicious patterns detected.