Back to skill

Security audit

Mikrotik Routeros

Security checks for vulnerabilities and agentic risk

Overview

This skill has a legitimate router administration purpose, but it includes unsafe credential handling, insecure connection examples, broad device privileges, and automatic third-party script updates that should be reviewed before use.

Install only after reviewing and tightening the examples for your environment. Prefer SSH keys or verified TLS, avoid plaintext RouterOS API port 8728, do not store passwords in TOOLS.md or command lines, pin or internally host third-party scripts, disable unattended updates on production devices, and reduce RouterOS script policies to the minimum needed.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (8)

T03 · Remote Payload Retrieval and Execution

Error
Location
references/eworm-scripts.md:29
Finding

Mutable Third-Party RouterOS Code Is Downloaded, Executed, and Automatically Updated

Content
View full analysis
"data"); } /system/script { run global-config; run global-functions; } # Loads configuration and functions at boot /system/scheduler/add name="global-scripts" start-time=startup \ on-event="/system/script { run global-config; run global-functions; }" # Optional daily automatic script update /system/scheduler/add name="ScriptInstallUpdate" start-time=startup interval=1d \ on-event=":global ScriptInstallUpdate; \$ScriptInstallUpdate;" ``` ### Technical Analysis The instructions retrieve mutable RouterOS source from an external domain, save it as privileged device scripts, and immediately execute it. The downloaded payload is not pinned to an immutable release or commit and is not authenticated with a code signature or expected cryptographic digest. TLS validates only the server connection at retrieval time. It does not protect against compromise of the upstream project, hosting environment, domain, or authorized publishing account. The daily update scheduler allows the effective payload to change after the Skill and initial script version have been reviewed. The startup scheduler also causes downloaded code to execute after router reboots. These behaviors exceed the minimum permissions needed for ordinary router monitoring or notification tasks. ### Attack Path 1. An attacker compromises the upstream publishing account, hosting service, DNS path, or another component capable of changing the `.rsc` responses. 2. The attacker replaces one of the mutable ...[truncated 825 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/mikrotik_api.py:10
Finding

Packaged RouterOS API Client Transmits Credentials over an Unencrypted Connection

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/routeros-api.md:27
Finding

API Examples Disable TLS Verification and Place Credentials in Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
references/failover-notifications.md:50
Finding

Notification Scripts Are Assigned Unnecessary Administrative RouterOS Policies

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/vsol-olt.md:8
Finding

OLT SSH Guidance Disables Host Verification While Enabling Legacy Cryptography

Content
View full analysis
VSOL OLTs often require legacy SSH algorithms — always include KexAlgorithms and HostKeyAlgorithms flags. ``` ### Technical Analysis `StrictHostKeyChecking=no` permits an SSH client to accept an untrusted or changed server key, removing reliable OLT identity verification. The command simultaneously enables SHA-1-era key exchange and host-key algorithms. Legacy firmware compatibility may justify narrowly enabling an older algorithm, but it does not require disabling host-key verification. Using `sshpass` causes the password to be supplied automatically to whichever endpoint the unauthenticated SSH connection reaches. ### Attack Path 1. An operator connects to the OLT over a network path controlled or observed by an attacker. 2. The attacker impersonates the OLT and presents an arbitrary SSH host key. 3. `StrictHostKeyChecking=no` accepts the forged endpoint. 4. `sshpass` supplies the OLT password to the attacker's SSH service. 5. The attacker uses the captured credentials against the legitimate OLT. 6. The attacker can then alter GPON provisioning, VLAN mappings, or device configuration according to the account's privileges. ### Impact Assessment Compromise of a privileged OLT account can affect many subscribers simultaneously. Potential impact includes ONU reprovisioning, service interruption, unauthorized VLAN changes, configuration theft, traffic redirection, and loss of management access. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/failover-notifications.md:74
Finding

Notification and Backup Examples Persist Secrets in URLs and Send API Keys over Plaintext HTTP

Content
View full analysis
ROTEADOR: " . $routerName . " %0A%0A" . \ "LINK: " . $comentario . " %0A%0A" . \ "STATUS: " . $LinkStatus . " %0A" . \ "____________________________") keep-result=no ``` ```routeros /tool fetch mode=http http-method=post \ http-header-field="Content-Type: application/json, apikey: SUA_API_KEY_AQUI" \ http-data=("{\"number\": \"55XXXXXXXXXXX\", \"text\": \"" . $TextoEnvio . "\"}") \ url="http://:8080/message/sendText/failover" ``` ```routeros $ScriptInstallUpdate backup-upload # Configure destination in global-config-overlay: # :global BackupUploadUrl "sftp://user:pass@servidor/path/" # :global BackupSendBinary true # :global BackupSendExport true /system/scheduler/add name=backup-upload interval=1d start-time=startup \ on-event="/system/script/run backup-upload;" ``` ### Technical Analysis The Telegram bot token is incorporated into the request URL. URLs may be retained by diagnostic logs, proxies, monitoring systems, shell transcripts, or device troubleshooting output. The Evolution API key is embedded in RouterOS script source and transmitted over unencrypted HTTP. The backup example places a username and password directly in a URL stored in a global configuration script. RouterOS users or scripts with access to sensitive script configuration may recover these credentials. Sending router identity and link state to Telegram, ...[truncated 1105 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/mikrotik_api.py:119
Finding

API Client Uses a Plaintext Password Parsed from TOOLS.md Despite Warning Against It

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:120
Finding

Unpinned Package Is Installed Directly into the System Python Environment

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (39)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The documented curl -u "$MIKROTIK_USER:$MIKROTIK_PASS" pattern encourages placing credentials directly on the command line, where they may be exposed through process listings, shell history, debugging logs, or agent telemetry. In the context of router administration, exposure of these credentials can lead to full compromise of network infrastructure.

Content

Scanner excerpt · SKILL.md (reported line 138)May include surrounding context.

conn.disconnect()

text

### REST API (curl — ROS 7.1+)
```bash
# Use env vars — never hardcode credentials
curl -u "$MIKROTIK_USER:$MIKROTIK_PASS" \

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/routeros-api.md (reported line 114)May include surrounding context.

/ip service enable www-ssl

text

#### curl Examples
```bash
BASE="https://172.16.100.1/rest"
AUTH="admin:senha"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares access to environment-based credentials and operational connectivity details but does not define an explicit tool/permission scope. In an agent ecosystem, that increases the chance the skill is invoked with broader-than-necessary access to secrets or execution capabilities, especially because it is designed to manage infrastructure devices.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger description is broad enough to match many generic networking or ISP-related conversations, which can cause the skill to activate outside its intended context. Because the skill contains instructions for live network administration, over-triggering could expose credentials, encourage unsafe command generation, or route unrelated tasks into a high-privilege workflow.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The phrase any ISP infrastructure task is effectively unbounded and gives the skill authority to claim a very large class of operational requests. In a system where skills may access device credentials or propose commands, this ambiguity increases the risk of accidental activation and unsafe actions in unrelated contexts.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/eworm-scripts.md (reported line 25)May include surrounding context.

/certificate/import file-name="root-ye.pem" passphrase="" /certificate/set name="Root-YE" [ find where common-name="Root YE" ]

Verifica fingerprint:

/certificate/print proplist=name,fingerprint
where fingerprint="e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666"

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/routeros-api.md (reported line 138)May include surrounding context.

/certificate/import file-name="root-ye.pem" passphrase="" /certificate/set name="Root-YE" [ find where common-name="Root YE" ]

Verifica fingerprint:

/certificate/print proplist=name,fingerprint
where fingerprint="e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666"

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/routeros-api.md (reported line 153)May include surrounding context.

/certificate/import file-name="root-ye.pem" passphrase="" /certificate/set name="Root-YE" [ find where common-name="Root YE" ]

Verifica fingerprint:

/certificate/print proplist=name,fingerprint
where fingerprint="e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666"

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/routeros-api.md (reported line 156)May include surrounding context.

/certificate/import file-name="root-ye.pem" passphrase="" /certificate/set name="Root-YE" [ find where common-name="Root YE" ]

Verifica fingerprint:

/certificate/print proplist=name,fingerprint
where fingerprint="e14ffcad5b0025731006caa43a121a22d8e9700f4fb9cf852f02a708aa5d5666"

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The document instructs operators to fetch executable RouterOS scripts from a remote site and enable unattended daily updates that overwrite on-device automation. Even with HTTPS and certificate checking, this creates a supply-chain risk: compromise of the upstream repository, signing/trust chain, or fetched content could push malicious logic directly onto production routers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The backup-upload example encourages exporting backups to an external server using a URL that embeds credentials, but does not warn that RouterOS backups and exports may contain highly sensitive configuration, secrets, and network topology data. If the destination, transport, logs, or stored URL are exposed, an attacker could obtain credentials and full device configuration for further compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Telegram setup directs users to place a bot token and chat ID into router configuration and send device-generated notifications to a third-party platform without highlighting the privacy and credential-handling implications. Exposure of the token could let an attacker read or spoof notifications, while message contents may leak operational details about the ISP network.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document instructs operators to send router identity, link names, and status events to third-party services including Telegram, WhatsApp/Evolution API, and Google Sheets, but it does not warn about privacy, retention, or metadata exposure. In an ISP/network-operations context, these notifications can disclose infrastructure identifiers and operational state to external platforms, increasing reconnaissance and compliance risk if misconfigured or unauthorized.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

The script sends router name, link identifier, and failover status to the Telegram Bot API over the internet. In this skill's context, that outbound transmission is intentional, but it still creates a genuine data-sharing risk because infrastructure metadata leaves the router and may expose operational details to third parties or unintended recipients if the token/chat ID is mismanaged.

Content

Scanner excerpt · references/failover-notifications.md (reported line 77)May include surrounding context.

md
:global botToken "SEU_TOKEN_AQUI"
:global groupID "SEU_CHAT_ID_AQUI"
:delay 2
/tool fetch url=("https://api.telegram.org/bot" . $botToken . "/sendMessage?chat_id=" . $groupID . \
    "&parse_mode=HTML&text=" . \
    $emoji . $emoji . $emoji . $emoji . $emoji . $emoji . $emoji . "%0A%0A" . \
    "<b>ROTEADOR:</b> " . $routerName . " %0A%0A" . \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/failover-notifications.md (reported line 149)May include surrounding context.

Após subir, criar instância via API:

bash
curl -X POST http://<ip>:8080/instance/create \
  -H "Content-Type: application/json" \
  -H "apikey: <sua-api-key>" \
  -d '{"instanceName":"failover","qrcode":true}'

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes expert management of MikroTik RouterOS devices and VSOL GPON OLTs, plus related ISP infrastructure tasks. This section introduces GenieACS/TR-069 CPE provisioning, which is a distinct management domain not clearly justified by the stated purpose and broadens the skill into ACS/CPE administration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
91% confidence
Finding

The script performs an outbound request to the Telegram API from a network device, creating an external data transmission path from sensitive ISP infrastructure. Even though the purpose is alerting, this can disclose device identity and fault conditions to a third party and may be abused or misconfigured to exfiltrate additional information if not tightly controlled.

Content

Scanner excerpt · references/isp-stack.md (reported line 202)May include surrounding context.

md
/routing ospf instance set 0 disabled=no
    /log error "$HOSTNAME NO OSPF"
    :delay 4000ms
    /tool fetch url=("https://api.telegram.org/bot" . $BOT_ID . \
      "/sendMessage?chat_id=" . $CHAT_ID . \
      "&text=" . $HOSTNAME . " NO OSPF, OSPF RESTARTING") keep-result=no
  }

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
98% confidence
Finding

Setting ssl_verify=False is an unsafe default because it suppresses certificate validation for RouterOS API-over-SSL connections. In this context, the file is teaching privileged network administration, so insecure copy-paste examples can directly weaken real-world management workflows.

Content

Scanner excerpt · references/routeros-api.md (reported line 33)May include surrounding context.

conn = routeros_api.RouterOsApiPool( host=host, username=user, password=pw, plaintext_login=True, use_ssl=True, ssl_verify=False, ssl_verify_hostname=False, port=8729 )

text

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
98% confidence
Finding

Setting ssl_verify=False is an unsafe default because it suppresses certificate validation for RouterOS API-over-SSL connections. In this context, the file is teaching privileged network administration, so insecure copy-paste examples can directly weaken real-world management workflows.

Content

Scanner excerpt · references/routeros-api.md (reported line 33)May include surrounding context.

conn = routeros_api.RouterOsApiPool( host=host, username=user, password=pw, plaintext_login=True, use_ssl=True, ssl_verify=False, ssl_verify_hostname=False, port=8729 )

text

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The reference documents destructive and state-changing operations such as add, set, remove, move, reboot, and backup save without an explicit warning about production impact. In a network automation context, readers may copy these commands directly into live environments, causing outages, lockouts, or policy changes without understanding the blast radius.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/routeros-api.md (reported line 114)May include surrounding context.

/ip service enable www-ssl

text

#### curl Examples
```bash
BASE="https://172.16.100.1/rest"
AUTH="admin:senha"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes inline credentials such as admin:senha and demonstrates authenticated requests without warning users not to hardcode or expose secrets. This can normalize insecure handling of management credentials for ISP infrastructure, increasing the chance of credential leakage through shell history, screenshots, repos, logs, or copied automation snippets.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The REST examples explicitly disable TLS certificate verification with curl -k and requests verify=False, which permits man-in-the-middle interception of credentials and API traffic. In an infrastructure-management skill that targets routers and OLTs, this is especially risky because the same connection can carry privileged configuration changes, device inventory, and operational data.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
97% confidence
Finding

The Python requests example uses verify=False for an authenticated HTTPS call to a router management API. This exposes credentials and responses to interception and spoofing, which is particularly dangerous because the API can reveal topology and apply configuration changes.

Content

Scanner excerpt · references/routeros-api.md (reported line 150)May include surrounding context.

md
auth = HTTPBasicAuth('admin', 'senha')

# GET
r = requests.get(f'{base}/interface', auth=auth, verify=False)
print(r.json())

# POST with proplist

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/routeros-api.md (reported line 154)May include surrounding context.

print(r.json())

POST with proplist

r = requests.post(f'{base}/ip/address/print', auth=auth, verify=False, json={'_proplist': ['address', 'interface']})

text

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/failover-notifications.md:180