Back to skill

Security audit

Tistory API CLI

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Tistory blog CLI guide, but it asks users to install unpinned external code that will use blog credentials and can modify or delete blog posts.

Install only if you trust the PyPI package publisher and are comfortable giving the CLI a Tistory token. Prefer an isolated tool environment, verify the package source/version first, use the narrowest token available, and be careful with delete and upload commands because they can affect live blog content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Unpinned and Unverifiable Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 35–42
Vulnerability Type: Supply-chain exposure through an unpinned external dependency
Risk Level: Medium

Vulnerable Code

markdown
## 설치

- pipx
  - pipx install tistory-api-cli
- uv
  - uv tool install tistory-api-cli
- pip (권장도 낮음)
  - pip install tistory-api-cli

Technical Analysis

Every documented installation method retrieves the current release of tistory-api-cli from an external package registry without pinning an exact version or verifying an artifact hash. The reviewed project contains only SKILL.md; it does not include the package source, dependency lockfile, integrity metadata, tests, or CI configuration claimed by the documentation. Its GitHub link is also marked as forthcoming.

Consequently, the implementation installed by users cannot be compared with the reviewed Skill. A compromised maintainer account, malicious replacement release, package-registry compromise, or unexpected future package change could introduce arbitrary installation-time or runtime behavior. This finding identifies an unsafe dependency trust model; it does not establish that the current external package is malicious.

Attack Path

  1. An attacker compromises the package publication channel or causes a malicious release of tistory-api-cli to become the version selected by the package manager.
  2. A user follows the documented pipx, uv, or pip command without specifying a reviewed version or expected hash.
  3. The package manager downloads and installs the attacker-controlled artifact.
  4. Malicious installation hooks or CLI runtime code execute with the permissions of the installing user.
  5. When the CLI is configured or invoked, the malicious code may access environment variables such as TISTORY_ACCESS_TOKEN and TISTORY_BLOG_NAME, read user-supplied files such as uploaded images or post content, alter blog data, or perform other ...[truncated 660 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin installation instructions to an exact reviewed package version rather than allowing package managers to select the latest release.
  2. Publish expected SHA-256 hashes and require hash verification during installation where supported.
  3. Include the auditable implementation in the Skill package or provide an authoritative source repository linked to immutable release tags and commits.
  4. Supply a dependency lockfile with exact transitive versions and integrity information.
  5. Sign release artifacts and document signature verification procedures.
  6. Add the referenced tests and CI configuration to the repository so users can verify the stated security and quality controls.
  7. Ensure package documentation identifies the verified publisher and canonical registry location to reduce dependency-confusion and package-spoofing risks.
  8. Recommend installation in an isolated environment and use a narrowly scoped Tistory token with only the permissions required for the intended operation.
  9. Align documentation and licensing metadata with the actual distributed artifacts before publication.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes a post deletion command, but it does not include any warning that the action is destructive or potentially irreversible. Under the markdown criteria for missing user warnings, behaviors that can affect user data should be accompanied by a clear warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The skill documentation advertises image upload via POST, which transmits local file data to a remote service, but it does not mention that files are sent over the network. For markdown files, network operations affecting user data should be disclosed so users understand the privacy and data-handling implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.