Back to skill

Security audit

Safe Bitwarden Cli

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says for Bitwarden, but it handles real passwords and 2FA codes through the system clipboard while overstating how protected that path is.

Install only if you are comfortable letting the agent search Bitwarden item metadata and copy passwords or 2FA codes into your system clipboard. Avoid using it on shared, monitored, remote-desktop, or clipboard-history-enabled systems unless you clear or harden the clipboard yourself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

The core declared purpose—bridging to Bitwarden and copying passwords/TOTP codes to the clipboard—is broadly consistent with the code. However, the code also implements additional capabilities not reflected in the description: a search function over vault items and a setup/diagnostic function that enumerates local environment details such as platform and clipboard tool path. These are materially undeclared behaviors beyond simple password/TOTP copying. The 'kernel-level piping' claim is mostly marketing language; the code uses normal shell pipes to native clipboard utilities, not any special kernel-level mechanism.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to copy passwords and TOTP-related secrets into the native system clipboard while framing the design as highly secure, but it does not warn that clipboards are commonly accessible to other local processes, clipboard history features, remote desktop tools, and sync services. In a credential-management skill, this omission can mislead users into treating clipboard transfer as risk-free, increasing the chance of credential exposure on shared or monitored systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill is presented as a secure bridge for copying secrets, but it also exposes vault enumeration through bw list items --search, which reveals item names, IDs, and usernames. In an agent-skill context, that broadens the accessible secret metadata surface and can enable discovery of sensitive accounts even when the user expected only targeted copy operations.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The code copies Bitwarden passwords into the native system clipboard while describing the operation as 'secure', 'zero-trust', and 'kernel-pipe'. Native clipboards are commonly readable by other local applications, clipboard managers, remote desktop tooling, and user actions, so this creates a real secret exposure risk and may mislead users into overtrusting the protection level.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The TOTP flow has the same issue as the password path: it places active one-time codes into the native clipboard despite 'secure' and 'hardened' wording. In a skill context, this is especially risky because short-lived MFA codes may still be captured by clipboard monitors or logs during their validity window, undermining account protections.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file presents a Simplified Chinese link as the only explicit language variant, while the policy requires avoiding forced language or locale constraints without user opt-in or justification. There is no statement that the skill supports user language choice or that the locale limitation is intentional for a specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.