Back to skill

Security audit

Age

Security checks for vulnerabilities and agentic risk

Overview

This is a reference skill for age encryption; the sensitive-looking commands are printed examples, not automatically executed behavior.

Install only if you want an age encryption command reference. Treat the examples as powerful shell snippets: review paths, recipients, private keys, .env files, and cloud bucket destinations before running or asking an agent to run them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 36)May include surrounding context.

sh
├────────────────┼────────────────┼────────────────┤
  │ Key format     │ X25519         │ RSA/DSA/ECC    │
  │ Config needed  │ None           │ ~/.gnupg/      │
  │ Key management │ Just files     │ Keyring/server │
  │ Trust model    │ None           │ Web of Trust   │
  │ Signing        │ No             │ Yes            │
  │ Key size       │ 62 chars       │ Variable       │

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 103)May include surrounding context.

sh
- ssh-rsa (2048+ bits)

  # Encrypt to SSH key
  age -R ~/.ssh/id_ed25519.pub -o secret.age plaintext.txt

  # Decrypt with SSH private key
  age -d -i ~/.ssh/id_ed25519 -o plaintext.txt secret.age

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 106)May include surrounding context.

sh
- ssh-rsa (2048+ bits)

  # Encrypt to SSH key
  age -R ~/.ssh/id_ed25519.pub -o secret.age plaintext.txt

  # Decrypt with SSH private key
  age -d -i ~/.ssh/id_ed25519 -o plaintext.txt secret.age

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 205)May include surrounding context.

sh
- ssh-rsa (2048+ bits)

  # Encrypt to SSH key
  age -R ~/.ssh/id_ed25519.pub -o secret.age plaintext.txt

  # Decrypt with SSH private key
  age -d -i ~/.ssh/id_ed25519 -o plaintext.txt secret.age

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 208)May include surrounding context.

sh
- ssh-rsa (2048+ bits)

  # Encrypt to SSH key
  age -R ~/.ssh/id_ed25519.pub -o secret.age plaintext.txt

  # Decrypt with SSH private key
  age -d -i ~/.ssh/id_ed25519 -o plaintext.txt secret.age

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 168)May include surrounding context.

sh
cat largefile.bin | gzip | age -r age1recipient... -o largefile.gz.age

  # Encrypt then base64 (for text transport)
  age -r age1recipient... -a < secret.txt  # -a flag = ASCII armor
EOF
}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 292)May include surrounding context.

sh
cat largefile.bin | gzip | age -r age1recipient... -o largefile.gz.age

  # Encrypt then base64 (for text transport)
  age -r age1recipient... -a < secret.txt  # -a flag = ASCII armor
EOF
}

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 256)May include surrounding context.

sh
2. ENCRYPTED DOTFILES IN GIT
   # Encrypt sensitive files before committing
   age -R ~/.config/age/recipients.txt -o .env.age .env
   git add .env.age
   echo ".env" >> .gitignore

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 261)May include surrounding context.

sh
2. ENCRYPTED DOTFILES IN GIT
   # Encrypt sensitive files before committing
   age -R ~/.config/age/recipients.txt -o .env.age .env
   git add .env.age
   echo ".env" >> .gitignore

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 258)May include surrounding context.

sh
# Encrypt sensitive files before committing
   age -R ~/.config/age/recipients.txt -o .env.age .env
   git add .env.age
   echo ".env" >> .gitignore

   # Decrypt after cloning
   age -d -i ~/.config/age/identity.txt -o .env .env.age

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/script.sh (reported line 305)May include surrounding context.

sh
age: "age1recipient1...,age1recipient2..."

   # Encrypt
   sops -e secrets.yaml > secrets.enc.yaml

   # Edit in place
   sops secrets.enc.yaml

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/script.sh (reported line 83)May include surrounding context.

sh
KEY STORAGE BEST PRACTICES:
  # Set restrictive permissions
  chmod 600 key.txt

  # Store in secure location
  mkdir -p ~/.config/age

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/script.sh (reported line 86)May include surrounding context.

sh
chmod 600 key.txt

  # Store in secure location
  mkdir -p ~/.config/age
  mv key.txt ~/.config/age/identity.txt
  chmod 700 ~/.config/age

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/script.sh (reported line 88)May include surrounding context.

sh
# Store in secure location
  mkdir -p ~/.config/age
  mv key.txt ~/.config/age/identity.txt
  chmod 700 ~/.config/age

  # Back up your secret key!
  # If you lose it, encrypted files are gone forever.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 162)May include surrounding context.

sh
PIPE OPERATIONS:
  # Encrypt and stream
  mysqldump mydb | age -r age1recipient... | aws s3 cp - s3://bucket/backup.sql.age

  # Compress then encrypt (recommended order)
  cat largefile.bin | gzip | age -r age1recipient... -o largefile.gz.age

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · scripts/script.sh (reported line 216)May include surrounding context.

sh
PIPE OPERATIONS:
  # Encrypt and stream
  mysqldump mydb | age -r age1recipient... | aws s3 cp - s3://bucket/backup.sql.age

  # Compress then encrypt (recommended order)
  cat largefile.bin | gzip | age -r age1recipient... -o largefile.gz.age

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/script.sh (reported line 264)May include surrounding context.

sh
age -d -i ~/.config/age/identity.txt -o .env .env.age

3. SHARE SECRETS WITH TEAM
   # Create team recipients file
   cat > team-keys.txt << KEYS
   # Alice (DevOps)
   age1alice...

Static analysis

No suspicious patterns detected.