Back to skill

Security audit

Tencent Cloud Deploy Web

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real Tencent Cloud website-ops assistant, but it asks for long-lived cloud access and includes unsafe fallback guidance to put cloud keys in chat and persist them.

Review before installing. Use only with a restricted Tencent Cloud subaccount for resources you intend the agent to manage. Do not paste cloud keys into chat; use the local setup wizard or a platform secret store. Avoid adding persistent SSH keys unless you deliberately want ongoing server login access, and audit/revoke the agent-ops credentials when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
references/human-cards.md:37
Finding

Long-Lived Tencent Cloud Credentials Are Instructed to Be Submitted Through Chat

Content
View full analysis

Vulnerability Details

File Location: references/human-cards.md, lines 37–48
Vulnerability Type: Plaintext credential exposure through retained conversation history
Risk Level: High

Vulnerable instructions:

text
## C0-Remote: The agent and user are not on the same computer (the agent runs in the cloud or on a server)

In this case, the web wizard cannot be used because the user's browser cannot access 127.0.0.1 on the agent's machine. Select options in this order:

1. Platform-provided secrets or environment-variable settings: ask the user to enter SecretId and SecretKey into the platform's secret settings as TENCENTCLOUD_SECRET_ID and TENCENTCLOUD_SECRET_KEY.
2. If the platform has no such settings: the only option is to ask the user to send the credentials in the conversation. After receiving them, the agent immediately calls tcapi.save_credential() to save them for long-term use.
   Explain that:
   - The credentials will remain in the conversation history, but their permissions are limited.
   - If concerned about leakage, the user can disable agent-ops and provide a new credential pair.
   Do not ask the user to rotate the credentials after use, because the agent would no longer be able to continue long-term work.

The quoted text is an English translation of the operative instructions at the specified location.

Technical Analysis

When the agent runs remotely and no platform secret facility exists, the Skill explicitly directs the user to submit a Tencent Cloud SecretId and SecretKey through the conversation. It acknowledges that the credentials remain in conversation history, directs the agent to persist them using tcapi.save_credential(), and discourages rotation after use.

This moves long-lived authentication material from a dedicated secret-handling boundary into the agent platform's conversation-storage boundary. Conversation records may be retained in model context, platform ...[truncated 2568 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the instruction that permits Tencent Cloud credentials to be submitted through conversation messages.
  2. Require one of the following protected enrollment mechanisms:
    • A platform-managed secret store.
    • Environment-variable injection through a protected configuration interface.
    • A user-run local enrollment utility that writes directly to the credential file.
    • A dedicated authenticated secret-submission channel that excludes values from conversation history, logs, telemetry, and model context.
  3. If no protected channel is available, terminate enrollment with a clear explanation instead of accepting credentials through chat.
  4. Prefer short-lived Tencent Cloud credentials with a session token where supported. Apply narrow expiration periods and resource-level restrictions.
  5. Do not discourage credential rotation. Provide a documented rotation procedure that replaces stored credentials without interrupting service longer than necessary.
  6. Revoke and rotate any credential pairs previously submitted through conversations.
  7. Add explicit checks or agent instructions that reject messages containing apparent Tencent Cloud secrets and direct the user to a protected setup method.
  8. Retain the existing least-privilege policy and local file protections, but further scope access to only the specific resources the user has selected where Tencent Cloud policy semantics permit it.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
Findings (24)

Tainted flow: 'req' from os.environ.get (line 146, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.

Content

Scanner excerpt · scripts/tcapi.py (reported line 148)May include surrounding context.

python
url, headers, body = build_request(service, action, params or {}, sid, skey, region, token, version)
    req = urllib.request.Request(url, data=body, headers=headers, method="POST")
    try:
        with urllib.request.urlopen(req, timeout=timeout) as r:
            data = json.loads(r.read().decode("utf-8"))
    except urllib.error.HTTPError as e:
        data = json.loads(e.read().decode("utf-8") or "{}")

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill is presented as a website deployment assistant, but it also instructs the agent to execute arbitrary commands as root on remote Tencent Cloud instances via TAT and to upload local script contents for execution. Even if operationally useful, this is a materially more powerful capability than the description suggests, and it can be abused for full server compromise, destructive changes, or persistence if the agent is misled or the workflow is subverted.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

This is a true vulnerability because the file first tells users not to send secrets in chat, then later instructs exactly that under a fallback path. That contradiction can socially condition users to ignore earlier safety guidance, making credential disclosure more likely and undermining trust boundaries around secret handling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This is a true vulnerability because the skill explicitly instructs the agent to ask the user to paste Tencent Cloud SecretId and SecretKey into the chat and then persist them for long-term use. Chat channels and conversation history are broader exposure surfaces than a local credential-entry flow, and this directly contradicts the safer model described elsewhere, increasing the chance of credential leakage, retention beyond user expectations, and unauthorized reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This is a true vulnerability because it permits users to provide cloud API credentials in chat and save them for ongoing use, while the warning text in this file is insufficient relative to the sensitivity and retention risk of long-lived credentials. Even if the permissions are intended to be limited, compromise of those keys could still expose DNS, CDN, SSL, server-management, or other account capabilities and create a durable secret-sprawl problem.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

This is a true vulnerability because the instructions normalize sending highly sensitive cloud access keys into the dialogue and retaining them for long-term operations. In the context of a cloud-operations skill, those credentials enable control-plane actions over production infrastructure, so leakage could lead to domain hijacking, certificate misuse, CDN changes, server access, or service disruption within the granted scope.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Referencing the user's SSH authorization path in the context of adding the agent's own key is not merely documentation; it describes a persistence mechanism on a customer host. In this skill's ops context, the danger is elevated because the agent is already operating as root on internet-facing servers, so planting SSH access would grant durable privileged entry that survives normal session boundaries.

Content

Scanner excerpt · references/routes.md (reported line 101)May include surrounding context.

md
# 2. 直接在服务器上执行命令(root 身份,不需要 SSH)
RUN --instance <id> "uname -a; df -h /; free -m"
RUN --instance <id> --file deploy.sh --timeout 900      # 较长的部署脚本,先在本地写好
#    想用 SSH 时:用 RUN 把你自己的公钥追加到 /home/ubuntu/.ssh/authorized_keys
#    不要调用 AssociateInstancesKeyPairs:它会强制关机,并让原来的密钥失效

# 3. 防火墙:官方文档说 Linux 默认放行 22/80/443,但我们遇到过 443 不通的情况,以实际查询结果为准

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

Referencing the user's SSH authorization path in the context of adding the agent's own key is not merely documentation; it describes a persistence mechanism on a customer host. In this skill's ops context, the danger is elevated because the agent is already operating as root on internet-facing servers, so planting SSH access would grant durable privileged entry that survives normal session boundaries.

Content

Scanner excerpt · references/routes.md (reported line 101)May include surrounding context.

md
# 2. 直接在服务器上执行命令(root 身份,不需要 SSH)
RUN --instance <id> "uname -a; df -h /; free -m"
RUN --instance <id> --file deploy.sh --timeout 900      # 较长的部署脚本,先在本地写好
#    想用 SSH 时:用 RUN 把你自己的公钥追加到 /home/ubuntu/.ssh/authorized_keys
#    不要调用 AssociateInstancesKeyPairs:它会强制关机,并让原来的密钥失效

# 3. 防火墙:官方文档说 Linux 默认放行 22/80/443,但我们遇到过 443 不通的情况,以实际查询结果为准

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script exposes a general-purpose remote command execution primitive over Tencent Cloud TAT, including arbitrary shell content loaded from a file or command line. In the context of an agent skill for non-technical users, that capability is broader than the stated deployment/DNS/SSL/CDN scope and could be used to run destructive or persistence-establishing commands on managed servers, especially since the default user is root.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares broad operational capabilities including shell, file read/write, network, and environment access but does not define any explicit tool scope or allowed-tools boundary. In a skill that manages cloud infrastructure and credentials, this omission increases the chance of the agent using more capabilities than intended, including touching local files or executing commands beyond the minimum needed for deployment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instruction says the agent must speak to the user in a specific style and language context, including avoiding technical terms and using Chinese phrasing such as "做好了什么、现在能访问哪个网址、还需要你做什么". There is no indication that the user can choose another language, which creates a language/locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction says the user-facing delivery note '不要出现任何技术术语或报错原文', and the entire prescribed output template is in Chinese, which effectively constrains the agent to respond in Chinese. There is no indication that the user may choose another language or locale, so this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all instructional and reference content exclusively in Chinese, including the title and all table entries. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is explicitly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The natural-language documentation and user-facing strings are entirely in Chinese, including usage guidance and notifications, with no indication that another language can be selected. This can violate language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring says the tool executes shell commands on the server '以 root 身份' (as root), suggesting a fixed execution context. However, the code exposes a --user option and passes that value directly as the TAT Username, so execution is not limited to root and the stated behavior is inaccurate.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This file includes user-facing natural-language instructions and usage text only in Chinese. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale constraint is explicitly documented and justified, which it is not here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring and all user-facing messages are written only in Chinese, and the setup flow appears intended for end users. This imposes a language choice without offering any opt-in or alternative locale, which matches the policy category for language/locale violations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains natural-language instructions and output strings entirely in Chinese, including messages intended for downstream agent/user handling. Because the file does not offer any user opt-in or locale selection, it imposes a specific language choice, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The module docstring, including usage instructions and operational descriptions, is entirely in Chinese. For a general-purpose CLI utility, this imposes a specific language on users without any documented opt-in or alternative locale, which matches the language/locale policy violation criteria.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script is a broad Tencent Cloud API client, not a narrowly scoped website deployment helper. Because it accepts arbitrary service and action names and includes support for services beyond DNS/CDN/SSL/web hosting, the surrounding skill can potentially perform unrelated cloud administration operations if invoked by an agent, increasing the blast radius of prompt misuse or agent error.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The embedded capability list includes identity/account and billing-related APIs such as sts, cam, domain, and billing, which exceed what a non-technical website deployment assistant should need. In an agent context, extra privileged APIs are dangerous because prompt injection, misrouting, or operator confusion could trigger sensitive account discovery or financial/account-impacting operations far outside the user's intended task.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The document declares lang="zh-CN", and all visible instructional content is presented only in Simplified Chinese. Under the policy rule, forcing a specific language without user opt-in or documented justification is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The code checks for Tencent Cloud credentials via the TENCENTCLOUD_SECRET_ID environment variable and profile path, which is sensitive credential-related access. Although the module docstring explains the tool's overall purpose, there is no explicit user-facing notice in the execution flow that the script will inspect local cloud credential sources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script performs live cloud identity and permission probes against Tencent Cloud APIs without any runtime confirmation or explicit notice immediately before the network calls. In this skill context, those calls are read-only and align with the tool's stated purpose, but they still disclose account metadata and access patterns to the provider and may surprise users who did not expect external checks.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.