Back to skill

Security audit

Connect Tool Library

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent tool-library purpose, but it asks users to install an unpinned CLI and pass API tokens on the command line without enough safeguards.

Review this skill before installing. Use only a trusted, pinned cogenticlink version, avoid putting real tokens in shared terminals or logs, check how ~/.cogenticlab/link/config.json is protected, and prefer narrowly scoped tokens you can revoke.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:7
Finding

Unpinned Third-Party CLI Handles Sensitive Tokens and Tool Parameters

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:23
Finding

API Token Passed as a Command-Line Argument and Stored Without Documented Protection

Content
View full analysis
[description]` ``` ```markdown 1. **Check/Create Library** – If no library exists, instruct the user to set one: `cogenticlink libraries set '' '[description]'`. If the token is unknown, ask the user to create a tool library in Cogentic Hub. ``` ### Technical Analysis The documented setup procedure requires an API token to be supplied as a positional command-line argument. Secrets placed on a command line can be exposed through several channels: - Shell history files. - Process-listing and process-inspection interfaces while the command is running. - Terminal session recording. - Agent execution transcripts. - CI/CD logs and shell tracing. - Error reporting or telemetry that captures complete commands. Quoting the library name and description does not protect the token. The Skill also identifies `~/.cogenticlab/link/config.json` as required configuration but does not state whether tokens are encrypted, redacted, or protected by restrictive filesystem permissions. Network transmission of an authentication token may be necessary for the declared remote-tool functionality. However, exposure through command arguments is not the minimum privilege or minimum disclosure mechanism necessary to achieve that functionality. A protected prompt, standard input, or secret-manager reference can supply the token without placing it in the process command line. ### Attack Path 1. A user follows the documented command and inserts a valid API token as the `` positional argument. 2. The token becom ...[truncated 1546 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The skill declares installation via an unpinned Node package and references execution through npx, which can pull whatever version is current at install or run time. In a security-sensitive skill that brokers remote CLI/API/MCP tool execution, this creates supply-chain risk because a compromised or breaking upstream release could alter behavior or execute malicious code on the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to add and manage API tokens directly through CLI commands without any guidance on secret sensitivity, secure storage, redaction, or shell history exposure. Because this skill's core purpose is managing remote tool-library credentials, omission of token-handling safeguards materially increases the chance of accidental credential disclosure and subsequent unauthorized access to connected tools or services.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.