Back to skill

Security audit

MeshMonitor API

Security checks for vulnerabilities and agentic risk

Overview

This skill is not clearly malicious, but it needs review because it can use a bearer token to read mesh data, send live mesh messages, and exposes token-handling risks.

Install only if you are comfortable giving the agent a MeshMonitor bearer token with the same read/write powers you have. Prefer read-only or least-privilege tokens, use HTTPS-only base URLs, avoid pasting real tokens into shell history, and require explicit human approval before using `send-message` or `raw` with non-GET methods.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/meshmonitor_api.py:8
Finding

Bearer Token Can Be Transmitted Over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: scripts/meshmonitor_api.py:8-18; insecure usage is documented in SKILL.md:24 and SKILL.md:107-127
Vulnerability Type: Plaintext transmission of authentication credentials
Risk Level: High

Vulnerable Code

python
def req(url, token=None, method='GET', body=None):
    headers = {}
    data = None
    if token:
        headers['Authorization'] = f'Bearer {token}'
    if body is not None:
        headers['Content-Type'] = 'application/json'
        data = json.dumps(body).encode('utf-8')
    r = urllib.request.Request(url, headers=headers, method=method, data=data)
    with urllib.request.urlopen(r, timeout=30) as resp:
        return resp.read().decode('utf-8', errors='replace')

The documented usage explicitly demonstrates an unencrypted URL:

bash
python3 scripts/meshmonitor_api.py --base-url http://HOST:PORT --token 'mm_v1_...' info

Technical Analysis

The CLI accepts an arbitrary base URL and attaches the user-supplied bearer token to the HTTP Authorization header. It neither requires HTTPS nor warns or requests confirmation when the URL uses plaintext HTTP. The project documentation actively recommends an http:// example.

HTTP provides no confidentiality or server authentication. An attacker capable of observing or modifying traffic between the client and the MeshMonitor server can recover the complete bearer token. Because bearer credentials do not require additional proof of possession, possession of the captured value is sufficient to impersonate the user.

Network communication is necessary for the declared MeshMonitor integration, but permitting sensitive authentication over plaintext transport by default exceeds safe minimum-privilege handling of the credential.

Attack Path

  1. A user follows the documented example and supplies an http:// MeshMonitor base URL.
  2. The helper adds the MeshMonitor token to the ...[truncated 1012 chars]
Remediation
View remediation

Remediation Suggestions

  • Require https:// for authenticated requests by default.
  • Reject plaintext HTTP whenever a bearer token is present.
  • If local or legacy HTTP support is unavoidable, require an explicit option such as --allow-insecure-http and display a prominent credential-exposure warning.
  • Consider allowing plaintext HTTP only for loopback addresses, while still requiring explicit consent.
  • Replace the HTTP examples in SKILL.md with HTTPS examples.
  • Document certificate validation requirements and avoid recommending disabled TLS verification.
  • Test the URL scheme before constructing or sending the authenticated request.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/meshmonitor_api.py:8
Finding

Bearer Authorization Header May Be Disclosed Through Cross-Origin Redirects

Content
View full analysis

Vulnerability Details

File Location: scripts/meshmonitor_api.py:8-18
Vulnerability Type: Credential forwarding during automatic redirects
Risk Level: High

Vulnerable Code

python
def req(url, token=None, method='GET', body=None):
    headers = {}
    data = None
    if token:
        headers['Authorization'] = f'Bearer {token}'
    if body is not None:
        headers['Content-Type'] = 'application/json'
        data = json.dumps(body).encode('utf-8')
    r = urllib.request.Request(url, headers=headers, method=method, data=data)
    with urllib.request.urlopen(r, timeout=30) as resp:
        return resp.read().decode('utf-8', errors='replace')

Technical Analysis

The helper uses the default urllib.request.urlopen redirect behavior for requests containing the bearer token. It does not define a redirect policy, verify that a redirect remains on the original origin, or explicitly strip the Authorization header before following a redirect.

Consequently, an authenticated request may disclose its bearer credential if the configured MeshMonitor endpoint, an intercepted HTTP connection, or a compromised server responds with a redirect to an attacker-controlled destination. Scheme downgrades also are not explicitly prohibited.

Legitimate API redirects generally do not require forwarding a reusable credential to a different host. Cross-origin credential forwarding therefore is not necessary for the Skill's declared functionality.

Attack Path

  1. The user configures a compromised or attacker-controlled base URL, or an attacker intercepts a plaintext request to the configured endpoint.
  2. The endpoint returns an HTTP redirect whose destination is controlled by the attacker.
  3. The default redirect handler follows the redirect without an application-level same-origin authorization policy.
  4. The redirected request exposes the bearer token to the attacker-controlled destination.

...[truncated 732 chars]

Remediation
View remediation

Remediation Suggestions

  • Disable automatic redirects for requests that contain credentials, or handle redirects manually.
  • Permit authenticated redirects only when the destination has the same normalized HTTPS scheme, hostname, and effective port as the original request.
  • Strip the Authorization header before any permitted cross-origin redirect.
  • Reject HTTPS-to-HTTP downgrade redirects unconditionally.
  • Set a small redirect limit to prevent redirect loops.
  • Report rejected redirects clearly without including the token in errors or logs.
  • Add tests covering same-origin redirects, cross-origin redirects, and HTTPS downgrade attempts.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/meshmonitor_api.py:314
Finding

Bearer Token Accepted and Documented as a Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: scripts/meshmonitor_api.py:314; usage examples in SKILL.md:24 and SKILL.md:107-127
Vulnerability Type: Sensitive credential exposure through process arguments and shell history
Risk Level: Medium

Vulnerable Code

python
p = argparse.ArgumentParser(description='MeshMonitor API helper')
p.add_argument('--base-url', required=True)
p.add_argument('--token')
sub = p.add_subparsers(dest='cmd', required=True)

The documented invocation places the token directly in the command:

bash
python3 scripts/meshmonitor_api.py --base-url http://HOST:PORT --token 'mm_v1_...' info

Technical Analysis

Supplying a secret through --token places it in the process argument vector. Depending on the operating system and its process-inspection controls, command-line arguments may be visible to other local users or monitoring software while the process runs. The command may also be retained in shell history, terminal transcripts, job definitions, support bundles, audit records, CI logs, or automation output.

Quoting the token prevents ordinary shell expansion but does not prevent these disclosure channels. The documentation makes this insecure mechanism the standard workflow rather than offering a protected secret-input method.

Attack Path

  1. A user invokes the documented command with the real token supplied through --token.
  2. The token is recorded in shell history or exposed in the process argument list while the helper is running.
  3. Another local user, administrator, monitoring agent, log reader, or party with access to a diagnostic bundle retrieves the command.
  4. The party extracts the MeshMonitor bearer token.
  5. The token is replayed against the MeshMonitor API until it expires or is revoked.

Impact Assessment

The exposed credential grants the observer the API permissions assigned to the affected MeshMonitor user. Depending on token pr ...[truncated 402 chars]

Remediation
View remediation

Remediation Suggestions

  • Prefer a protected environment variable such as MESHMONITOR_TOKEN.
  • Support interactive secret entry through getpass.getpass() so the token is not echoed or placed in the argument vector.
  • Optionally support a token file whose permissions are verified before reading it.
  • If --token must remain for compatibility, clearly mark it as insecure and discourage its use.
  • Remove literal token placeholders from command patterns that encourage users to paste real credentials into shell history.
  • Ensure errors, debugging output, and exception messages never print the token.
  • Recommend immediate token revocation and regeneration if command histories or logs containing a real credential have been shared.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill metadata frames this as an inspection/reporting integration, but it includes a state-changing send-message operation that can transmit messages into the mesh. That creates a capability mismatch: a user or upstream agent may invoke the skill expecting read-only behavior, yet the code can perform writes with the provided bearer token, causing unauthorized communications or operational disruption.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Allowing arbitrary HTTP methods for the raw command unjustifiably expands this reporting skill into a general-purpose API client. That makes it easy to issue POST, PUT, PATCH, or DELETE requests against MeshMonitor endpoints, turning a nominally observational skill into a mutation-capable interface with little control or review.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill clearly instructs the agent to make authenticated network calls to a live MeshMonitor API, but it does not declare any explicit tool scope or permissions boundary. That omission weakens review and containment because consumers may assume the skill is informational while it actually enables live network interaction with a bearer token.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description presents an inspection/reporting capability, but the helper coverage includes send-message, which is an active write operation on the live mesh. This scope mismatch can cause an agent or operator to invoke the skill under the assumption it is read-only, leading to unintended transmissions or policy bypass.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documented send-message command materially expands the skill beyond inspection into operational control of a live system. In a security context, hidden or under-declared mutating capabilities are dangerous because they defeat least-privilege assumptions and can be misused to inject traffic onto the mesh.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Including a message-sending example in the recommended usage normalizes a live write action despite the skill being framed as an inspection/reporting tool. This increases the chance of accidental or unauthorized transmissions because users may follow examples without appreciating that they affect production mesh state.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation shows how to send a mesh message but does not warn that this is a write operation with real-world effects on the live mesh network. Missing safety qualifiers around mutating commands can lead to accidental operational impact, spam, confusion among mesh participants, or abuse by an agent acting too autonomously.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The notes explicitly document a write-capable endpoint (POST /messages) even though the skill is described as inspection-focused. This creates a capability mismatch that can lead an agent or integrator to perform live mesh transmissions the user did not expect, potentially causing unintended outbound actions on radio-backed infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The notes describe sending messages on a live mesh without a prominent warning that such actions may queue, relay, or otherwise affect real radio/network operations. In this skill context, that makes the issue more dangerous because Meshtastic meshes are operational systems where unintentional transmissions can create spam, confusion, or resource consumption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code performs HTTP requests to a user-supplied base URL and includes an Authorization bearer token when provided, but it has no confirmation prompt, logging, or explanatory comment/docstring warning that user/system data and credentials may be transmitted over the network. Multiple commands then retrieve or send potentially sensitive telemetry, message, topology, and node data through this helper.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The message-sending operation performs a POST that causes an external side effect without any built-in confirmation or warning. In agentic contexts, this increases the risk of accidental or socially engineered message transmission to channels or nodes, especially because the skill otherwise appears focused on inspection and reporting.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The generic raw command allows callers to access arbitrary API paths rather than only the documented inspection/reporting endpoints. In combination with bearer-token authentication, this bypasses any intended scope boundaries and can expose unreviewed or privileged endpoints, including state-changing operations if the token permits them.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The document discusses progressing from read-endpoint probing to building write flows, but the manifest does not disclose that the skill may support mutation-capable actions. While this is primarily a transparency and scope-control issue, it can still enable surprising behavior if an agent infers that write operations are acceptable in a context presented as observational.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.