Back to skill

Security audit

Cloak — Protect .env Secrets from AI Agents

Security checks for vulnerabilities and agentic risk

Overview

The skill’s secret-protection purpose is coherent, but its install instructions tell users or agents to execute unverified remote installer scripts directly in a shell.

Review the Cloak project and installer source before installing. Prefer a signed, versioned package or a download-verify-inspect-run flow instead of piping remote scripts into a shell. If installed, keep Cloak actions user-directed, especially commands that reveal, edit, set, or run processes with real secrets.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:86
Finding

Unverified Remote Installer Download and Immediate Shell Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 86–91
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
# macOS / Linux
curl -fsSL https://getcloak.dev/install.sh | sh

# Windows (PowerShell)
irm https://getcloak.dev/install.ps1 | iex

Technical Analysis

The installation instructions retrieve mutable scripts from an external website and execute them immediately using a shell or PowerShell interpreter. Neither command pins a release version, verifies a cryptographic signature or checksum, nor gives the user an opportunity to inspect the downloaded code before execution.

The project does not contain a local installer, integrity metadata, or other evidence from which the behavior of these remote scripts can be audited. The trustworthiness and future contents of the referenced URLs therefore cannot be established from the reviewed artifact.

Installing the Cloak utility is relevant to the Skill's declared secret-protection functionality, but direct download-to-interpreter pipelines exceed the minimum-risk mechanism necessary to perform that installation. A verified, versioned package or separately downloaded and authenticated artifact would provide the same functionality with less supply-chain exposure.

Attack Path

  1. An agent or user follows the installation command in SKILL.md.
  2. The command connects to getcloak.dev and retrieves the current response from the installer URL.
  3. An attacker who compromises the website, DNS infrastructure, TLS endpoint, publishing process, or installer storage replaces the expected script with a malicious payload.
  4. The shell or PowerShell interpreter executes the response immediately without integrity verification or prior inspection.
  5. The payload runs with the privileges of the invoking user and may access user-readable files, install persistence, modify development tools, or steal credentials.
  6. If installation is per ...[truncated 845 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove both direct pipe-to-interpreter installation commands.
  2. Direct users to a version-pinned package from an authenticated official package repository where possible.
  3. If standalone installers are required, use a staged process:
    • Download a specific release artifact to a local file.
    • Obtain its expected SHA-256 digest through a separately authenticated release channel.
    • Verify the digest before execution.
    • Prefer a cryptographic signature tied to a documented publisher key.
    • Inspect the downloaded script before running it.
    • Execute it explicitly only after successful verification and informed user approval.
  4. Publish immutable, versioned installer URLs rather than mutable install.sh and install.ps1 endpoints.
  5. Document that installation should occur as a non-privileged user unless a specific operation demonstrably requires elevation.
  6. Require agents to ask for explicit user consent before downloading or executing any installer.
  7. Document the installer’s filesystem changes, network access, installed binaries, requested permissions, and uninstall procedure.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 9)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 122)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
---
name: cloak-env-protection
description: Protect .env secrets from AI agents. Real credentials encrypted in a vault — agents see structurally valid sandbox values on disk.
version: 0.1.0
---

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill includes curl ... | sh and PowerShell irm ... | iex, both of which fetch code from the internet and execute it immediately. In a skill consumed by coding agents, this is dangerous because it encourages unsafely executing unreviewed remote code and could directly compromise the developer machine or CI environment.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

bash
# macOS / Linux
curl -fsSL https://getcloak.dev/install.sh | sh

# Windows (PowerShell)
irm https://getcloak.dev/install.ps1 | iex

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The shell pipe into sh is a classic command-chaining abuse pattern because it converts downloaded network content straight into executable code in one step. This collapses review, verification, and execution into a single action, increasing the chance of silent compromise if the source is malicious or tampered with.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

bash
# macOS / Linux
curl -fsSL https://getcloak.dev/install.sh | sh

# Windows (PowerShell)
irm https://getcloak.dev/install.ps1 | iex

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
On first interaction with a project, check for a `.cloak` file in the project root.

- **`.cloak` exists** → Cloak is active. Follow the rules below.
- **`.cloak` does NOT exist but `.env` exists** → suggest `cloak init` (always ask first, never run without consent).
- **Neither exists** → no action needed.

## Rules

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill recommends installing software by piping a network-fetched script directly into a shell/PowerShell interpreter, with no integrity verification, pinning, or warning about the trust boundary. In an agent skill context, this is especially risky because it normalizes a dangerous execution pattern that could lead to arbitrary code execution if the remote endpoint, transport, or distribution pipeline is compromised.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.