Back to skill

Security audit

Автоматический поиск клиентов (родителей) для репетитора по математике в группах ВКонтакте с умной фильтрацией и приоритизацией онлайн-запросов.

Security checks for vulnerabilities and agentic risk

Overview

This VK lead-monitoring skill is purpose-aligned, but it asks users to store an API token in plaintext and creates recurring social-media data collection without enough controls or privacy guidance.

Install only if you are comfortable with an agent repeatedly querying VK and building a local lead database from public posts. Use a least-privilege VK token, avoid committing or sharing config.json after adding the token, rotate the token if exposed, and make sure you can disable the 3-hour schedule and delete collected CSV/Sheet data when no longer needed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
config.json:6
Finding

Plaintext Storage of VK Service Token

Content
View full analysis

Vulnerability Details

File Location: config.json, lines 6-9
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: Medium

json
"auth": {
  "vk_service_token": "PASTE_YOUR_TOKEN_HERE",
  "api_version": "5.131"
},

Technical Analysis

The configuration provides a field intended to be replaced with a real VK service token. The project documentation directs users to place their service token into the configuration file, causing the credential to be stored as plaintext inside the Skill directory.

Plaintext configuration secrets may be exposed through source-control commits, backups, shared archives, overly permissive filesystem access, diagnostic bundles, or access by other local processes. Although the distributed file contains only a placeholder and no active credential, following the documented setup procedure creates the insecure condition.

Attack Path

  1. A user replaces PASTE_YOUR_TOKEN_HERE with a valid VK service token.
  2. The populated config.json remains in the Skill directory as plaintext.
  3. The file is inadvertently committed, archived, shared, backed up, or read by an unauthorized local user or process.
  4. An attacker extracts the token from the vk_service_token field.
  5. The attacker submits VK API requests using the stolen token.
  6. The attacker gains access to the VK API operations and data permitted by that token until it is revoked or expires.

Impact Assessment

Successful exploitation can compromise the confidentiality of the VK service token and permit unauthorized VK API access within the token's assigned scope. The precise impact depends on the permissions attached to the token. Potential consequences include unauthorized access to API-visible information, consumption of API quotas, and actions attributable to the associated VK application.

This issue does not directly provide operating-system privilege escalation or arbitrary code executi ...[truncated 88 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the token value from the tracked configuration file and load it from an environment variable, such as VK_API_TOKEN.
  2. Retain only a non-sensitive reference in configuration, for example:
    json
    "auth": {
      "token_env": "VK_API_TOKEN",
      "api_version": "5.131"
    }
    
  3. Prefer an operating-system credential store or managed secret service when available.
  4. Add local files capable of containing real credentials to .gitignore, and provide a sanitized example configuration separately.
  5. Restrict secret-file permissions to the account running the Skill.
  6. Ensure logs, error reports, and generated output never include the token or request URLs containing it.
  7. Validate at startup that the placeholder has not been treated as a real token, without printing the supplied credential.
  8. Document token rotation and immediate revocation procedures for suspected exposure.
  9. Apply the minimum VK permissions necessary for reading the intended public data.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The README instructs users to obtain and place a VK access token into a local config file for a skill that has internet access, file system read/write, and scheduled execution. Even though it does not directly exfiltrate the token in this file, encouraging long-lived credential storage in plaintext increases the blast radius if the skill, host, or logs are later compromised.

Content

Scanner excerpt · README.md (reported line 14)May include surrounding context.

md
* `target_groups`: Впишите ссылки на 10-15 групп, где сидит ваша аудитория.
3.  **Запуск**: Скажите агенту: *"Запусти мониторинг клиентов в ВК"*.

## 🔑 Где взять Access Token? (Для пользователя)

Вам не нужно быть программистом. Это бесплатно и занимает 2 минуты:
1. Перейдите в [VK Developers](https://vk.com/apps?act=manage).

Ae4

Medium
Category
analysis-evasion
Confidence
80% confidence
Finding

Suspicious Unicode normalization or mixed-script content

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README presents all user-facing instructions in Russian and does not indicate that the skill is region- or language-specific beyond using VK as a platform. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill performs recurring network monitoring of VK groups and persists collected results, but it does not explicitly warn the user that the automation will continue making outbound requests and storing personal data from posts. This creates a consent and privacy risk because users may enable ongoing collection without understanding the scope, duration, or retention of the data being gathered.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill requests a VK service token but does not include guidance on secure handling, storage, masking, or scope minimization of the credential. This is dangerous because users may paste sensitive tokens into insecure contexts or the implementation may retain them longer than necessary, enabling account or API abuse if exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The instruction to set a timer every 3 hours enables persistent automated execution without a clear user-facing warning or confirmation. In a skill with internet access and task scheduling permissions, silent recurrence increases the risk of unintended continuous surveillance, resource consumption, and unnoticed repeated data collection.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill stores author names, post links, and excerpts of requests in CSV or Google Sheets without a clear privacy notice, minimization policy, or retention controls. Even if the source content is publicly accessible, compiling and persisting identifiable information into a lead database materially increases privacy and misuse risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The configuration explicitly stores VK post URLs, author identifiers, and full post text in a CSV file for lead generation. Because this skill is designed to monitor and collect data about individuals in social groups, retaining personal data without minimization, consent handling, or any privacy notice creates a real privacy and compliance risk if the file is exposed, reused, or processed beyond the original context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The natural-language content appears to require Russian, including description, trigger examples, and operational instructions, but there is no indication that the skill offers language choice or is intentionally restricted to Russian-speaking users. Per the policy, forcing a specific language without opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The config uses Russian-only values and keywords such as "ЗАМЕНИТЕ_ЭТИ_ССЫЛКИ_НА_ВАШИ", "репетитор", and "нужен учитель" with no indication that language selection is optional or user-configurable. That creates a natural-language locale constraint that is not documented as opt-in or region-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.