Back to skill

Security audit

rpe-grafana

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to do its stated Grafana read-only job, but it can send Grafana credentials over plain HTTP if configured that way.

Review before installing if your Grafana is not strictly local or otherwise protected. Use HTTPS, a dedicated least-privilege Viewer/service account, avoid admin credentials, and only point the skill at Grafana dashboards and datasources the agent is authorized to query.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:18
Finding

Grafana Credentials May Be Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: index.js:18-29; insecure configuration example at SKILL.md:51-58
Vulnerability Type: Transmission of reusable credentials over an unencrypted channel
Risk Level: Medium

Vulnerable Code

index.js:18-29:

js
const basicAuth = (user, password) =>
  "Basic " + Buffer.from(`${user}:${password}`).toString("base64");

const grafanaFetch = (url, user, password, path, options = {}) =>
  fetch(`${url}${path}`, {
    ...options,
    headers: {
      Authorization: basicAuth(user, password),
      "Content-Type": "application/json",
      ...options.headers,
    },
  });

SKILL.md:51-58:

json
{
  "plugins": {
    "entries": {
      "rpe-grafana": {
        "enabled": true,
        "config": {
          "url": "http://your-grafana:3000",
          "user": "your-username",

Technical Analysis

The plugin builds a reusable HTTP Basic Authentication value from the configured Grafana username and password or API key. Base64 encoding does not provide encryption. The resulting authorization header is attached to every Grafana request.

The configured URL is accepted without validating its scheme, and the documented setup explicitly demonstrates an http:// Grafana endpoint. If that example is followed across a network, the authorization header and Grafana responses are transmitted without transport encryption.

Authenticated network access is necessary for the Skill's declared purpose, and the reviewed code sends credentials only to the configured Grafana host. However, permitting plaintext transport is not necessary for normal production operation and exposes credentials beyond the minimum safe boundary.

Attack Path

  1. An operator configures GRAFANA_URL or the plugin url with an http:// endpoint, potentially following the supplied documentation.
  2. A user invokes one of the Grafana tools.
  3. grafanaFetch const ...[truncated 1117 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require Grafana URLs to use the https: scheme before making any request.
  2. If local development requires plaintext HTTP, permit it only through an explicit opt-in setting and restrict it to loopback addresses such as localhost, 127.0.0.1, or ::1.
  3. Replace the http://your-grafana:3000 documentation example with an HTTPS URL and clearly warn that Basic Authentication must not be used over plaintext HTTP.
  4. Recommend a dedicated, least-privilege Grafana service account token with only the dashboard and datasource query permissions required by this Skill.
  5. Avoid the fallback username of admin; require explicit credential configuration so users are not encouraged to use an administrative account.
  6. Where appropriate, validate the configured destination against an administrator-controlled allowlist to reduce accidental credential disclosure to an incorrect host.
  7. Return a clear configuration error without issuing a request when the URL is missing, malformed, or uses an unsafe scheme.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares access to environment-provided Grafana credentials and implies network interaction with a Grafana instance, but it does not define any explicit tool scope such as allowed-tools or permissions. In agent environments, missing scope declarations can cause overbroad execution privileges or make review and policy enforcement harder, increasing the chance that a skill with secret and network access is used in unintended ways.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs users to supply Grafana credentials and describes executing panel-derived requests against Grafana, but it does not include any warning about safe secret handling, least-privilege account use, or the sensitivity of dashboard-backed queries. This can lead users to provide high-privilege credentials or overlook that querying a panel may trigger requests based on dashboard configuration, potentially exposing sensitive data from dashboards or linked datasources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The configuration loader reads GRAFANA_USER and GRAFANA_PASSWORD from the environment, which are credential sources. There is no accompanying user-facing disclosure, warning comment, or tool description noting that credentials will be consumed from environment variables.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The helper issues authenticated HTTP requests to Grafana using an Authorization header, and later tools use it to send dashboard identifiers and panel query payloads. The file has no confirmation prompt, user-facing log/print, or warning comment/docstring explaining that remote requests and credential-backed access will occur.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.