Back to skill

Security audit

Volcengine TOS Storage

Security checks for vulnerabilities and agentic risk

Overview

This Volcengine storage skill is mostly purpose-aligned, but it deserves review because it can change cloud storage and silently reads local credential files with some under-disclosed safeguards.

Review this before installing if the agent will have access to real Volcengine credentials or important buckets. Use least-privilege IAM keys, install a pinned reviewed `tos` SDK version in an isolated environment, avoid running it from untrusted directories containing `.env` files, and treat upload/copy/presign/create operations as user-confirmed cloud mutations.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:22
Finding

Unpinned Third-Party TOS SDK Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:22
Vulnerability Type: Supply-chain risk caused by an unpinned third-party dependency
Risk Level: Medium

Vulnerable Code:

bash
pip install tos

Technical Analysis

The installation instructions retrieve the latest available version of the tos package without specifying a reviewed version or verifying an integrity hash. Consequently, the dependency installed by a user may differ from the dependency that was available when this Skill was audited.

The project references identify the intended package as the official Volcengine TOS SDK, and there is no evidence that the package is currently malicious. Nevertheless, an unpinned installation leaves the Skill exposed to future package compromise, a malicious release, compromised publishing credentials, or an unexpected backward-incompatible release.

The dependency is imported at module initialization:

python
try:
    import tos
except ImportError:
    print("Error: tos SDK is not installed. Run: pip install tos", file=sys.stderr)
    sys.exit(1)

Imported package code executes in the context of the user running the Skill. The script subsequently accesses Volcengine access keys and uses them to initialize the SDK client.

Attack Path

  1. An attacker compromises the upstream package, its publishing account, or a future package release.
  2. A user follows the documented command pip install tos.
  3. The package manager downloads and installs the compromised latest release because no version or hash is constrained.
  4. Malicious package code executes during installation or when import tos runs.
  5. The package code can access the process environment, including configured Volcengine credentials, and act with the operating-system privileges of the user running the Skill.
  6. The stolen credentials may then be used within the permissions assigned to the corresponding Volcengine IAM id ...[truncated 454 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the TOS SDK to a specific, reviewed version in a dependency file, for example:
    text
    tos==REVIEWED_VERSION
    
  2. Generate and verify package hashes using a locked requirements file:
    bash
    python -m pip install --require-hashes -r requirements.txt
    
  3. Record the expected package name, version, source repository, and package index in the documentation.
  4. Review dependency updates before changing the pin, and use automated vulnerability and provenance scanning.
  5. Install dependencies in an isolated virtual environment using a trusted package index.
  6. Apply least-privilege IAM policies to the configured credentials so that dependency compromise cannot access unrelated cloud resources.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/tos_manage.py:182
Finding

Documented Download Integrity Validation Is Not Implemented

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:95; scripts/tos_manage.py:182-186
Vulnerability Type: Missing download integrity validation and misleading security documentation
Risk Level: Low

Documented Security Guarantee:

markdown
- 下载时验证写入文件的大小与 Content-Length 一致。

This states that the downloaded file size is validated against Content-Length.

Implemented Download Logic:

python
def cmd_download(args: argparse.Namespace) -> None:
    client = _get_client()
    output_path = Path(args.file)
    output_path.parent.mkdir(parents=True, exist_ok=True)
    client.get_object_to_file(args.bucket, args.key, str(output_path))
    size = output_path.stat().st_size
    result = {
        "action": "download",
        "bucket": args.bucket,
        "key": args.key,
        "file": str(output_path.resolve()),
        "size": size,
    }
    if args.print_json:
        _json_out(result)
    else:
        print(f"Downloaded tos://{args.bucket}/{args.key} -> '{output_path}' ({size} bytes)")

Technical Analysis

The implementation records the size of the resulting local file but never obtains or compares it with the remote object's Content-Length. It also does not independently validate a cryptographic digest or ETag. Therefore, the explicit integrity guarantee in SKILL.md is not enforced by the script.

The underlying SDK may detect some network-transfer failures itself, but the script does not implement the promised independent check. If the SDK returns without raising an exception while the resulting file is incomplete or inconsistent, the script reports the operation as successful.

This issue is primarily a missing validation control rather than evidence of a malicious download mechanism. Exploitation depends on an abnormal or adversarial condition capable of causing the SDK to produce an inconsistent local file without raising an error.

Attack Path

...[truncated 1175 chars]

Remediation
View remediation

Remediation Suggestions

  1. Retrieve trusted remote object metadata with head_object before downloading and retain the expected content_length.
  2. Download to a temporary file in the destination directory rather than directly replacing the requested output.
  3. Compare the temporary file's size with the expected remote length after the SDK call completes.
  4. If the sizes differ, delete the temporary file, report the mismatch to standard error, and return a nonzero exit status.
  5. Atomically rename the temporary file to the requested destination only after validation succeeds.
  6. Where reliable integrity metadata is available, verify a cryptographic checksum in addition to length. Do not assume an ETag is always a simple content hash, particularly for multipart uploads.
  7. Add automated tests that simulate truncation, metadata mismatch, interrupted transfers, and pre-existing destination files.
  8. If independent validation is intentionally delegated to the SDK, revise SKILL.md so that it does not claim a check the script does not perform.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 22)May include surrounding context.

md
|-----------|----------|----------|
| `list-buckets` | `client.list_buckets()` | `GET /` |
| `create-bucket` | `client.create_bucket(bucket)` | `PUT /{bucket}` |
| `delete-bucket` | `client.delete_bucket(bucket)` | `DELETE /{bucket}` |
| `list-objects` | `client.list_objects_type2(bucket, prefix, max_keys)` | `GET /{bucket}?list-type=2` |
| `upload` | `client.put_object_from_file(bucket, key, file_path, content_type)` | `PUT /{bucket}/{key}` |
| `download` | `client.get_object_to_file(bucket, key, file_path)` | `GET /{bucket}/{key}` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 26)May include surrounding context.

md
| `list-objects` | `client.list_objects_type2(bucket, prefix, max_keys)` | `GET /{bucket}?list-type=2` |
| `upload` | `client.put_object_from_file(bucket, key, file_path, content_type)` | `PUT /{bucket}/{key}` |
| `download` | `client.get_object_to_file(bucket, key, file_path)` | `GET /{bucket}/{key}` |
| `delete` | `client.delete_object(bucket, key)` | `DELETE /{bucket}/{key}` |
| `head` | `client.head_object(bucket, key)` | `HEAD /{bucket}/{key}` |
| `presign` | `client.pre_signed_url(method, bucket, key, expires)` | (客户端签名) |
| `copy` | `client.copy_object(dst_bucket, dst_key, src_bucket, src_key)` | `PUT /{bucket}/{key}` + `x-tos-copy-source` |

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The script automatically loads credentials from a .env file in the current working directory before checking a repo-local .env. In an agent or automation context, operating in an untrusted directory can cause the tool to silently ingest attacker-supplied credentials or endpoints, redirecting storage operations or exfiltrating data to an attacker-controlled TOS account/service endpoint.

Content

Scanner excerpt · scripts/tos_manage.py (reported line 52)May include surrounding context.

python
def _load_env() -> None:
    _load_dotenv(Path.cwd() / ".env")
    repo_root = _find_repo_root(Path(__file__).resolve())
    if repo_root:
        _load_dotenv(repo_root / ".env")

Credential Access

High
Category
Privilege Escalation
Confidence
89% confidence
Finding

The tool also loads a repository-root .env discovered by walking parent directories from the script path, which can pull secrets from files not explicitly chosen by the caller. This broad, implicit trust boundary increases the risk of unintended credential use, secret confusion, and endpoint manipulation when the skill runs inside a larger repository or shared workspace.

Content

Scanner excerpt · scripts/tos_manage.py (reported line 55)May include surrounding context.

python
_load_dotenv(Path.cwd() / ".env")
    repo_root = _find_repo_root(Path(__file__).resolve())
    if repo_root:
        _load_dotenv(repo_root / ".env")


def _get_client() -> tos.TosClientV2:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a Python script that relies on environment variables for cloud credentials and reads local files for upload/download operations, but the manifest does not declare any explicit tool scope or permissions. This creates a governance gap: an agent may be allowed to access secrets and filesystem content without transparent least-privilege boundaries, increasing the risk of unintended credential exposure or file access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file contains substantial operational instructions in Chinese, including headings, command descriptions, safety rules, and guidance, while other parts are in English. That effectively imposes a language requirement on users without opt-in or justification, which matches the language/locale policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

该 markdown 文件的标题和内容均以中文呈现,属于自然语言层面的语言/locale 约束。按照规则,若未提供用户可选语言或未明确说明这是特定区域/合规场景所必需,则可视为语言策略风险。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.