Back to skill

Security audit

Office 365 + Adobe User Provisioning

Security checks for vulnerabilities and agentic risk

Overview

This skill can manage real Microsoft 365 and Adobe accounts, but its network API and credential handling are risky enough to require careful review before installation.

Install only in a tightly controlled admin environment after removing any bundled or production .env secrets, adding authentication before enabling the HTTP API, binding the API to localhost unless deliberately protected, disabling plaintext password email/BCC delivery, and requiring explicit confirmation for reset, delete, and selftest operations.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
app/api/server.py:59
Finding

Unauthenticated Network-Accessible Tenant Administration API

Content
View full analysis
/users", methods=["POST"]) def create_user(provider: str): provider = normalize_provider(provider) payload = request.get_json(force=True) or {} identifier = payload.get("identifier") if not identifier: return failure("Missing identifier", 400) product = payload.get("product") options = payload.get("options") or {} result = user_service.create_user(provider, identifier, product=product, **options) return success(result, 201) @app.route("/api//users//assign", methods=["POST"]) def assign_product(provider: str, identifier: str): provider = normalize_provider(provider) payload = request.get_json(force=True) or {} product = payload.get("product") if not product: return failure("Missing product", 400) result = user_service.assign_product(provider, identifier, product) return success(result) @app.route("/api//users//password", methods=["POST"]) def reset_password(provider: str, identifier: str): provider = normalize_provider(provider) payload = request.get_json(force=True) or {} result = user_service.reset_password( provider, identifier, new_password=payload.get("new_password"), force_change_password=payload.get("force_change_password", True), ) return success(result) @app.route("/api//users/", methods=["DELETE"]) def delete_user(provider: str, identifier: str): provider = normalize_provider(provider) result = user_service.delete_user(provider, identifier) return success(result) @app.route("/api//users/", methods=["GET"]) def describe_user(provider ...[truncated 2539 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
app/providers/adobe/auth.py:83
Finding

Adobe Administrative Credentials Can Be Sent to Arbitrary Configured Endpoints

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
app/providers/adobe/client.py:259
Finding

Adobe Administrative Bearer Token Exposed Through Debug Logging

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
app/providers/office365/user_manager.py:181
Finding

Plaintext Account Passwords Are Sent to Configurable Hidden Recipients

Content
View full analysis

欢迎加入 Office 365!

尊敬的 {display_name},

您的 Office 365 账户已成功创建,现在您可以开始使用 Microsoft 365 的各项服务了。

账户信息

  • 登录邮箱:{user_principal_name}
  • 初始密码:{self.default_password}
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (65)

Context-Inappropriate Capability

Critical
Category
Not specified by scanner
Confidence
100% confidence
Finding

The document says the local .env contains real production secrets, including client secrets, SMTP credentials, and a default password. This creates an immediate high-risk path to credential theft, unauthorized account access, mass account takeover, and abuse of email and provisioning systems; the presence of a default password further amplifies compromise risk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a full user lifecycle management tool for Microsoft 365 and Adobe Creative Cloud. However, the provided code chunk is limited to a generic logging helper that configures Python logging handlers and formatting. This is a supporting infrastructure component, not evidence of the declared account-management behavior. Because the actual code chunk's purpose is materially different from the declared purpose and does not implement any of the described capabilities, this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

代码与声明部分重合于 Adobe Creative Cloud 用户管理,但与声明相比明显不完整。该代码块专注于 Adobe UMAPI,访问的资源与操作对象都是 Adobe 组织、产品、Product Profiles 和用户,没有任何 Microsoft 365/Office 365/Azure AD/Graph/世纪互联相关接口、对象或流程。因此,如果将“该技能的描述是否准确代表所给代码块”作为判断标准,应视为不匹配:声明描述的是一个统一的 M365+Adobe 账户管理工具,而实际代码块只是其中 Adobe provider 的一部分。虽然后者可作为整体技能的子模块,但就当前提供的代码片段而言,描述范围明显大于实际行为。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents the skill as a unified account-management tool for both Microsoft 365 (21Vianet) and Adobe Creative Cloud, including bulk operations and shared provider behavior. However, the supplied code chunk is narrowly scoped to Adobe only: it uses AdobeTokenManager, AdobeClient, Adobe product/profile APIs, and Adobe user lifecycle operations. There is no Microsoft 365-related logic, no evidence of 21Vianet integration, and no bulk-processing implementation in this snippet. The implemented Adobe capabilities do align with part of the declared purpose, but the description materially overstates the scope of this specific code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

从已提供代码看,其核心确实属于 Microsoft 365 用户与许可证管理的一部分,因此与声明的大方向部分一致;创建用户、查询用户、更新/删除用户、查询 SKU、分配许可证都符合“开账号/管理 Office/M365”描述。但存在明显描述-行为不完全匹配之处:第一,代码包含 send_mail 发信能力,这属于额外的未声明能力,且会访问用户邮箱/邮件发送资源,不只是开户管理的支持细节;第二,声明强调同时支持 Adobe Creative Cloud,而此代码完全没有 Adobe 相关实现;第三,声明提到重置密码、批量、自检,但本片段未体现这些能力。综合判断,应标记为 mismatch,主要因为存在未声明的邮件发送能力以及声明范围明显超出该代码实际覆盖范围。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

该描述宣称的是一个覆盖 Microsoft 365 与 Adobe Creative Cloud 的统一账号管理工具,能力范围较广;但当前代码片段只实现了 Office 365/Microsoft 365 用户管理核心中的部分功能,且依赖 Graph Client 和 LicenseManager 完成创建、删号、重置密码及许可证分配。同时,代码还会在配置启用时通过 SMTP 发送通知邮件,属于实际存在但未在声明中明确说明的外部资源访问与能力。虽然这可能只是整体技能中的一个模块而非全部实现,但按提供的代码片段来看,声明范围明显大于实际行为,并且存在未声明的邮件发送能力,因此应判定为不匹配。

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The documentation explicitly states that the skill is self-contained and ships with credentials, which strongly suggests embedded secrets are distributed alongside operational code. Bundling live credentials into a portable skill dramatically increases the risk of secret leakage, unauthorized account provisioning, and compromise of production services.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions tell the operator to provide the initial password back to the requester in plain-language results. Disclosing credentials in chat or normal result text creates a high likelihood of interception, accidental retention in logs/transcripts, and unauthorized access to newly created accounts, especially in a provisioning context handling production identities.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The delete_user method removes a user from the organization and its docstring notes that all entitlements are automatically removed. This is a destructive, potentially irreversible administrative action, but the code contains no confirmation prompt or other user-facing safeguard before execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The account creation notification sends the initial password in plaintext email. Email is frequently stored, forwarded, indexed, and accessible across multiple systems, so transmitting credentials this way can directly compromise newly created Microsoft 365 accounts, especially in a privileged user-provisioning workflow like this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The password reset notification emails the new password in plaintext to the recipient. Because this module manages Office 365 identities, disclosure of reset credentials can immediately lead to account takeover if the mailbox, mail path, archives, or BCC recipients are compromised or misconfigured.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 50)May include surrounding context.

md
Raises:
        ValueError: 如果必需配置项缺失
    """
    # 加载 .env 文件
    load_dotenv()
    
    # 必需配置项

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 50)May include surrounding context.

md
Raises:
        ValueError: 如果必需配置项缺失
    """
    # 加载 .env 文件
    load_dotenv()
    
    # 必需配置项

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · app/providers/adobe/client.py (reported line 113)May include surrounding context.

python
Raises:
        ValueError: 如果必需配置项缺失
    """
    # 加载 .env 文件
    load_dotenv()
    
    # 必需配置项

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.py (reported line 19)May include surrounding context.

python
Raises:
        ValueError: 如果必需配置项缺失
    """
    # 加载 .env 文件
    load_dotenv()
    
    # 必需配置项

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · config.py (reported line 97)May include surrounding context.

python
Raises:
        ValueError: 如果必需配置项缺失
    """
    # 加载 .env 文件
    load_dotenv()
    
    # 必需配置项

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The README advertises destructive operations such as password resets, deletes, and selftests that create and remove real users, but it does not give a prominent warning about operational impact, authorization requirements, or production-safety precautions. In an agent skill context, this is more dangerous because the documentation is effectively an action guide for an automated system that may execute account changes quickly and at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README advertises destructive actions like reset and delete alongside routine commands without a prominent warning about irreversible or disruptive effects. In a skill that manages Microsoft 365 and Adobe identities, this can normalize dangerous operations and make operators or agents more likely to execute them without appreciating consequences such as account lockout, data-access disruption, or permanent deletion.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation phrases are broad everyday account-management terms such as '新建用户', '重置密码', and '删除用户', which can cause the skill to auto-activate in contexts where the user did not explicitly intend to invoke this high-privilege provisioning tool. Because the skill performs sensitive identity and license operations, accidental invocation increases the chance of unintended account creation, password resets, or deletions if an agent proceeds without strong confirmation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill advertises capabilities that imply file, environment, and network access but does not declare any explicit tool scope or permission boundaries. In a provisioning skill that can affect external accounts and secrets, missing scope metadata increases the chance of overbroad execution and makes it harder to enforce least privilege.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation text uses very broad trigger phrases around common account-help requests, which can cause the skill to activate in situations the user did not intend. For a tool that can create, reset, delete, and provision external accounts, overbroad activation materially raises the risk of unintended privileged actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill exposes destructive delete and self-test commands, and the self-test is described as creating, modifying, and deleting a temporary user. Without prominent warnings, safeguards, and environment separation, operators may trigger actions that alter production accounts or consume licenses unintentionally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code exposes a DELETE endpoint that removes a user via user_service.delete_user(...), but there is no confirmation prompt, user-visible disclosure, or explanatory comment/docstring indicating that the operation is destructive. For safety-sensitive actions like deletions, the file provides no warning signal to callers beyond the HTTP method itself.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This code prints and prompts users only in Chinese, including error and selection messages. The file does not provide any user opt-in, fallback language, or justification that the skill is intentionally limited to a Chinese-speaking locale, which fits the language/locale policy violation category.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
86% confidence
Finding

The code persists arbitrary provider state as plaintext JSON on disk without any access control, encryption, or filtering of sensitive fields. In the context of a user-provisioning skill for Microsoft 365 and Adobe accounts, this state may include credentials, reset results, tokens, or personal account metadata, creating a real risk of local disclosure or accidental retention of sensitive administrative data.

Content

Scanner excerpt · app/core/state.py (reported line 24)May include surrounding context.

python
def write_state(provider: str, data: Dict[str, Any]) -> None:
    """Persist state to disk."""
    _ensure_state_dir()
    path = state_file(provider)
    path.write_text(json.dumps(data, ensure_ascii=False, indent=2))

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
app/providers/office365/user_manager.py:30

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
main.py:169