Back to skill

Security audit

User Provision

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real account-provisioning skill, but it needs review because it relies on unpinned external code and handles initial passwords in unsafe ways while using powerful admin credentials.

Before installing, pin and review the external repository and dependencies, run it in an isolated admin environment, replace shared default passwords with per-user one-time credentials or an approved activation flow, prevent passwords from appearing in chat output or ordinary email, and require explicit confirmation of provider, user, products, and side effects before account creation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
skill.md:32
Finding

Mutable Remote Code Is Retrieved and Executed with Privileged Credentials

Content
View full analysis

Vulnerability Details

File Location: skill.md:32-40
Vulnerability Type: Remote code retrieval and insecure software supply chain
Risk Level: High

Vulnerable Code Snippet

bash
git clone https://github.com/eggyrooch-blip/office365-tools && cd office365-tools && pip install -r requirements.txt

The surrounding instructions identify this remote repository as the authoritative implementation and direct the agent to consult its documentation when implementation details are uncertain.

Technical Analysis

The Skill package does not contain the provisioning implementation. Instead, it directs the operator or agent to clone the current state of an external GitHub repository, install its dependency set, and execute its Python CLI.

No immutable commit hash, signed release, checksum, dependency lockfile requirement, package hash verification, or mandatory source review is specified. Consequently, the effective code executed by the Skill can change after this Skill has been reviewed. In addition, pip install -r requirements.txt may run package installation or build logic from dependencies selected by the mutable remote repository.

This is especially dangerous because the resulting CLI is expected to run where the following sensitive values are available:

  • Microsoft Entra application client secret
  • Tenant identifier and client identifier
  • Adobe User Management API credentials
  • SMTP username and password
  • Account default-password configuration

The behavior therefore matches both remote payload retrieval and an insecure dependency supply chain.

Attack Path

  1. An attacker compromises the referenced GitHub account, repository, maintainer credentials, or a dependency named in requirements.txt.
  2. The attacker adds malicious Python code, malicious package installation logic, or a substituted dependency version.
  3. An operator follows the Skill instructions and clones the ...[truncated 1061 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include the reviewed implementation inside the Skill package whenever feasible.
  2. If external retrieval is necessary, pin the repository to a reviewed full commit hash rather than a mutable branch or tag.
  3. Verify a cryptographic checksum or signed release before executing downloaded content.
  4. Pin every direct and transitive Python dependency to an exact reviewed version.
  5. Require package hashes, such as through a hash-locked requirements file and pip --require-hashes.
  6. Install and execute the CLI inside an isolated virtual environment or container with restricted filesystem and network access.
  7. Do not expose production secrets during installation or initialization.
  8. Use short-lived credentials and separate least-privilege service principals for Office 365, Adobe, and SMTP.
  9. Treat remote documentation as untrusted input rather than authoritative agent instructions.
  10. Perform source and dependency review whenever the pinned revision changes.

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:48
Finding

Predictable Shared Initial Password in Copy-Ready Configuration

Content
View full analysis

Vulnerability Details

File Location: skill.md:48-55
Vulnerability Type: Predictable default credential
Risk Level: High

Vulnerable Code Snippet

env
CLIENT_ID=your-entra-app-client-id
TENANT_ID=your-entra-tenant-id
CLIENT_SECRET=your-entra-app-secret
DEFAULT_PASSWORD=ChangeMe@2025
DEFAULT_DOMAIN=yourcorp.partner.onmschina.cn
FORCE_CHANGE_PASSWORD=true

Technical Analysis

The copy-ready environment template supplies ChangeMe@2025 as a usable initial password. Because DEFAULT_PASSWORD is shared configuration rather than a per-user generated secret, operators may copy the example unchanged or configure another static password that is reused for every provisioned account.

Requiring a password change on first login reduces exposure only after the legitimate user authenticates. It does not protect a newly created account before its first legitimate login, and it provides no protection if forced password change is disabled, misconfigured, or not enforced by the remote implementation.

Password predictability is particularly serious for automated onboarding because account identifiers and email naming conventions may be discoverable or guessable.

Attack Path

  1. An operator copies the provided .env template without replacing DEFAULT_PASSWORD, or replaces it with another organization-wide static value.
  2. The provisioning CLI creates one or more Office 365 accounts with that shared password.
  3. An attacker learns or guesses a newly provisioned account identifier.
  4. The attacker authenticates with the publicly documented or otherwise known shared password before the intended user completes first login.
  5. The attacker changes the password or establishes access through the newly provisioned account, subject to tenant authentication controls.

Impact Assessment

Exploitation can result in unauthorized access to individual newly provisioned Office 365 accounts. The accessible ...[truncated 326 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the usable password value from the example and fail securely if a placeholder remains configured.
  2. Generate a unique, cryptographically random initial password for every user.
  3. Use a cryptographically secure random-number generator and sufficient password entropy.
  4. Never use a tenant-wide or batch-wide shared initial password.
  5. Enforce password change at first login and verify that the tenant accepted this policy.
  6. Prefer passwordless onboarding, temporary access passes, or an identity-provider activation workflow where supported.
  7. Expire unused bootstrap credentials after a short period.
  8. Add automated checks that reject known examples, placeholders, and previously used initial passwords.
  9. Monitor newly provisioned accounts for authentication before the intended activation event.

T09 · Insecure Skill Coding Practices

Error
Location
skill.md:122
Finding

Conflicting Instructions Can Disclose Initial Passwords in Agent Output

Content
View full analysis

Vulnerability Details

File Location: skill.md:122-127, 163-169, 215-220
Vulnerability Type: Plaintext credential exposure through output and notification channels
Risk Level: High

Vulnerable Instruction Snippets

English translation of the relevant Skill directives:

text
The CLI will create the user, assign a license, and send a notification
email containing the initial password.

The successful result is expected to contain:
id, userPrincipalName, password
text
Give the user a summary containing:
LDAP, email, initial password, or invitation information.
text
Do not echo the initial password in logs.
It must appear only in the email body, and console output must be masked.

Technical Analysis

The Skill contains mutually inconsistent credential-handling requirements. One delivery instruction requires the agent to provide a summary containing the initial password, while the security section states that the password must appear only in the notification email and must be masked in console output. The expected CLI result also explicitly contains a password field.

An agent following the delivery requirement can place the plaintext credential in its response even if the CLI itself masks console logs. Agent responses may be retained in conversation history, model telemetry, orchestration logs, support transcripts, browser history, or other systems that are not approved secret-delivery channels.

The notification design also sends the initial password through ordinary SMTP email. Depending on mail configuration and retention policies, plaintext credentials may be copied into sender mailboxes, recipient mailboxes, BCC mailboxes, mail gateways, archives, and backups.

Attack Path

  1. The provisioning CLI creates an account and returns an object containing the initial password.
  2. The agent follows the delivery instruction requiring an account summary with that pass ...[truncated 1272 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the requirement to include initial passwords in agent responses, summaries, logs, command output, or reports.
  2. Make the security rule unambiguous: no plaintext password may be returned through the agent interface.
  3. Change CLI results so they do not contain a plaintext password field after provisioning.
  4. Return only account identifiers, product assignments, verification status, and secret-delivery status.
  5. Use a one-time secret link, temporary access pass, passwordless activation, or approved enterprise secret-delivery system.
  6. Avoid ordinary email for password delivery. If email is unavoidable, send an activation link rather than the credential itself.
  7. Do not send bootstrap credentials to BCC recipients.
  8. Redact secrets at the source before data reaches agent tooling, telemetry, or exception handlers.
  9. Configure short expiration periods and revoke bootstrap credentials immediately after first use.
  10. Add automated tests that fail if generated output contains values matching password fields or configured secrets.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skill.md (reported line 46)May include surrounding context.

  1. Adobe:Developer Console 已建 OAuth Server-to-Server credential 绑定 User Management API
  2. 首次运行:python main.py office365 init 和 python main.py adobe init --force-default(选默认产品,例如 All Apps)

.env 模板(复制到 office-usertools/.env 后按实际填写)

env
# --------- Office 365(世纪互联) ---------

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly tells the agent to include '初始密码' in the user-facing summary, which is a direct instruction to expose credentials in conversational output. This is particularly dangerous because agent transcripts, logs, chat history, screenshots, and downstream integrations may retain or leak the password, creating a straightforward path to account compromise.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises broad trigger phrases such as '新增用户', '开户', and '给 XX 开账号', which are common administrative phrases and can cause the agent to invoke a high-impact provisioning workflow without strong disambiguation. In this context the action creates accounts, assigns licenses, and may reset passwords, so accidental activation can directly lead to unauthorized or mistaken account creation.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The mandatory trigger table contains ambiguous mappings like '新员工开账号' => both O365 + Adobe and '给 XX 开账号' => ask provider then execute, without clear safeguards against overlap or contextual misunderstanding. Because the skill performs privileged identity actions across two independent systems, ambiguous activation increases the chance of over-provisioning or provisioning in the wrong platform.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill instructs that the CLI will send notification emails containing initial passwords, but it does not present a strong user-facing warning or enforce a safer credential-delivery mechanism. Sending initial passwords by email is sensitive because email forwarding, mailbox compromise, or misaddressing can expose credentials and enable immediate account takeover.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.