Back to skill

Security audit

devopsellence

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent deployment-helper skill, but users should be careful with provider tokens and cleanup commands that affect live infrastructure.

Install only if you intend to let the agent operate devopsellence deployments and nodes. Prefer the stdin token examples, avoid the --token form for real secrets, verify the target node or environment before deploy/remove actions, and run cleanup commands only when you mean to detach, uninstall, and remove that node.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:137
Finding

Cloud Provider Token Exposed Through Process Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 137 and 173
Vulnerability Type: Secret exposure through command-line arguments
Risk Level: Medium

Vulnerable Code

The same insecure alternative appears at both locations:

sh
# or: devopsellence provider login hetzner --token "$HCLOUD_TOKEN"

Technical Analysis

The instruction expands HCLOUD_TOKEN into the command's argument vector. Depending on the operating system and execution environment, command arguments may be visible to other local processes, process-monitoring tools, audit systems, shell tracing, diagnostic collectors, or CI/CD telemetry.

Although the Skill presents an stdin-based command as the preferred option, explicitly documenting the --token alternative can cause agents or users to select the less secure path. The environment variable itself is not hardcoded, but its value becomes plaintext in the spawned process's arguments.

Attack Path

  1. A user stores a valid Hetzner provider token in HCLOUD_TOKEN.
  2. The user or agent follows the documented --token alternative.
  3. The shell expands the variable and places its plaintext value in the devopsellence process argument vector.
  4. A local process with sufficient process-inspection access, an audit service, or a telemetry collector captures the arguments while the command runs.
  5. The observer extracts the token and submits authenticated requests to the provider API.
  6. The attacker performs actions allowed by the token's assigned provider permissions.

This path requires local process-observation capability or access to tooling that records command arguments.

Impact Assessment

A disclosed token may permit unauthorized access to the associated Hetzner account or project. The exact impact depends on the token's provider-side permissions and may include viewing infrastructure, provisioning or modifying servers, disrupting workloads, deleting resources, or incurring costs.

The issue does not it ...[truncated 136 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove both documented --token "$HCLOUD_TOKEN" alternatives.
  2. Retain only the stdin-based form:
sh
printf '%s' "$HCLOUD_TOKEN" | devopsellence provider login hetzner --stdin
  1. Add an explicit instruction prohibiting provider secrets in command-line arguments.
  2. Recommend disabling shell tracing before handling secrets and ensuring command output does not echo credential material.
  3. Encourage narrowly scoped, short-lived provider tokens where supported, with prompt rotation after suspected exposure.
  4. If the CLI supports secure credential helpers or platform secret stores, prefer those mechanisms over persistent plaintext environment variables.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 161)May include surrounding context.

sh
devopsellence init --mode solo
devopsellence node create prod-1 --host <ip> --user root --ssh-key ~/.ssh/id_ed25519
devopsellence agent install prod-1
devopsellence node attach prod-1
devopsellence doctor

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The markdown instructs solo cleanup using agent uninstall and node remove --yes, which can affect deployed infrastructure and appear irreversible, but this section does not explicitly warn the user about the consequences before running them. Under the markdown-file criteria, destructive behaviours that could affect system integrity should be accompanied by a clear warning in the skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.