Back to skill

Security audit

Cc Switch

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real provider-switching tool, but its remote installer, persistent credential handling, and inconsistent Codex/Claude scope need review before use.

Install only after reviewing the installer and scripts locally; avoid the curl-to-bash path. Treat stored provider keys as plaintext secrets, use restrictive file permissions, verify the target endpoint before connectivity tests, and expect this skill to persistently modify local provider state and Claude/Codex-related settings.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (55)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The '| bash' construct creates an unsafe command chain that turns remote content directly into executable shell input. In this skill context, where users are encouraged to install quickly, the pattern materially increases exploitation risk because any malicious or altered response is executed immediately with the user's privileges.

Content

Scanner excerpt · README.md (reported line 20)May include surrounding context.

bash
# Download and install the latest version
curl -sSL https://raw.githubusercontent.com/stcatz/cc-switch-skill/main/install.sh | bash

Option 2: Manual Installation

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation tells users to pipe a remote script directly into bash, which executes whatever is currently hosted at that URL without prior inspection or integrity verification. If the repository, branch, hosting path, or network path is compromised, this can lead to immediate arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

The '| bash' chain creates an immediate execution path from downloaded network content into a shell interpreter. In the context of a skill README, this is especially risky because users may copy-paste the command verbatim, giving an attacker a straightforward route to run arbitrary commands if the remote content changes or is intercepted.

Content

Scanner excerpt · README_zh.md (reported line 20)May include surrounding context.

bash
# 下载并安装最新版本
curl -sSL https://raw.githubusercontent.com/stcatz/cc-switch-skill/main/install.sh | bash

方式 2:手动安装

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: cc-switch
description: Dual-mode provider management skill for Codex and compatible CLI tools. Works with cc-switch desktop app OR standalone (no desktop app required). Automatically detects mode: uses SQLite when cc-switch is present, otherwise uses JSON config. Pre-flight connectivity testing runs before switching with user confirmation on failure. For Codex, switching is endpoint-only: it reads the target provider's base URL but does not change cc-switch provider state, and only updates ~/.Codex/settings.json.
---

# CC Switch - Dual-Mode Provider Management

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · SKILL.md (reported line 199)May include surrounding context.

md
---
name: cc-switch
description: Dual-mode provider management skill for Codex and compatible CLI tools. Works with cc-switch desktop app OR standalone (no desktop app required). Automatically detects mode: uses SQLite when cc-switch is present, otherwise uses JSON config. Pre-flight connectivity testing runs before switching with user confirmation on failure. For Codex, switching is endpoint-only: it reads the target provider's base URL but does not change cc-switch provider state, and only updates ~/.Codex/settings.json.
---

# CC Switch - Dual-Mode Provider Management

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The skill documents a --skip-test option that bypasses the pre-flight connectivity/sanity check before switching providers. This weakens a safety control and can allow users or downstream automation to activate misconfigured, malicious, or unavailable endpoints without any verification, increasing risk of credential exposure or service disruption.

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

~/.Codex/skills/cc-switch/scripts/switch_provider.sh
--app Codex
--name "MiniMax"
--skip-test

text

### 4. Delete Provider

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The quick-reference table advertises that switching can be done with --skip-test, normalizing bypass of the only documented safety check. Presenting the bypass as a routine workflow increases the chance that automation or users will disable validation and switch to unsafe endpoints or broken configurations.

Content

Scanner excerpt · SKILL.md (reported line 229)May include surrounding context.

md
| List all | `list_providers.sh` | No |
| List by app | `list_providers.sh --app <app>` | No |
| Switch provider | `switch_provider.sh` | **Yes** (pre-flight) |
| Switch (skip test) | `switch_provider.sh --skip-test` | No |
| Delete provider | `delete_provider.sh` | No |
| Test connectivity | `test_connectivity.sh` | Yes (explicit) |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

The troubleshooting section explicitly recommends using --skip-test when tests fail but the provider 'works,' encouraging override of failed security or correctness checks. This can mask genuine authentication, endpoint, TLS, or routing problems and lead to unsafe provider activation.

Content

Scanner excerpt · SKILL.md (reported line 311)May include surrounding context.

Test Fails But Provider Works

If you want to switch despite test failure, use --skip-test flag:

bash
~/.Codex/skills/cc-switch/scripts/switch_provider.sh --app Codex --name Provider --skip-test

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
89% confidence
Finding

This repeated example again instructs use of --skip-test immediately after a failed connectivity check, reinforcing bypass of the skill's safeguard. The repetition makes the unsafe path more likely to be copied into scripts or habitual usage.

Content

Scanner excerpt · SKILL.md (reported line 313)May include surrounding context.

If you want to switch despite test failure, use --skip-test flag:

bash
~/.Codex/skills/cc-switch/scripts/switch_provider.sh --app Codex --name Provider --skip-test

Architecture Notes

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/common.sh (reported line 418)May include surrounding context.

sh
fi
}

# Merge only Claude Code's endpoint into ~/.claude/settings.json.
# This intentionally preserves the rest of the file and does not
# mutate cc-switch's provider state.
update_claude_settings_endpoint() {

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/common.sh (reported line 441)May include surrounding context.

sh
if [ -f "$settings_path" ] && [ -s "$settings_path" ]; then
        if ! jq --arg base_url "$base_url" \
            '.env = (.env // {}) | .env.ANTHROPIC_BASE_URL = $base_url' \
            "$settings_path" > "$temp_file"; then
            rm -f "$temp_file"
            echo "Error: Failed to merge endpoint into $settings_path" >&2

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · scripts/switch_provider.sh (reported line 31)May include surrounding context.

sh
provider_id="$2"
                shift 2
                ;;
        --skip-test)
                skip_test="true"
                shift
                ;;

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/common.sh (reported line 423)May include surrounding context.

sh
echo "✅ Applied Claude endpoint from provider: $provider_name"
    echo "Provider ID: $provider_id"
    echo "Updated: $HOME/.claude/settings.json -> .env.ANTHROPIC_BASE_URL"
    echo "ℹ️  cc-switch provider state was not changed."
else
    # Perform the switch for non-Claude apps.

Agent Config Directory Access

High
Category
Agent Snooping
Confidence
90% confidence
Finding

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

Content

Scanner excerpt · scripts/switch_provider.sh (reported line 182)May include surrounding context.

sh
echo "✅ Applied Claude endpoint from provider: $provider_name"
    echo "Provider ID: $provider_id"
    echo "Updated: $HOME/.claude/settings.json -> .env.ANTHROPIC_BASE_URL"
    echo "ℹ️  cc-switch provider state was not changed."
else
    # Perform the switch for non-Claude apps.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation shows API keys being stored directly in JSON configuration files and examples include plaintext 'api_key' fields, but it gives no warning about credential sensitivity, file permissions, backups, or secret-handling practices. This creates a realistic risk of credential leakage through local file exposure, source-control commits, logs, or shared environments.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README encourages very broad natural-language triggers like 'List providers' or 'Add a new provider' without describing any confirmation or scoping requirements. In an agentic environment, overly generic phrases can cause the skill to activate on ordinary conversation and perform provider-management actions unexpectedly, especially if the surrounding system auto-routes commands to shell scripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to provide API keys and later shows that provider data is stored in local JSON, but it does not warn that secrets may be persisted in plaintext in local files. This increases the risk of credential disclosure through weak filesystem permissions, backups, logs, screenshots, or accidental commits.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README encourages triggering the skill with very generic natural-language phrases such as '列出 provider' or '切换到 MiniMax' without clearly constraining scope, confirmation, or target environment. In an agent setting, broad invocation patterns can cause accidental activation or unintended provider changes when similar phrases appear in ordinary conversation.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 172)May include surrounding context.

md
Error Details:
HTTP Status: 401
API Endpoint: https://api.test.com/v1
Model: test-model

Response:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs users to manually copy active provider API keys and base URLs into other CLI tools, but provides no guidance on secure handling, storage, redaction, or avoiding shell history/log exposure. Because these are high-value secrets, omission of credential-handling safeguards can lead to accidental disclosure or persistence in insecure config files.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 292)May include surrounding context.

--name "My Provider"
--app Codex
--key "sk-xxxx"
--url "https://api.example.com/v1"

text

3. Test before switching:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 340)May include surrounding context.

--name "My Provider"
--app Codex
--key "sk-xxxx"
--url "https://api.example.com/v1"

text

3. Test before switching:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README_zh.md (reported line 293)May include surrounding context.

--name "My Provider"
--app Codex
--key "sk-xxxx"
--url "https://api.example.com/v1"

text

3. Test before switching:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README_zh.md (reported line 341)May include surrounding context.

--name "My Provider"
--app Codex
--key "sk-xxxx"
--url "https://api.example.com/v1"

text

3. Test before switching:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 248)May include surrounding context.

--name "My Provider"
--app Codex
--key "sk-xxxx"
--url "https://api.example.com/v1"

text

3. Test before switching:

Static analysis

No suspicious patterns detected.