Back to skill

Security audit

国内Minimax Coding Plan订阅计划用量查询

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does the Minimax usage check it claims, but its helper script unsafely reads and executes a parent .env file instead of the documented local config file.

Review this before installing or running. The Minimax API call itself is disclosed and purpose-aligned, but the script should be fixed to read only the intended local config file without using shell source, or to take MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID from the existing environment. Do not run it in a directory where a parent .env file may contain unrelated secrets or shell commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
minimax-coding-plan-usage.sh:6
Finding

Arbitrary Shell Execution Through Unsafe Parent Environment File Sourcing

Content
View full analysis

Vulnerability Details

File Location: minimax-coding-plan-usage.sh, line 6
Vulnerability Type: Unsafe execution of configuration content
Risk Level: Medium

Vulnerable Code:

bash
source "$(dirname "$0")/../../.env"

Technical Analysis

The script uses Bash source to load an .env file located two directories above the script. source does not safely parse configuration as data; it executes the entire file as shell code in the current process. Consequently, command substitutions, shell functions, redirections, and arbitrary commands placed in that file run with the privileges of the user invoking the Skill.

The path also conflicts with SKILL.md, which tells users to create .env in the same directory as the script. Traversing two parent directories unnecessarily expands the trust boundary to workspace-level configuration and exceeds the access required to obtain only MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID.

Attack Path

  1. An attacker or compromised local process obtains write access to the .env file located two directories above the script.
  2. The attacker inserts a shell command into that file, such as a command that copies readable credentials or modifies user-owned files.
  3. A user invokes minimax-coding-plan-usage.sh.
  4. At line 6, Bash sources the attacker-controlled file before making the MiniMax API request.
  5. The injected commands execute under the invoking user's identity and inherit the script's environment and accessible resources.

This path requires the attacker to influence the referenced parent .env; the reviewed project does not itself create or modify that file.

Impact Assessment

Successful exploitation permits arbitrary command execution with the invoking user's existing privileges. The attacker could read or modify files accessible to that user, access environment variables and credentials, initiate network requests, or alter user-level confi ...[truncated 448 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not use source, ., or eval to process an .env file.
  • Resolve configuration from the documented location beside the script rather than traversing parent directories.
  • Parse the file as data with a non-executing parser and strictly allowlist only MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID.
  • Reject malformed variable names, duplicate entries, shell metacharacters, command substitutions, and unexpected keys.
  • Verify that the configuration is a regular file, is not an unsafe symbolic link, and is not writable by untrusted users.
  • Require restrictive permissions, such as owner read/write only, because the file contains an API credential.
  • Prefer receiving the two values from an already-established process environment or a dedicated secrets manager.
  • Update SKILL.md so its setup instructions and invocation example exactly match the implemented file location and script name.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · minimax-coding-plan-usage.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
# Minimax Coding Plan Usage Check
# Usage: ./minimax-usage.sh
# Requires: MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID in .env

source "$(dirname "$0")/../../.env"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · minimax-coding-plan-usage.sh (reported line 6)May include surrounding context.

sh
# Usage: ./minimax-usage.sh
# Requires: MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID in .env

source "$(dirname "$0")/../../.env"

API_KEY="${MINIMAX_CODING_API_KEY}"
GROUP_ID="${MINIMAX_GROUP_ID}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · minimax-coding-plan-usage.sh (reported line 12)May include surrounding context.

sh
# Usage: ./minimax-usage.sh
# Requires: MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID in .env

source "$(dirname "$0")/../../.env"

API_KEY="${MINIMAX_CODING_API_KEY}"
GROUP_ID="${MINIMAX_GROUP_ID}"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs users to run a shell script and handle API credentials, but it does not declare any explicit tool scope or allowed-tools permissions. This creates an authorization gap where shell-capable behavior may be invoked without clear sandboxing or user-visible constraints, increasing the chance of unintended command execution or unsafe handling of secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.