Back to skill

Security audit

Vite Plugin Development

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Vite plugin development skill with one risky example that should be used carefully but no active harmful behavior.

Before using the config injection pattern, only pass explicitly public values into Vite define or virtual modules. Do not include tokens, passwords, private endpoints, or server-only environment values in config that will be bundled for browser use.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/plugin-patterns.md:100
Finding

Unrestricted Configuration Object Exposed in Client Bundle

Content
View full analysis
): Plugin { return { name: 'vite-plugin-config', config() { return { define: { __APP_CONFIG__: JSON.stringify(userConfig), }, } }, } } ``` ### Technical Analysis The documented plugin pattern accepts an unrestricted configuration object and serializes the entire object into Vite's `define` configuration. Vite statically substitutes this value into generated client-side code, making all included properties available in the browser bundle. The example does not enforce a schema, allowlist public properties, reject secret-like fields, or warn users that values supplied through this mechanism are public. If a developer passes a mixed configuration object containing API tokens, credentials, private service endpoints, or other server-only settings, those values will be embedded in downloadable JavaScript. Serialization with `JSON.stringify` prevents direct JavaScript syntax injection in this example, but it does not provide confidentiality or remove sensitive properties. ### Attack Path 1. A developer implements the documented `configPlugin` pattern. 2. The developer passes a configuration object containing both public settings and sensitive server-side values. 3. The plugin serializes the complete object through `JSON.stringify(userConfig)`. 4. Vite substitutes the serialized value into application code under `__APP_CONFIG__`. 5. The generated bundle is served to application users. 6. An unauthenticated attacker downloads or inspects the JavaScript bundle and extracts the embedded values. 7. If an exposed value is an active credential, the attacker may use it against the corresponding service with the per ...[truncated 664 chars]
Remediation
View remediation
` with a narrowly defined type containing only explicitly public fields. - Construct a new client configuration object from an allowlist rather than serializing the caller-provided object directly. - Reject keys associated with secrets, such as `token`, `secret`, `password`, `privateKey`, and server-only credentials. - Clearly document that every value passed to Vite's `define` option is embedded in client code and must be treated as public. - Keep credentials and private environment variables exclusively in server-side code. - Add tests that build the plugin and scan generated artifacts for known secret fixtures. - If this pattern has already been used with sensitive values, remove affected bundles, revoke and rotate exposed credentials, and review access logs for unauthorized use. A safer pattern is: ```ts interface PublicAppConfig { apiBaseUrl: string featureFlags: Record } export default function configPlugin(config: PublicAppConfig): Plugin { const publicConfig: PublicAppConfig = { apiBaseUrl: config.apiBaseUrl, featureFlags: config.featureFlags, } return { name: 'vite-plugin-config', config() { return { define: { __APP_CONFIG__: JSON.stringify(publicConfig), }, } }, } } ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes a pattern explicitly described as exposing env/config to client code and demonstrates serializing userConfig into client-side constants. The description does not warn readers that sensitive values or secrets should be excluded, which is a privacy and system-integrity concern under the markdown-file warning criteria.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.