Back to skill

Security audit

LearningX CLI

Security checks for vulnerabilities and agentic risk

Overview

The skill is not clearly malicious, but it runs an unverified local Go CLI for LMS operations, which needs review before installation.

Install only if you trust the exact lx-agent repository path and revision that LX_AGENT_ROOT or the working directory will point to. Prefer a pinned, reviewed binary or a locked, administrator-managed repository, and avoid running bot or serve modes until their network behavior and credential handling are documented.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run-lx-agent-cli.sh:4
Finding

Untrusted External Repository Code Execution Through Configurable Root Path

Content
View full analysis

Vulnerability Details

File Location: scripts/run-lx-agent-cli.sh:4-21
Vulnerability Type: Execution of unverified external repository code
Risk Level: High

Vulnerable Code

bash
ROOT_DIR="${LX_AGENT_ROOT:-$(pwd)}"

if [[ $# -lt 1 ]]; then
  echo "Usage: run-lx-agent-cli.sh <command> [args...]" >&2
  echo "Example: run-lx-agent-cli.sh config" >&2
  exit 2
fi

if [[ ! -f "$ROOT_DIR/go.mod" || ! -d "$ROOT_DIR/cmd/lx-agent" ]]; then
  echo "LX_AGENT_ROOT does not look like an lx-agent repo: $ROOT_DIR" >&2
  exit 1
fi

cmd="$1"
shift || true

cd "$ROOT_DIR"
go run ./cmd/lx-agent "$cmd" "$@"

Technical Analysis

The bridge accepts an arbitrary directory through LX_AGENT_ROOT, falling back to the current working directory. It validates only that the selected directory contains a go.mod file and a cmd/lx-agent directory. These name-based checks do not establish the repository's identity, ownership, integrity, or trusted revision.

The subsequent go run ./cmd/lx-agent command compiles and executes code from that unverified directory with the bridge process's privileges. A malicious repository can therefore execute arbitrary Go program logic. Depending on the module configuration and local Go environment, go run can also resolve and download dependencies specified by an attacker-controlled go.mod, introducing an additional supply-chain and network-execution surface.

This audit cannot verify the intended lx-agent implementation because its source code is not included in the project. Consequently, the CLI's authentication handling, configuration output, network destinations, and bot or serve behavior remain outside the audited trust boundary.

Attack Path

  1. An attacker gains control over the LX_AGENT_ROOT environment variable, the process's working directory, or a directory expected to contain the lx-agent repository.
  2. The attacker creates a go.mod file an ...[truncated 1329 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace the caller-controlled repository root with a fixed, canonical path managed by the Skill or administrator.
  2. If configurability is necessary, canonicalize the path and enforce an allowlist of approved repository locations.
  3. Verify repository provenance and integrity before execution, such as by checking a pinned commit and cryptographic artifact digest.
  4. Reject repositories or executable source trees writable by untrusted users.
  5. Build the reviewed CLI ahead of time and invoke a pinned binary instead of using go run at runtime.
  6. Use vendored or checksum-locked dependencies and disable unexpected network dependency resolution during execution.
  7. Run the CLI with a restricted service account, minimal filesystem permissions, a sanitized environment, and constrained network access.
  8. Ensure diagnostic commands never print token values, particularly because SKILL.md requires invoking the config command during verification.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description is specific to operating SNU's Canvas LMS and includes behavioral constraints around validating the configured Canvas URL and not handling API tokens via chat. The supplied code chunk does something much narrower: it checks that the current directory looks like an lx-agent Go repo and then forwards a command to a Go CLI entrypoint. As provided, this chunk neither accesses Canvas nor enforces the described safety/domain checks. While it may be a launcher for a larger tool that eventually performs those tasks, this code chunk itself does not substantiate the declared purpose and is materially more generic than described.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
When the CLI returns 401 or token-related errors:

1. Run `skills/learningx-cli/scripts/run-lx-agent-cli.sh config` to confirm which token/URL is configured.
2. Tell the user: "Canvas API 토큰이 만료되었거나 유효하지 않습니다. LMS 웹사이트의 Settings → New Access Token에서 새 토큰을 발급한 뒤, 서버의 config.yaml 파일에서 canvas.token 값을 직접 업데이트해주세요."
3. **Do NOT** ask them to send the token in chat.
4. **Do NOT** attempt to curl the API yourself to "test" the token.
5. After the user confirms they updated the config, re-run the CLI command to verify.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: snu-canvas-cli
description: Operate SNU's Canvas LMS (etl.snu.ac.kr) through CLI commands. Use when you need to inspect config, list courses/assignments/files/announcements, run bot/serve modes, or troubleshoot Canvas API issues. Never guess or substitute LMS domains; validate the configured Canvas URL first. Never ask users to send API tokens via chat.
---

# SNU Canvas CLI

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Lines L08-L12 and L42/L78 explicitly say to operate exclusively through the CLI bridge and never call Canvas endpoints directly with curl or any HTTP client. However, the required verification flow at L49-L53 instructs running curl -I against the Canvas host, which contradicts the earlier prohibition on direct HTTP usage.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 13)May include surrounding context.

md
## Critical Rules

1. **CLI-only access** — Always use the bridge script below. Never curl/fetch Canvas API endpoints directly. The CLI handles authentication, XSRF tokens, and error handling internally.
2. **Never ask for tokens in chat** — Tokens are secrets. Never ask the user to paste or send API tokens via Telegram, Slack, or any chat. Instead, guide them to update `config.yaml` or set `CANVAS_TOKEN` env var on the server.
3. **Never expose token values** — Do not print, log, or display token values (even partially masked) in responses.
4. **Follow verification flow** — Always run `config` command first before diagnosing issues.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prescribed response text is written in Korean and is presented as the required message to tell the user during 401/token errors. Because the file does not state that the skill is Korean-only or offer a language choice, this creates a language/locale policy concern.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest presents the skill as "LearningX CLI" while the metadata says it operates SNU's Canvas LMS, creating a mismatch in identity and target system. This can mislead users or downstream agents into invoking the wrong tool or trusting actions against an unintended platform, which is especially risky for LMS administration workflows involving credentials, course data, and network validation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The default prompt instructs use of an "lx-agent Telegram/LearningX CLI" even though the stated skill purpose is Canvas LMS inspection and operation. Introducing Telegram capability without justification expands the attack surface and may route sensitive LMS operations, metadata, or credentials through an unrelated channel or toolchain, increasing the chance of data leakage or unauthorized actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes invocation scope in very broad terms such as 'when you need to inspect config... or troubleshoot Canvas API issues,' which could overlap with many ordinary support requests. It does not provide explicit trigger phrases, narrow activation conditions, or negative examples to clarify when the skill should not be used.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.