Back to skill

Security audit

Moss Platform Quick Auth

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small, disclosed quick-auth helper that handles sensitive login credentials, so users should verify the host and avoid exposing raw tokens in chat.

Install only if you intend to use Moss quick auth. Check that the host is correct before running it, and prefer redacted output for access_token, refresh_token, api_key, and temp_password unless you truly need the raw values in the chat transcript.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The output contract explicitly allows returning raw credentials on request and references disclosure of a one-time temp_password. Exposing access tokens, refresh tokens, api_key, or one-time passwords in assistant responses materially increases the risk of credential leakage through chat logs, screenshots, client telemetry, or prompt injection-driven exfiltration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructions are written in Chinese and the metadata explicitly says 'B-only Quick Auth' without offering any language choice. Under the policy rules, forcing a specific language or locale without user opt-in is a natural-language policy violation unless the constraint is documented and justified as region-specific, which is not stated here.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

1) 先尝试 api-login

bash
curl -sS -X POST "https://<host>/studio-api/v1/auth/quick/api-login" \
  -H 'Content-Type: application/json' \
  --data '{"email":"<email>"}'

Static analysis

No suspicious patterns detected.