Back to skill

Security audit

LinkSKILL

Security checks for vulnerabilities and agentic risk

Overview

The skill is a plausible API integration helper, but it handles reusable credentials unsafely and can attach them to arbitrary HTTP requests.

Install only after reviewing and preferably fixing credential handling. Use non-production credentials, avoid --url with a configured authenticated platform, avoid --show-cache, rotate any token printed in logs, and restrict use to trusted endpoints until destination allowlisting, redaction, file-permission hardening, and destructive-request confirmation are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/http_request_tool.py:36
Finding

Cached platform credentials can be forwarded to an arbitrary URL

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth_manager.py:98
Finding

Authentication secrets and login responses are exposed through standard output

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/auth_manager.py:35
Finding

Reusable credentials are stored in a plaintext cache without enforced restrictive permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The documented capability extends beyond API discovery into arbitrary HTTP request execution, auth-header injection, and automatic subprocess-based re-authentication. That is materially broader than a simple OpenAPI discovery tool and can lead to state-changing operations against remote systems, especially when paired with POST/PUT/PATCH/DELETE support and automatic credential reuse.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented capability extends beyond API discovery into arbitrary HTTP request execution, auth-header injection, and automatic subprocess-based re-authentication. That is materially broader than a simple OpenAPI discovery tool and can lead to state-changing operations against remote systems, especially when paired with POST/PUT/PATCH/DELETE support and automatic credential reuse.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

When a cached token is reused, the script prints the full token to stdout. Because tokens are bearer secrets, anyone who obtains the output can often reuse them directly to authenticate to the target platform until expiry.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The --show-cache code path dumps the entire cached credential structure to stdout with no warning or redaction. This creates a straightforward secret exfiltration channel through terminal output, job logs, and audit pipelines.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill advertises and documents shell, network, file read, and file write behaviors but does not declare any explicit tool scope or permission boundaries. In a skill that performs authentication, token caching, and arbitrary API requests, missing scope declarations increases the chance of unintended access, misuse of local files, or execution beyond what a user expects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The invocation description is extremely broad ('universal' integration for 'any platform'), which encourages over-trust and use in sensitive contexts without clear boundaries. In security terms, overly broad positioning can cause operators to supply credentials, endpoints, and payloads to a tool whose limits and safety assumptions are not explicitly defined.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill supports authenticated network requests and destructive HTTP methods but provides no prominent user-facing warning about transmitting data off-host, reusing cached credentials, or modifying remote systems. In this context, lack of warning is especially risky because the tool is designed to work against arbitrary internal or external platforms, making accidental data exposure or unintended state changes more likely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/auth_manager.py (reported line 88)May include surrounding context.

python
print(f"[LOGIN] {url}")
    try:
        resp = requests.post(url, json=body, headers={"Content-Type": "application/json"}, timeout=TIMEOUT)
    except requests.RequestException as e:
        sys.exit(f"[ERROR] Login request failed: {e}")

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This script exposes bearer tokens and cached authentication material directly to stdout through both the normal cache-hit path and the --show-cache option. In enterprise automation environments, stdout is often captured by shells, CI/CD logs, agent traces, or centralized logging, so printing secrets can lead to credential disclosure and downstream account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script stores authentication tokens in a local JSON cache file without warning the user and without any visible protection such as restrictive file permissions or encryption. On multi-user systems or shared workspaces, this can expose reusable credentials to other local users, backup systems, or support tooling.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The help text suggests a benign cache-inspection feature, but the implementation prints the full token cache, including active authentication tokens. This mismatch increases the risk of accidental disclosure because users may invoke the option without realizing it will reveal reusable credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This tool automatically loads cached bearer-style tokens and sends them to either a configured gateway endpoint or any directly supplied --url without enforcing an allowlist or warning the user. In a universal API integration skill, that increases the risk of credential and data exfiltration if a user is induced to target an attacker-controlled host or an untrusted endpoint.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/http_request_tool.py (reported line 99)May include surrounding context.

python
if platform_id:
        cmd.extend(["--platform", platform_id])
    print("[AUTO] Triggering re-authentication...")
    subprocess.run(cmd)
    return True

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/http_request_tool.py (reported line 73)May include surrounding context.

python
if params:
        kwargs["params"] = params if isinstance(params, dict) else json.loads(params)

    resp = getattr(requests, method.lower())(url, **kwargs)

    print(f"[{method}] {url}")
    print(f"Status: {resp.status_code}")

Static analysis

No suspicious patterns detected.