Back to skill

Security audit

boc deploy

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent deployment purpose, but it handles root SSH passwords and long-running infrastructure changes without enough safeguards.

Review before installing. Use a dedicated least-privilege deployment account if supported, avoid reusable root passwords, protect any generated config with mode 600, keep it out of logs and support bundles, remove local and remote copies after deployment, rotate exposed credentials, and plan rollback/cancellation before running the background install.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:19
Finding

Plaintext SSH Credentials Stored in Deployment Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 19 and 61–78
Vulnerability Type: Plaintext sensitive-data storage
Risk Level: High

Vulnerable code snippets:

markdown
| ssh_password | SSH密码 | 是 | Password |
markdown
根据输入参数生成 `config.yaml`,包含:
- 节点配置(IP、端口、用户、密码、角色)
- VIP配置
- NFS配置
- 容器运行时配置
- Kubernetes版本
- 数据库配置
- 网络配置(calico ipip/bgp)
- BOC Portal组件配置
markdown
### 3. 上传配置文件到部署机

将生成的 config.yaml 上传到部署机的 `/root/config.yaml`

Technical Analysis

The workflow requires an SSH password, embeds node passwords in a generated config.yaml, and uploads that file to the persistent path /root/config.yaml. It does not require restrictive file permissions, secret redaction, an authenticated encrypted transfer mechanism, ephemeral storage, or deletion after deployment.

Consequently, a reusable infrastructure credential may remain in plaintext on both the system generating the configuration and the deployment server. Backups, diagnostic archives, accidental disclosure, overly broad file permissions, or a privileged local process could expose it. The risk is amplified when the supplied account is root, as shown in the documented examples.

Attack Path

  1. An operator supplies the required SSH username and password to the Skill.
  2. The Skill generates config.yaml with the password included in node configuration.
  3. The generated file is stored locally and uploaded as /root/config.yaml.
  4. The file remains available without a documented permission-hardening or cleanup procedure.
  5. An attacker with access to the host, a backup, a support archive, or another unintended copy reads the plaintext credential.
  6. The attacker uses the credential to authenticate to deployment or cluster nodes.
  7. If the credential belongs to root, the attacker obtains administrative control of affected systems and can compromise the BOC/Kubernetes environment.

...[truncated 483 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace password authentication with SSH public-key authentication, an SSH agent, short-lived certificates, or a managed secrets service.
  2. Do not serialize reusable credentials into config.yaml. Pass secrets through a protected runtime channel or reference secrets by identifier.
  3. If the deployment software strictly requires a password-bearing file:
    • Create it atomically with mode 0600.
    • Store it only in a protected, non-shared location.
    • Transfer it exclusively over an authenticated encrypted protocol.
    • Prevent its contents from appearing in command output, logs, status responses, and exception messages.
    • Securely remove local and remote copies immediately after deployment.
  4. Use a dedicated least-privilege deployment account rather than root wherever the platform supports it.
  5. Rotate any credential that may already have been stored through this workflow.
  6. Document retention, cleanup, redaction, and file-permission requirements directly in the Skill instructions.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs users to generate and upload a config file containing SSH credentials to /root/config.yaml and then run a privileged, infrastructure-wide deployment without any guidance on secret handling, file permissions, cleanup, or rollback. In this context, the omission is dangerous because the deployment targets multiple hosts as root and the plaintext credential file may persist on disk and in operational workflows, increasing the chance of credential disclosure and broad compromise.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

Using nohup to launch the deployment in the background creates a detached long-running privileged process that can continue after the initiating session ends, reducing operator visibility and control. In a deployment skill that runs broad installation actions across infrastructure, this increases the risk of unattended changes, delayed detection of failures, and difficulty stopping or auditing the operation.

Content

Scanner excerpt · SKILL.md (reported line 84)May include surrounding context.

bash
cd /opt/BOC_k8s_noarch
nohup ./bocctl run -a install -c /root/config.yaml > log/bocctl.log 2>&1 &

部署过程约 40-60 分钟。

Static analysis

No suspicious patterns detected.