Back to skill

Security audit

Coala Client

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-style skill for using the coala-client CLI; its higher-risk features are disclosed and user-initiated, though users should treat remote imports, shell execution, and plaintext API-key files carefully.

Install only if you trust the coala-client package source. Review remote CWL, ZIP, and skill sources before importing them, be cautious with sandboxed shell commands, and protect any API keys stored in ~/.config/coala/env with restrictive file permissions or a secret manager.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:5
Finding

Unpinned Executable Package Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:18
Finding

Plaintext API Credential Storage Guidance Without Permission Hardening

Content
View full analysis
/` — per-toolset dirs with `run_mcp.py` and CWL files - Skills: `~/.config/coala/skills/` (one subfolder per imported source) - Env: `~/.config/coala/env` (optional; key=value for providers and MCP env) ``` ```markdown ## Providers and env Set provider via `-p` or env `PROVIDER`. Set keys and URLs per provider (e.g. `OPENAI_API_KEY`, `GEMINI_API_KEY`, `OLLAMA_BASE_URL`). Optional: put vars in `~/.config/coala/env`. `coala config` — print current config paths and provider/model info. ``` ### Technical Analysis The Skill explicitly recommends storing provider variables, including API keys, in `~/.config/coala/env`. This is a plaintext `key=value` file, but the instructions do not require restrictive file permissions, verify ownership, warn against accidental inclusion in backups or repositories, or recommend use of an operating-system credential store. Plaintext credential files are not inherently exploitable when ownership and permissions are correctly enforced. However, absent permission hardening, credentials may become readable by other local users, exposed through overly broad backup or diagnostic collection, or accidentally copied into source-control repositories. ### Attack Path 1. A user follows the documented guidance and writes an API key such as `OPENAI_API_KEY` or `GEMINI_API_KEY` to `~/.config/coala/env`. 2. The file is created with permissions that permit unintended local access, or it is copied into a backup, support archive, or repository without secret filtering. 3. An unauthorized party reads the plaintext credential. 4. The party uses the key against the corresponding provider API until it is revoked, ex ...[truncated 673 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · SKILL.md (reported line 66)May include surrounding context.

md
## Chat commands

- `/help`, `/exit`, `/quit`, `/clear`  
- `/tools` — list MCP tools  
- `/servers` — list connected MCP servers  
- `/skill` — list skills; `/skill <name>` — load a skill  
- `/model` — show model info

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The description advertises an optional sandbox for running shell commands but does not warn that command execution is inherently risky even when sandboxed. Users may infer this is routine and safe, when in practice shell execution can still affect local files, consume resources, or expose data depending on sandbox configuration.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs users to import CWL toolsets and skills from local or remote ZIP/HTTP(S) sources without any warning that doing so changes local configuration and can introduce executable MCP integrations. In this context, imported toolsets create server definitions and per-toolset runtime files, so a user may trust unvetted remote content and unintentionally add code-capable integrations to future sessions.

Content

No source excerpt is available for this finding.