Back to skill

Security audit

PassManager

Security checks for vulnerabilities and agentic risk

Overview

This local password manager has no evidence of network exfiltration, but it needs review because its advertised access controls are not enforced and its CLI/docs expose high-value secrets.

Review before installing for real credentials. Do not rely on the advertised RBAC, do not pass real master passwords or stored passwords on the command line, restrict ~/.passmanager and backup permissions manually, and avoid restore/delete/team operations until confirmation and authorization checks are added.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/passmanager.py:257
Finding

Declared RBAC Is Not Enforced on Credential and Administrative Operations

Content
View full analysis
bool: """检查用户是否有权限执行某操作""" if not user: return False conn = sqlite3.connect(self.db_path) c = conn.cursor() c.execute("SELECT role FROM team_members WHERE name = ?", (user,)) row = c.fetchone() conn.close() if not row: return False role = row[0] role_perms = { "admin": ["add", "get", "list", "update", "delete", "backup", "restore", "audit", "team_add", "team_remove", "team_list", "status", "init"], "user": ["add", "get", "list", "update"], "auditor": ["get", "list", "audit"], "guest": ["get"], } allowed = role_perms.get(role, []) return required_action in allowed ``` For example, privileged CLI handlers invoke the underlying operations directly, without calling `check_permission()` or authenticating the claimed administrator: ```python def cmd_delete(args): pm = PassManager() ok = pm.delete(args.user, args.type, args.service, args.username) if ok: print(f"✅ 凭证已删除: {args.type}/{args.service}/{args.username}") else: print("❌ 删除失败。凭证不存在。") ``` ```python def cmd_restore(args): pm = PassManager() if pm.restore(args.input): print(f"✅ 恢复成功: {args.input}") else: print("❌ 恢复失败。检查备份文件是否存在。") ``` ```python def cmd_team_add(args): pm = PassManager() if pm.team_add(args.admin, args.name, args.role): print(f"✅ 团队成员添加成功: {args.name} ({args.role})") else: print("❌ 添加失败。用户可能已存在。") ``` ### Technical Analysis The RBA ...[truncated 2602 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/passmanager.py:829
Finding

Master Passwords and Stored Credentials Are Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/passmanager.py:75
Finding

Sensitive Database, Audit, and Backup Files Do Not Receive Consistently Restrictive Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (18)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code defines a role-based permission model in check_permission(), but privileged operations such as add/get/list/update/delete, backup/restore, audit access, and team management never call it. Any local caller who can invoke the CLI or import the class can perform administrative actions by supplying arbitrary usernames, making the documented access-control model ineffective and enabling unauthorized credential access, modification, deletion, team changes, and backup/restore.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The restore function copies the supplied backup over the live database and may also replace the master key file, which is a destructive and potentially irreversible operation. The code logs the action after completion, but there is no user-facing warning or confirmation before the overwrite happens.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation instructs users to supply the master password and credential passwords directly on the command line, which commonly exposes secrets through shell history, process listings, terminal logging, and audit tooling. In a password-management skill, this is especially dangerous because it trains users to leak the very high-value secrets the tool is meant to protect.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The overview describes PassManager as a local encrypted password manager using AES-256-GCM, which conveys a strong security property. However, the changelog states that v1.0.0 was the initial release and used only 'base64 obfuscation — deprecated,' creating a direct contradiction within the document about what this version actually does.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation presents destructive commands like delete, update-assistant, and delete-assistant without warning, confirmation, or recovery guidance. In an agent skill context, this increases the chance an assistant or operator will execute irreversible changes to credential stores or access control state, causing data loss or privilege disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Restore and export operations are highly sensitive because restore can overwrite a live credential database and export can create portable copies of secrets. Omitting overwrite warnings, destination handling guidance, and secure export instructions can lead to accidental data destruction or exposure of credential material.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Bulk import and update operations can modify many credentials at once, amplifying the blast radius of mistakes or malformed inputs. In a password-management skill, undocumented safeguards for batch changes materially increase the risk of mass corruption, unintended rotation, or service outages.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · docs/passmanager_skill.md (reported line 281)May include surrounding context.

python3 scripts/test_passmanager.py

4. Configure auto backup (cron)

crontab -e

Add: 0 2 * * * /usr/bin/python3 /path/to/passmanager/scripts/backup.py

text

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · docs/passmanager_skill.md (reported line 341)May include surrounding context.

Q1: Database connection failed

bash
# Check file permissions
ls -la ~/.passmanager/

# Fix permissions
chmod 600 ~/.passmanager/passwords.db

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · docs/passmanager_skill.md (reported line 368)May include surrounding context.

Q1: Database connection failed

bash
# Check file permissions
ls -la ~/.passmanager/

# Fix permissions
chmod 600 ~/.passmanager/passwords.db

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · docs/passmanager_skill.md (reported line 344)May include surrounding context.

md
ls -la ~/.passmanager/

# Fix permissions
chmod 600 ~/.passmanager/passwords.db

# Re-initialize
python3 scripts/passmanager.py init --force

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The training manual teaches sensitive operations such as password retrieval, export, restore, and deletion, but does not consistently warn trainees about disclosure risk, irreversible actions, or the need for confirmation and authorization before performing them. In a password-management context, normalizing these actions without explicit caution can increase the chance of accidental secret exposure, unsafe backup handling, or destructive mistakes by operators.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Natural-language descriptions and all user-facing messages are hard-coded in Chinese, with no option to select another language or locale. This can violate language/locale policy when users have not opted into Chinese output.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The class documentation claims all sensitive fields are encrypted with AES-256-GCM, but notes are stored in the notes column as plaintext and returned directly in list/get operations. Users may place recovery codes, secret answers, or operational secrets in notes based on that claim, causing unintended plaintext disclosure through database access, backups, logs, or listings.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The delete method performs irreversible credential deletion and the CLI wrapper immediately executes it, but there is no confirmation prompt before the destructive action. Although success/failure is printed afterward, that does not warn the user before data loss occurs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The statement says 'Zero Hardcoded Passwords' and that this 'eliminate[s] security risks entirely,' but the rest of the document clearly describes a password manager that stores and manages sensitive password values. This is not merely incomplete wording; it overstates and conflicts with the documented existence of managed credentials and ongoing security controls like auditing and access control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

SQP-3 applies to all file types and covers language or locale policy violations. The entire training manual is presented in Chinese and targets all OpenClaw assistants, but it does not indicate that language selection is optional or that the Chinese-only requirement is justified by a region-specific need.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file’s docstring, argparse description/help text, and success/failure messages are all presented only in Chinese. This imposes a specific language on all users without offering an alternative or documenting that the skill is intentionally locale-specific.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.