Back to skill

Security audit

CDN

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent CDN guidance, but it includes copy-ready production-impacting purge and firewall commands without enough safety scoping or rollback guidance.

Review this skill carefully before installing. It is documentation-only and does not run code by itself, but users should not copy its full purge or firewall examples into production without validating provider IDs, current CDN IP ranges, origin capacity, staging behavior, monitoring, and rollback steps.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
security.md:35
Finding

Incomplete CDN Firewall Allowlist Can Cause Origin Denial of Service

Content
View full analysis

Vulnerability Details

File Location: security.md, lines 35–38
Vulnerability Type: Incomplete and unsafe firewall configuration
Risk Level: High

bash
# Only allow CDN IPs (example for Cloudflare)
# Get current IPs: https://www.cloudflare.com/ips/
iptables -A INPUT -p tcp --dport 443 -s 103.21.244.0/22 -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -j DROP

Technical Analysis

The executable example permits HTTPS traffic from only one Cloudflare IPv4 network and then unconditionally drops all other inbound TCP traffic to port 443. Cloudflare operates multiple IPv4 and IPv6 network ranges, so this configuration is not a complete provider allowlist.

The commands also append rules without validating the existing firewall policy, rule order, required monitoring sources, administrative access paths, or a rollback mechanism. Consequently, the effective behavior may vary by host and can immediately disrupt legitimate traffic.

Attack Path

  1. An operator copies the documented commands to an origin server.
  2. The firewall permits port 443 only for 103.21.244.0/22.
  3. The unconditional DROP rule rejects requests from every other source.
  4. Legitimate CDN edge nodes using other Cloudflare IPv4 or IPv6 ranges cannot reach the origin.
  5. Requests routed through those edge nodes fail, producing regional or widespread service disruption.
  6. If legitimate traffic is repeatedly forced through excluded CDN ranges, the incomplete rule set can amplify the availability impact.

Impact Assessment

This issue does not grant an attacker additional system privileges or direct data access. Its primary impact is availability: it can cause partial or complete origin denial of service, regional delivery failures, failed health checks, monitoring loss, and operational lockout from services using port 443.

The scope includes the origin host on which the commands are applied and every CDN-served application dep ...[truncated 22 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not publish a single provider network as a complete allowlist.
  • Retrieve the provider's authoritative current IPv4 and IPv6 ranges and validate the response before generating firewall rules.
  • Build the complete replacement policy in a dedicated chain, then activate it atomically to avoid partially applied rules.
  • Preserve explicitly required access for health checks, monitoring, management systems, and emergency recovery.
  • Verify rule ordering and the host's default policies before applying changes.
  • Test the policy in a staging environment and confirm connectivity through multiple CDN regions.
  • Configure an automatic rollback or out-of-band recovery mechanism before enforcement.
  • Regularly synchronize the allowlist because CDN address ranges can change.
  • Where possible, use authenticated origin pulls in addition to network allowlisting.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (9)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · caching.md (reported line 90)May include surrounding context.

Surrogate-Key: product-123 category-shoes homepage

Purge by tag

curl -X POST "cdn.api/purge" -d '{"tags":["product-123"]}'

text
- Purge all content with specific tag
- More precise than path-based purging

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation includes a full Cloudflare cache purge example using purge_everything:true without any warning that it invalidates all cached content for a zone. In an operational skill, this can prompt users to run a broad destructive action in production, causing traffic spikes to origin, degraded performance, and accidental service disruption.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · providers.md (reported line 18)May include surrounding context.

Cloudflare

bash
# Purge cache
curl -X POST "https://api.cloudflare.com/client/v4/zones/{zone_id}/purge_cache" \
  -H "Authorization: Bearer $CF_TOKEN" \
  -d '{"purge_everything":true}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · providers.md (reported line 18)May include surrounding context.

Cloudflare

bash
# Purge cache
curl -X POST "https://api.cloudflare.com/client/v4/zones/{zone_id}/purge_cache" \
  -H "Authorization: Bearer $CF_TOKEN" \
  -d '{"purge_everything":true}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · providers.md (reported line 23)May include surrounding context.

Cloudflare

bash
# Purge cache
curl -X POST "https://api.cloudflare.com/client/v4/zones/{zone_id}/purge_cache" \
  -H "Authorization: Bearer $CF_TOKEN" \
  -d '{"purge_everything":true}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · providers.md (reported line 44)May include surrounding context.

Bunny CDN

bash
# Purge URL
curl -X POST "https://api.bunny.net/purge?url=https://example.com/image.jpg" \
  -H "AccessKey: $BUNNY_API_KEY"

# Purge entire pull zone

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · providers.md (reported line 48)May include surrounding context.

Bunny CDN

bash
# Purge URL
curl -X POST "https://api.bunny.net/purge?url=https://example.com/image.jpg" \
  -H "AccessKey: $BUNNY_API_KEY"

# Purge entire pull zone

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The Bunny CDN example documents a full pull-zone purge command without caution about its broad production impact. Users may copy and execute it directly, triggering unnecessary global cache invalidation and avoidable origin load or outage-like behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file contains operational commands that modify iptables and end with a blanket DROP on port 443. There is no accompanying warning that applying these rules incorrectly could block legitimate traffic or lock administrators out, which is a system-integrity risk for a markdown skill description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.