Back to skill

Security audit

Encryption

Security checks for vulnerabilities and agentic risk

Overview

This encryption guidance skill is coherent, but it includes copyable high-impact infrastructure scripts with weak safety framing, so users should review it before use.

Install only if you want encryption and infrastructure security examples and are prepared to review commands before running them. Treat the shell snippets as templates, not production-ready automation: validate inputs, confirm ownership of cloud destinations, add rollback and failure handling for secret rotation, protect generated evidence files, and update placeholder or expired certificate-pinning values.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
infra.md:141
Finding

Unvalidated Domain Input Permits Command-Line Option Injection

Content
View full analysis
/dev/null | openssl x509 -noout -dates -subject -issuer # Check headers echo "=== Security Headers ===" curl -sI https://$DOMAIN | grep -iE "strict-transport|content-security|x-frame" ``` ### Technical Analysis The script assigns its first positional argument to `DOMAIN` and expands it without quoting or validation in commands executed by `nmap`, `openssl`, and `curl`. Unquoted shell expansion performs word splitting. Consequently, a value containing whitespace can become multiple command-line arguments. Downstream utilities may interpret the additional arguments as options rather than as part of the intended hostname. In particular, `curl` accepts options interspersed with URLs, while `nmap` also exposes options that materially alter scan behavior and output handling. Shell metacharacters embedded inside the variable are not reparsed as shell syntax during ordinary parameter expansion, so this is not direct arbitrary shell-command injection by itself. It is nevertheless command-line option injection that can expose unintended functionality of the invoked tools. ### Attack Path 1. An attacker gains the ability to supply the domain argument to the documented audit script, directly or through an automation system. 2. The attacker submits a crafted value containing whitespace and additional utility-specific options. 3. The shell splits the unquoted expansion into multiple arguments. 4. `nmap`, `openssl`, or `curl` interprets attacker-controlled arguments as command options or additional targets. 5. Depending on the utility and avai ...[truncated 856 chars]
Remediation
View remediation
&2 exit 2 fi echo "=== Protocols ===" nmap --script ssl-enum-ciphers -p 443 -- "$DOMAIN" | grep -E "TLSv|SSLv" echo "=== Certificate ===" echo | openssl s_client -servername "$DOMAIN" -connect "${DOMAIN}:443" 2>/dev/null | openssl x509 -noout -dates -subject -issuer echo "=== Security Headers ===" curl --silent --show-error --head -- "https://${DOMAIN}" | grep -iE "strict-transport|content-security|x-frame" ``` Additional hardening measures should include: - Decide explicitly whether IP addresses, IPv6 literals, ports, or internationalized domain names are supported and validate them with dedicated parsers. - Run network-audit scripts under a minimally privileged service account. - Apply network egress restrictions to prevent access to sensitive internal or metadata endpoints. - Add tests using values containing whitespace, leading hyphens, newlines, and utility-specific options. - Avoid composing host-and-port values from untrusted strings unless each component has been independently validated. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
mobile.md:149
Finding

Expired Android Certificate Pinning Configuration Disables Intended Pin Enforcement

Content
View full analysis
``` The complete affected pin-set example is: ```xml AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA= BBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB= ``` ### Technical Analysis The Android Network Security Configuration example sets the pin-set expiration to `2025-01-01`, which is already in the past. Android does not enforce an expired pin set. An application copying this example may therefore appear to implement certificate pinning while relying only on the normal platform certificate trust process. Pin expiration is designed to prevent an application from permanently losing connectivity when operators can no longer update its pins. However, an already-expired date makes the documented control ineffective from initial deployment. The placeholder pin values also require replacement with valid deployment-specific SPKI hashes before the example can be used safely. ### Attack Path 1. A developer copies the provided Android network security configuration. 2. The developer replaces the example domain and potentially the placeholder pins but fails to update the expiration date. 3. The application is built and deployed after `2025-01-01`. 4. Android treats the pin set as expired and does not enforce the listed pins. 5. An attacker capable of intercepting network traffic presents a certificate that is accepted by the device's ordinary trust store. 6. The connection succeeds despite not matching the application’s intended certificate pins. Exploitation still requires the attacker to obtain or present a certificate trusted by the device, such as through a compromised or improperly trusted certificate auth ...[truncated 698 chars]
Remediation
View remediation
PRODUCTION_SPKI_SHA256_PIN BACKUP_SPKI_SHA256_PIN ``` The hardening plan should also include: - Documenting that the sample date and pin values must never be copied unchanged. - Establishing a pin and certificate rotation procedure before deployment. - Monitoring the pin expiration date and alerting well before it is reached. - Adding CI checks that reject expired or near-expiry pin sets. - Testing both the primary and backup pins before release. - Coordinating pin lifetime with application update support and certificate rotation schedules. - Evaluating whether pinning is operationally appropriate, since incorrect pin management can cause application-wide loss of connectivity. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mobile.md (reported line 8)May include surrounding context.

swift
import Security

class KeychainHelper {
    static func save(key: String, data: Data) -> Bool {
        let query: [String: Any] = [
            kSecClass as String: kSecClassGenericPassword,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mobile.md (reported line 62)May include surrounding context.

swift
import Security

class KeychainHelper {
    static func save(key: String, data: Data) -> Bool {
        let query: [String: Any] = [
            kSecClass as String: kSecClassGenericPassword,

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · mobile.md (reported line 89)May include surrounding context.

swift
import Security

class KeychainHelper {
    static func save(key: String, data: Data) -> Bool {
        let query: [String: Any] = [
            kSecClass as String: kSecClassGenericPassword,

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest describes encryption-focused capabilities like encrypting files, securing passwords, managing keys, and auditing code for cryptographic best practices. While encrypting the backup is in scope, pushing artifacts to S3 introduces a storage/network operation that is not clearly justified by that stated purpose and goes beyond cryptographic handling itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The example transmits database backups to external cloud storage without any explicit warning about data movement, trust boundaries, retention, or bucket access controls. Even though the file is encrypted first, users may copy this pattern into environments where bucket policies, logging, residency, or key-handling requirements make the transfer risky or non-compliant.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · infra.md (reported line 130)May include surrounding context.

fi

Upload to cold storage

aws s3 cp backup-$DATE.sql.age s3://backups-encrypted/

text

### Verify backup is actually encrypted

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This script changes a production database password, updates Vault, and restarts application pods without any explicit safety warning, rollback guidance, or operator confirmation. A user running it as-is could cause outages, lockouts, or partial secret desynchronization if any step fails, especially because the script assumes successful sequencing and uses a fixed sleep before invalidation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

Managing or rotating secrets is within the manifest's scope, but restarting application pods is an operational deployment action rather than a cryptographic or key-management function. This broadens the skill into service orchestration capabilities that are not declared in the description.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

Auditing code for cryptographic best practices can justify static or configuration-focused review, but this script performs live host probing with nmap and curl against remote services. That is a wider operational security scanning capability not clearly implied by the manifest's wording.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest mentions encryption and cryptographic best-practice auditing, but this script assembles broader compliance evidence from database settings, block devices, and secret metadata. That is a more general compliance automation capability than the stated encryption-focused purpose alone supports.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The compliance report writes potentially sensitive infrastructure and Vault metadata into a local markdown file without warning about data exposure, storage location, or access controls. Such evidence files can leak system configuration details or secret-version metadata if stored in shared directories, committed to source control, or attached to tickets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.