Back to skill

Security audit

skills-monitor

Security checks for vulnerabilities and agentic risk

Overview

This monitoring skill is broadly coherent, but it needs Review because it handles agent credentials and reports with insecure public-server defaults, weak API authorization, default telemetry behavior, and an under-disclosed hardcoded WeCom webhook.

Install only after reviewing and hardening the server configuration: remove or replace the hardcoded WeCom webhook, require authentication on overview/dashboard routes, fix agent registration so existing tokens cannot be overwritten unauthenticated, disable debug mode, set a random secret, bind locally or put the service behind HTTPS, require HTTPS for remote uploads, and make realtime telemetry opt-in with consent checks.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (6)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
server/services/report_service.py:29
Finding

Unauthenticated Agent Token Replacement Enables Account Takeover

Content
View full analysis
Agent: """ 注册新 Agent 或更新已有 Agent """ token_hash = hashlib.sha256(token.encode("utf-8")).hexdigest() agent = Agent.query.filter_by(agent_id=agent_id).first() if agent: # 更新 agent.token_hash = token_hash agent.updated_at = datetime.utcnow() else: # 新建 agent = Agent( agent_id=agent_id, token_hash=token_hash, ) db.session.add(agent) for key in ("name", "os_info", "python_version", "monitor_version", "total_skills", "runnable_skills"): if key in kwargs and kwargs[key] is not None: setattr(agent, key, kwargs[key]) db.session.commit() return agent ``` ### Technical Analysis The registration endpoint is unauthenticated and treats registration of an existing `agent_id` as an update. When the identifier a ...[truncated 1549 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
server/api/overview_api.py:308
Finding

Unauthenticated Overview API Discloses Fleet and Agent Inventory

Content
View full analysis
dict: end_date = date.today() start_date = end_date - timedelta(days=days - 1) all_agents = Agent.query.order_by(Agent.last_report_at.desc().nullslast()).all() total_agents = len(all_agents) ``` ```python agents_summary.append({ "agent_id": agent.agent_id, "name": agent.name or f"Agent-{agent.agent_id[:8]}", "health_score": round(health, 1) if health else None, "total_skills": agent.total_skills or 0, "runnable_skills": agent.runnable_skills or 0, "total_runs": overview.get("total_runs", latest.total_runs if latest else 0), "success_rate": overview.get("success_rate", latest.success_rate if latest else 0), "active_skills": overview.get("active_skills", latest.active_skills if latest else 0), "avg_duration_ms": overview.get("avg_duration_ms", 0), "os_info": agent.os_info or "未知", "python_version": agent.python_version or "", "monitor_version": agent.monitor_version or "", "report_count": report_count, "recent_reports_7d": recent_reports, "last_report_at": agent.last_report_at.strftime("%Y-%m-%d %H:%M") if agent.last_report_at else "未上报", "created_at": agent.created_at.strftime("%Y-%m-%d") if agent.created_at else "", "status": status, "status_label": status_label, }) ``` ```python @overview_bp.route("/overview") def overview_page(): days = min(int(request.args.get("days", "30")), 90) data = _collect_overview_data(days) return render_template("overview.html", data=data) @overview_bp.route("/api/overview/data") def overview_data(): days = min(int(request.args.get("days", "30")), 90) data = _collect_overview_dat ...[truncated 1880 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
skills_monitor/core/interceptor.py:23
Finding

Realtime Telemetry Is Enabled Without Enforcing User Consent

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
server/config.py:14
Finding

Public Debug Mode and Predictable Flask Session Secret Are Enabled by Default

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
skills_monitor/core/uploader.py:24
Finding

Agent Credentials and Monitoring Reports May Be Transmitted Over Plain HTTP

Content
View full analysis
Dict[str, str]: return { "X-Agent-ID": self._agent_id or "", "X-Agent-Token": self._token or "", "Content-Type": "application/json", } ``` Registration sends the reusable token in the request body: ```python resp = requests.post( f"{self.server_url}/api/agent/register", json=payload, timeout=15, ) ``` Report uploads send it in request headers: ```python resp = requests.post( f"{self.server_url}/api/agent/report", headers=self._headers, json=payload, timeout=30, ) ``` ### Technical Analysis The uploader accepts arbitrary server URLs but does not validate the scheme or restrict plain HTTP to loopback addresses. The reusable Agent token is transmitted in registration JSON and later in the `X-Agent-Token` header. Plain HTTP is reasonable for a strictly local loopback service, but the CLI also allows operators to configure another server URL. If a remote HTTP endpoint is used, network intermediaries can observe or modify both credentials and report content. The code also does not explicitly constrain redirects, so an initially trusted endpoint could potentially redirect a request to another destination through the HTTP client's normal redirect behavior. ### Attack Path 1. A user configures a remote server with an `http://` URL, whether accidentally or throug ...[truncated 713 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
requirements.txt:4
Finding

Unbounded and Non-Integrity-Pinned Dependencies Create Supply-Chain Risk

Content
View full analysis
=2.3.0 flask-sqlalchemy>=3.0.0 requests>=2.28.0 pandas>=1.5.0 apscheduler>=3.10.0 python-dotenv>=1.0.0 keyring>=25.0.0 ``` ### Technical Analysis All dependencies use open-ended minimum-version constraints. There are no upper bounds, exact tested versions, lockfile entries, or package hashes. As a result, a future installation can resolve to substantially different versions from those reviewed during this audit. Future major releases may introduce incompatible behavior, altered security defaults, or newly compromised transitive dependencies. This finding does not establish that any listed package is currently malicious. It identifies an avoidable supply-chain weakness in dependency resolution and build reproducibility. ### Attack Path 1. A future package or transitive dependency release satisfies one of the open-ended `>=` constraints. 2. An operator installs or redeploys the project. 3. The package manager retrieves the new version automatically. 4. Installation hooks or imported package code execute in the deployment environment. 5. If the release is compromised or unexpectedly incompatible, it can execute attacker-controlled behavior or weaken application security. ### Impact Assessment Potential impact depends on the privileges used for installation and runtime. It may include: - Arbitrary code execution during installation or import. - Access to application configuration and environment variables. - Access to server data and Agent reports. - Compromise of deployment hosts when packages are installed with elevated privileges. - Non-reproducible builds and difficult incident investigation. ]]>
Remediation
View remediation
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (376)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

WeCom integration with bot/app credentials, callback tokens/AES keys, inbound messaging, and ngrok exposure adds credential-management and public-callback attack surface that is much broader than basic local monitoring. If users are not clearly warned, they may expose a Flask service or configure sensitive tokens without understanding the network-facing implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.