Back to skill

Security audit

cos-vectors-skill

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Tencent Cloud COS vector-management tool, but it handles cloud credentials and destructive cloud operations with unsafe defaults and weak safeguards.

Review carefully before installing. Use only least-privilege Tencent Cloud credentials, prefer secure environment/secret injection over command-line secrets, force HTTPS for every call, and manually confirm any delete or bucket-policy operation before letting an agent run it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/common.py:35
Finding

Sensitive COS API Traffic Uses Plaintext HTTP by Default

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/common.py:15
Finding

Cloud Credentials Can Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:39
Finding

Unpinned Runtime Dependency Installation Creates Supply-Chain Risk

Content
View full analysis
Remediation
View remediation
``` 2. Maintain a lockfile that pins all transitive dependencies. 3. Use hash verification, such as pip's `--require-hashes`, with reviewed distribution hashes. 4. Install only from an explicitly trusted package index over HTTPS. 5. Remove `--upgrade` and `--force-reinstall` from routine execution instructions. 6. Review dependency updates before changing version pins and use automated vulnerability and provenance checks. 7. Install dependencies in an isolated virtual environment under a non-privileged account. 8. Consider distributing a reproducible requirements file rather than instructing users to resolve mutable dependencies at runtime. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (28)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill documents HTTP as the default transport while also supporting direct credential submission, which can expose credentials, vector data, and management operations to interception or tampering in transit. In a cloud administration skill, insecure-by-default transport is especially dangerous because it affects every operation, including authentication and destructive requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README includes command-line examples that pass SecretId and SecretKey directly as arguments, which can expose secrets through shell history, process listings, CI logs, and terminal recording. Although environment variables are also shown, the documentation does not warn that CLI arguments are less safe, so users may inadvertently leak cloud credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README documents destructive operations such as deleting vector buckets, indexes, and vectors, but it does not clearly warn that these actions may be irreversible or require prior backup/confirmation. In a CodeBuddy skill context, natural-language triggering increases the chance of accidental destructive execution by users or agents, making missing safety guidance materially risky.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding

The skill declares environment-variable requirements and clearly relies on file/script execution patterns, but it does not define an explicit tool scope such as allowed-tools or permissions. That omission weakens least-privilege boundaries and makes it harder for a host agent to constrain secret access and file reads during execution.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation repeatedly instructs users to pass Tencent Cloud SecretId and SecretKey directly on the command line. Command-line secrets are commonly exposed through shell history, process listings, logs, and agent transcripts, so this creates an unnecessary credential disclosure path for highly privileged cloud API keys.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asks users to provide sensitive cloud API credentials without any warning about their sensitivity or secure handling requirements. In an agent setting, that omission materially increases the likelihood that users will paste secrets into prompts, transcripts, or unsafe storage locations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation exposes destructive operations such as deleting buckets, policies, indexes, and vectors without warning about irreversible effects or recommending confirmation safeguards. In a high-impact cloud storage context, this can lead to accidental data loss, service disruption, or policy removal that weakens security posture.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The client defaults to plain HTTP for API communication, which can expose Tencent Cloud credentials and request data to interception or modification via man-in-the-middle attacks. In this skill’s context, the code handles SecretId and SecretKey for managing vector buckets, indexes, and data, so insecure transport directly risks account compromise and unauthorized access to stored vectors.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This file contains natural-language strings for the docstring and CLI help that force a specific language for all users. Under the policy, language-specific behavior should either offer user opt-in/choice or be clearly justified as region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstring presents the script purpose and usage exclusively in Chinese, which imposes a specific language on users without any opt-in or alternative. The policy for this audit flags language or locale restrictions when they are forced and not justified as region-specific.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This code performs a deletion operation by calling client.delete_index(...), which is a destructive action affecting user data or system state. The script provides no confirmation prompt, warning print/log, or inline notice near the operation, so a user may invoke it without sufficient disclosure of the irreversible effect.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This script performs an irreversible destructive operation against a cloud resource immediately after argument parsing, with no interactive confirmation, dry-run mode, or secondary safety check visible in the file. In the context of a vector-bucket management skill, accidental invocation, parameter mix-ups, or automation misuse could delete production data and service configuration, causing data loss and operational disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code performs a deletion operation against a vector index via client.delete_vectors, which is safety-relevant because it may remove user data irreversibly. While the script has a usage docstring and prints success afterward, there is no pre-action confirmation prompt or explicit warning about the destructive nature of the operation in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

All user-facing natural-language strings in the docstring and argument help are in Chinese, with no indication that the tool is intended only for a Chinese-speaking or region-specific audience and no option to choose another language. This can violate a language/locale policy when a skill imposes a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This code performs a network operation that sends user-supplied vector payloads and metadata to Tencent Cloud via client.put_vectors(...). Although the script purpose implies an upload, there is no visible runtime disclosure, confirmation, or warning in the code or docstring that the provided data will be transmitted to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The README is entirely written in Chinese and the invocation examples are presented only in Chinese, with no note about supported languages or user choice. Under the language/locale policy, forcing a specific language without opt-in can be a natural-language policy concern unless it is explicitly justified as region-specific.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill claims to support a credential-checking flow but normalizes insecure direct secret entry in the same section, undermining safe operator behavior. This mixed guidance increases the chance that users and agents will choose the least secure path and leak cloud credentials during routine use.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

该文件全文以中文呈现,包括标题、参数说明和注意事项,但没有说明这是面向特定中文用户群体的区域化文档,也没有提供其他语言选项。按照自然语言策略检查,这属于强制单一语言展示而缺少用户选择或明确范围说明的情况。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

Docstrings, argument help text, and error messages are all written in Chinese, which imposes a specific language on users. The file does not provide an opt-in, fallback language, or any justification that this skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The docstring and argument descriptions force a specific language for user-facing instructions, which can violate language or locale policy when no opt-in or justification is provided. There is no indication that this skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The docstring and CLI description use Chinese-only text (删除腾讯云 COS 向量桶) with no indication that the language is optional or region-specific. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The file's user-facing natural language documentation and argument help strings are entirely in Chinese, with no indication that language choice is optional or that the skill is intentionally limited to a Chinese-speaking context. This can violate language/locale policy when a specific language is imposed without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file’s user-facing natural-language strings, including the module docstring and argument/help text, are presented only in Chinese. Under the policy, forcing a specific language without user opt-in can be a natural-language policy violation when no locale choice or justification is provided.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This code performs a remote API call to COS and may return vector contents and metadata, then emits the response data, but there is no confirmation prompt, warning print, or comment/docstring explaining that potentially sensitive remote data will be retrieved and displayed. For a code file, network operations that transmit or expose user/system data should include some form of visible disclosure unless clearly warned elsewhere.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains user-facing natural-language strings in Chinese for the description and argument help text. Under the policy, forcing a specific language without user choice can be a locale/language policy violation when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.