Back to skill

Security audit

Tailscale

Security checks for vulnerabilities and agentic risk

Overview

This Tailscale skill is coherent for tailnet administration, but it includes powerful destructive and credential-management actions without enough built-in safeguards or warnings.

Install only if you intend to let the agent administer your Tailscale tailnet, not just inspect status. Use a narrowly scoped, short-lived API key where possible, protect the credential file with restrictive permissions, verify device/key IDs manually before deletion, and treat Funnel commands as public internet exposure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
README.md:43
Finding

Credential file is created without enforcing restrictive permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/ts-api.sh:25
Finding

Tailscale API key is passed through a curl command-line argument

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description frames the skill as routine Tailscale management, but the documented behavior includes more sensitive actions such as device authorization/deletion, DNS changes, ACL access, and tag management. This mismatch can mislead users or orchestration layers into invoking a skill with broader authority than expected, enabling unintended tailnet-wide changes.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

A user-controlled identifier is interpolated directly into a destructive API path for device deletion after permissive resolution logic that may return arbitrary input unchanged. Even if shell injection is mitigated by quoting, this still enables parameter abuse: an attacker or ambiguous prompt can cause deletion of unintended devices or misuse privileged API actions.

Content

Scanner excerpt · scripts/ts-api.sh (reported line 155)May include surrounding context.

sh
cmd_delete() {
    local id
    id=$(resolve_device "$1")
    api DELETE "/device/${id}"
    echo '{"status": "ok", "device": "'"$id"'", "deleted": true}'
}

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

The key deletion endpoint uses a directly supplied key ID with no validation, confirmation, or policy restriction, enabling privileged destructive operations from untrusted or ambiguous input. In an agent setting, this creates a realistic path for prompt-driven misuse that can revoke active credentials and break automation.

Content

Scanner excerpt · scripts/ts-api.sh (reported line 238)May include surrounding context.

sh
cmd_delete_key() {
    local id="$1"
    api DELETE "/tailnet/${TS_TAILNET}/keys/${id}"
    echo '{"status": "ok", "key": "'"$id"'", "deleted": true}'
}

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 16)May include surrounding context.

md
**API (tailnet-wide):**
- **Devices** — list all devices, authorize/delete, set tags
- **Auth keys** — create reusable/ephemeral keys for new devices
- **DNS** — manage nameservers, toggle MagicDNS
- **ACLs** — view and validate access control policies

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly recommends tailscale funnel for exposing a local service publicly, but it does not warn that this makes the service internet-accessible rather than tailnet-only. In an agent skill context, that omission is dangerous because users may treat it like a routine network-management action and unintentionally publish an internal service without understanding the exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The README includes authorization and deletion commands for devices without warning that these are privileged administrative operations and that deletion may disrupt connectivity or require reprovisioning. In a skill that may be invoked by an agent, missing safety guidance increases the chance of accidental destructive actions against a tailnet.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents extensive shell-based capabilities but does not declare any explicit tool scope or permissions boundary. In an agent environment, this increases the chance the agent can invoke shell commands more broadly than intended, including sensitive network-management operations, without clear policy gating or user-consent controls.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 4)May include surrounding context.

md
---
name: tailscale
version: 1.0.0
description: Manage Tailscale tailnet via CLI and API. Use when the user asks to "check tailscale status", "list tailscale devices", "ping a device", "send file via tailscale", "tailscale funnel", "create auth key", "check who's online", or mentions Tailscale network management.
---

# Tailscale Skill

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill recommends tailscale funnel to expose a local service publicly but provides no warning that this publishes the service to the internet. Users may believe they are only sharing within the private tailnet and inadvertently expose internal development or administrative services to unauthenticated external access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented device deletion command is destructive and can remove managed nodes from the tailnet, potentially causing service disruption or loss of access. Presenting it without an explicit warning or confirmation step increases the risk of accidental administrative damage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Auth key creation is a sensitive credential-management operation; reusable keys in particular can enable persistent enrollment of new devices into the tailnet if mishandled. Documenting this without warnings about secrecy, scope, expiry, tagging, and reuse risk increases the likelihood of credential leakage or over-privileged device onboarding.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ts-api.sh (reported line 8)May include surrounding context.

sh
set -euo pipefail

CONFIG_FILE="${TS_CONFIG:-$HOME/.clawdbot/credentials/tailscale/config.json}"
API_BASE="https://api.tailscale.com/api/v2"

# Load config
if [[ -f "$CONFIG_FILE" ]]; then

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script exposes administrative actions well beyond passive status and device inspection, including device authorization/deletion, tag changes, key creation/deletion, DNS changes, and ACL operations. In an agent skill context, this violates least privilege and increases the chance that ambiguous or manipulated prompts can trigger high-impact state changes in the user's tailnet.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

ACL retrieval and validation are not clearly required by the stated purpose centered on status, devices, pinging, file send, funnel, and basic network management. Access to ACL policy can disclose sensitive network authorization logic, and validation endpoints broaden the skill's authority surface without strong justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The device deletion command performs an irreversible administrative action immediately after resolving a user-supplied identifier, with no confirmation, dry-run, or warning. In an agent environment, accidental phrasing, prompt injection, or mistaken identity resolution could remove the wrong device from the tailnet.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auth key deletion command immediately deletes the specified key without any confirmation or safety interlock. This can disrupt provisioning workflows or revoke critical automation credentials if the wrong key is targeted by a user or by an agent acting on ambiguous instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.