T09 · Insecure Skill Coding Practices
- Location
README.md:43- Finding
Credential file is created without enforcing restrictive permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Tailscale skill is coherent for tailnet administration, but it includes powerful destructive and credential-management actions without enough built-in safeguards or warnings.
Install only if you intend to let the agent administer your Tailscale tailnet, not just inspect status. Use a narrowly scoped, short-lived API key where possible, protect the credential file with restrictive permissions, verify device/key IDs manually before deletion, and treat Funnel commands as public internet exposure.
README.md:43Credential file is created without enforcing restrictive permissions
scripts/ts-api.sh:25Tailscale API key is passed through a curl command-line argument
The declared description frames the skill as routine Tailscale management, but the documented behavior includes more sensitive actions such as device authorization/deletion, DNS changes, ACL access, and tag management. This mismatch can mislead users or orchestration layers into invoking a skill with broader authority than expected, enabling unintended tailnet-wide changes.
A user-controlled identifier is interpolated directly into a destructive API path for device deletion after permissive resolution logic that may return arbitrary input unchanged. Even if shell injection is mitigated by quoting, this still enables parameter abuse: an attacker or ambiguous prompt can cause deletion of unintended devices or misuse privileged API actions.
cmd_delete() {
local id
id=$(resolve_device "$1")
api DELETE "/device/${id}"
echo '{"status": "ok", "device": "'"$id"'", "deleted": true}'
}
The key deletion endpoint uses a directly supplied key ID with no validation, confirmation, or policy restriction, enabling privileged destructive operations from untrusted or ambiguous input. In an agent setting, this creates a realistic path for prompt-driven misuse that can revoke active credentials and break automation.
cmd_delete_key() {
local id="$1"
api DELETE "/tailnet/${TS_TAILNET}/keys/${id}"
echo '{"status": "ok", "key": "'"$id"'", "deleted": true}'
}
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
**API (tailnet-wide):**
- **Devices** — list all devices, authorize/delete, set tags
- **Auth keys** — create reusable/ephemeral keys for new devices
- **DNS** — manage nameservers, toggle MagicDNS
- **ACLs** — view and validate access control policies
The README explicitly recommends tailscale funnel for exposing a local service publicly, but it does not warn that this makes the service internet-accessible rather than tailnet-only. In an agent skill context, that omission is dangerous because users may treat it like a routine network-management action and unintentionally publish an internal service without understanding the exposure.
The README includes authorization and deletion commands for devices without warning that these are privileged administrative operations and that deletion may disrupt connectivity or require reprovisioning. In a skill that may be invoked by an agent, missing safety guidance increases the chance of accidental destructive actions against a tailnet.
The skill documents extensive shell-based capabilities but does not declare any explicit tool scope or permissions boundary. In an agent environment, this increases the chance the agent can invoke shell commands more broadly than intended, including sensitive network-management operations, without clear policy gating or user-consent controls.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
---
name: tailscale
version: 1.0.0
description: Manage Tailscale tailnet via CLI and API. Use when the user asks to "check tailscale status", "list tailscale devices", "ping a device", "send file via tailscale", "tailscale funnel", "create auth key", "check who's online", or mentions Tailscale network management.
---
# Tailscale Skill
The skill recommends tailscale funnel to expose a local service publicly but provides no warning that this publishes the service to the internet. Users may believe they are only sharing within the private tailnet and inadvertently expose internal development or administrative services to unauthenticated external access.
The documented device deletion command is destructive and can remove managed nodes from the tailnet, potentially causing service disruption or loss of access. Presenting it without an explicit warning or confirmation step increases the risk of accidental administrative damage.
Auth key creation is a sensitive credential-management operation; reusable keys in particular can enable persistent enrollment of new devices into the tailnet if mishandled. Documenting this without warnings about secrecy, scope, expiry, tagging, and reuse risk increases the likelihood of credential leakage or over-privileged device onboarding.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
set -euo pipefail
CONFIG_FILE="${TS_CONFIG:-$HOME/.clawdbot/credentials/tailscale/config.json}"
API_BASE="https://api.tailscale.com/api/v2"
# Load config
if [[ -f "$CONFIG_FILE" ]]; then
The script exposes administrative actions well beyond passive status and device inspection, including device authorization/deletion, tag changes, key creation/deletion, DNS changes, and ACL operations. In an agent skill context, this violates least privilege and increases the chance that ambiguous or manipulated prompts can trigger high-impact state changes in the user's tailnet.
ACL retrieval and validation are not clearly required by the stated purpose centered on status, devices, pinging, file send, funnel, and basic network management. Access to ACL policy can disclose sensitive network authorization logic, and validation endpoints broaden the skill's authority surface without strong justification.
The device deletion command performs an irreversible administrative action immediately after resolving a user-supplied identifier, with no confirmation, dry-run, or warning. In an agent environment, accidental phrasing, prompt injection, or mistaken identity resolution could remove the wrong device from the tailnet.
The auth key deletion command immediately deletes the specified key without any confirmation or safety interlock. This can disrupt provisioning workflows or revoke critical automation credentials if the wrong key is targeted by a user or by an agent acting on ambiguous instructions.
No suspicious patterns detected.