Back to skill

Security audit

volcengine-tos-vectors-skills

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent TOS Vectors helper, but it enables cloud data deletion, IAM policy changes, credential-backed network use, and unpinned package installation without enough scoping or warnings.

Install only in an isolated environment, pin and verify the `tos` SDK version, use least-privileged TOS credentials, and require explicit confirmation before deletes or policy changes. Treat retrieved vector metadata as untrusted before sending it to any LLM, especially if the index may contain private or third-party content.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
README.md:78
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
WORKFLOWS.md:181
Finding

Indirect Prompt Injection Through Untrusted Retrieved Vector Metadata

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown explicitly advertises deletion capabilities for vector buckets and vectors, including batch delete, but does not include any caution about irreversible data removal or the need to confirm targets before use. Under the markdown-file criteria, descriptions that omit warnings about behaviors affecting user data should be flagged.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file documents bucket deletion through delete_vector_bucket but only states the technical prerequisite that the bucket be empty. It does not warn users that the operation is destructive and may permanently remove storage resources and associated configuration, which is the kind of system-impacting behavior that should be disclosed in markdown skill documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The delete_index section instructs users how to delete a vector index but does not disclose the destructive impact of removing the index and its contents. For markdown documentation, destructive operations affecting user data should include a clear warning so users understand the risk before invoking them.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The delete_vectors section explains how to delete vectors by key but provides no user-facing warning about permanent data removal. Because this behavior directly affects stored user data, the markdown should explicitly disclose the destructive nature of the operation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill reads sensitive credentials from environment variables and demonstrates network-capable client initialization, but it does not declare any explicit tool scope or permissions boundary. In an agent setting, this can cause the skill to be invoked with access to secrets or execution capabilities that are broader than intended, reducing auditability and increasing the chance of unauthorized external actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description says to use the skill for broad categories like embeddings, semantic search, RAG systems, recommendation engines, or whenever the user mentions vector databases or similarity search. This wide trigger surface can cause the agent to select the skill for many generic AI/ML tasks, unnecessarily exposing credentials and enabling write/delete operations in contexts where the user may only want conceptual guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The bucket deletion example shows a destructive operation with no warning, confirmation step, or emphasis that the bucket must be empty and that deletion is irreversible. In an agent-assisted workflow, examples often become copied actions, so this increases the risk of accidental data loss or service disruption.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill includes code to delete vectors by key without any accompanying warning about irreversibility, verification of the target set, or recovery guidance. Because this skill manages production-like data stores, normalizing deletion in examples can lead to unintended removal of indexed content and degraded downstream search or RAG behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The RAG example sends both the user's question and retrieved document context to an external LLM service, which can expose sensitive or proprietary data if the indexed content contains private information. In a vector-search/RAG skill this is contextually plausible and common, but the lack of any warning, data-classification guidance, or redaction step increases the risk of inadvertent data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The update workflow deletes existing vectors before inserting replacements, creating a destructive window where data may be permanently lost if the subsequent insert fails or is incomplete. In a data-maintenance skill this behavior is functionally relevant, but without warnings, backup guidance, or safer upsert/transactional patterns it can cause integrity and availability issues.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The module documentation presents this as a TOS Vectors search script, which implies searching with a meaningful embedding derived from the query. However, the implementation uses generate_dummy_embedding based on an MD5 hash repeated across all dimensions, which is only a demonstration placeholder and does not perform real semantic embedding generation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.