Back to skill

Security audit

authlock

Security checks for vulnerabilities and agentic risk

Overview

AuthLock is a real secret-vault tool, but it handles high-value secrets with unsafe execution and misleading protection boundaries that deserve manual review before use.

Install only if you are comfortable reviewing and controlling every invocation. Avoid `--exec`, avoid writing decrypted secrets back to sensitive paths, use a tightly scoped vault path, and do not rely on the advertised MFA-bound model as strong protection because the stored config can enable offline decryption if exposed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (6)

T09 · Insecure Skill Coding Practices

Error
Location
authlock_cli.py:107
Finding

Plaintext TOTP Seed Allows Offline Vault Decryption

Content
View full analysis
bytes: """Derive encryption key from TOTP seed""" password = seed.encode() if pin: password = (seed + pin).encode() ``` The initialization logic stores that seed directly: ```python config["totp_seed"] = seed config["created_at"] = datetime.utcnow().isoformat() + "Z" config["level"] = level_name save_config(home, config) ``` ### Technical Analysis The TOTP seed serves two security roles: 1. It is the shared secret used to generate and verify TOTP codes. 2. It is the password material from which vault encryption keys are derived. The seed is stored as plaintext JSON in `config.json`. Neither `save_config()` nor the directory initialization code explicitly enforces restrictive permissions on this file. Consequently, its effective permissions depend on the process umask and pre-existing filesystem state. Possession of the seed is sufficient to reproduce the PBKDF2-derived key for every sealed record. An attacker does not need to invoke `cmd_open()`, satisfy its TOTP check, or wait for a valid TOTP interval. The TOTP verification is only an application-level authorization check and is not cryptographically required for decryption. This undermines the declared “MFA-bound” property. It also creates a single point of compromise because the same long-lived seed protects all records in the selected AuthLock location. ### Attack Path 1. An attacker gains read access to `.authlock/config.json`, such as through permissive file permissions, a wo ...[truncated 1168 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
authlock_cli.py:421
Finding

Shell Command Injection Through the Decrypt-and-Execute Interface

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
authlock_cli.py:330
Finding

Path Traversal Through Unvalidated Secret Names

Content
View full analysis
/sealed/../../target.sealed ``` This affects creation, opening, and deletion. The forced `.sealed ...[truncated 1264 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
authlock_cli.py:510
Finding

PIN Stored as Reversible Base64 and Not Bound to Configuration Enforcement

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
authlock_cli.py:421
Finding

Decrypted Secrets Can Persist in Named Temporary Files

Content
View full analysis
--exec ...` with valid authentication. 2. AuthLock decrypts the secret and writes it to a named temporary file. 3. The process is forcibly terminated after file creation but before the `finally` cleanup completes. 4. The temporary pathname remains on the filesystem. 5. A process with the same account privileges, an administrator, a backup system, or a later forensic reader recovers the plaintext secret. ### Impact Assessment Residual temporary files may expose passwords, certificates, API tokens, or SSH private keys. Ordinary users should be restricted by the file's permissions, but pr ...[truncated 222 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:12
Finding

Security-Critical Dependencies Are Installed Without Version or Integrity Pinning

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (14)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The stated purpose is secret protection, but the skill also enables arbitrary command execution via --exec, broad filesystem/path management, and relies on a locally stored TOTP seed for both encryption and decryption. This mismatch can mislead users and orchestrators about the true risk surface, and the --exec flow can turn decrypted secrets into direct inputs to shell commands, amplifying the blast radius of compromise.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 76)May include surrounding context.

bash
# All commands support --path parameter
authlock seal secret.txt --name my-pass --path /custom/path
authlock open my-pass --code 123456 --path /custom/path
authlock list --path /custom/path

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

bash
# Encrypt file
authlock seal ~/.ssh/id_rsa --name my-server-key

# Encrypt text (from pipe)
echo "super_secret_password" | authlock seal - --name db-password

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The documented open ... --output ~/.ssh/id_rsa and especially --exec "ssh -i - user@host" flows normalize decrypting credentials directly into sensitive locations or piping them into command execution. This is dangerous because it encourages operational patterns where plaintext private keys are reconstructed on disk or fed into shell-driven actions, increasing the risk of leakage, misuse, and command-injection-adjacent abuse if arguments are not rigidly controlled.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
authlock open my-server-key --code 123456

# Decrypt to file
authlock open my-server-key --code 123456 --output ~/.ssh/id_rsa

# Decrypt and execute (SSH example)
authlock open prod-ssh-key --code 123456 --exec "ssh -i - user@host"

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

A secret-protection CLI that can immediately execute decrypted material via --exec materially increases risk: the feature turns secret retrieval into code execution. In this context, decrypted payloads may be scripts, credentials, or attacker-supplied content, so the tool becomes a convenient execution bridge for malicious or unsafe artifacts.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This is a true tool-parameter-abuse issue because the --exec parameter directly influences a shell command that runs after decryption. In a secret-handling tool, such abuse is more dangerous than usual because it combines access to sensitive plaintext with arbitrary command execution, enabling exfiltration, persistence, or destructive actions.

Content

Scanner excerpt · authlock_cli.py (reported line 429)May include surrounding context.

python
try:
            os.chmod(tmp_path, 0o600)
            cmd = args.exec.replace("-", tmp_path)
            subprocess.run(cmd, shell=True)
        finally:
            os.unlink(tmp_path)
    else:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents shell execution, file reads/writes, and environment-variable-based path selection, but it does not declare any tool scope or permissions boundary. This is dangerous because an agent may invoke filesystem and shell capabilities implicitly, increasing the chance of unauthorized secret access, writes, or command execution without explicit review.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases include generic terms related to secrets, passwords, and encryption, which can cause the skill to activate during ordinary discussion rather than an explicit request to use this secret-management tool. Unintended activation is especially risky here because the skill handles sensitive material and may prompt for TOTP codes or perform secret-related operations in the wrong context.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The standalone keyword list is broad and lacks constraints, making accidental invocation more likely across routine discussions involving secrets, certificates, or password storage. In a skill that can access secret material and shell/file capabilities, overbroad activation materially increases exposure and social-engineering risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

Many user-facing prompts, status messages, and help strings are hard-coded in Chinese, while the tool description and command naming are otherwise mixed-language. This imposes a specific language on users without offering a locale selection or documenting that the tool is intended only for a Chinese-speaking environment.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · authlock_cli.py (reported line 274)May include surrounding context.

python
else:
        seed = pyotp.random_base32()
    
    # Create TOTP object
    totp = pyotp.TOTP(seed)
    
    # Generate URI for QR code

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tool decrypts secrets and can execute a command on the resulting temporary file without any warning or confirmation at the moment of execution. In a secret-management context, this is dangerous because users may invoke decryption expecting disclosure only, while the feature can trigger unintended execution of sensitive or malicious content.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
98% confidence
Finding

The tool takes user-controlled input from --exec, substitutes the decrypted temporary file path, and passes the resulting string to subprocess.run(..., shell=True). This enables arbitrary shell execution in the context of handling decrypted secrets, so any injected shell metacharacters or unsafe command composition can execute unintended commands and expose or modify sensitive material.

Content

Scanner excerpt · authlock_cli.py (reported line 429)May include surrounding context.

python
try:
            os.chmod(tmp_path, 0o600)
            cmd = args.exec.replace("-", tmp_path)
            subprocess.run(cmd, shell=True)
        finally:
            os.unlink(tmp_path)
    else:

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The configuration flow stores a value named pin_hash, implying persistent PIN-based protection, but decryption never verifies user input against this stored value. As implemented, any PIN entered at seal/open only changes key derivation ad hoc, while the saved pin_hash provides no access control and may mislead users into believing a PIN policy is enforced when it is not.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:233