T09 · Insecure Skill Coding Practices
- Location
SKILL.md:44- Finding
Consul API Exposed on All Network Interfaces Without Mandatory Security Controls
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a Consul CLI reference skill with no hidden code, but it presents several high-impact Consul administration commands without enough safety scoping or warnings.
Install only if you want a broad Consul CLI reference and will require human review before running any destructive, credential-related, remote-exec, or network-exposing command. Treat ACL SecretIDs, Consul tokens, and keyring values as secrets, avoid exposing Consul on 0.0.0.0 without strong controls, and verify backups, targets, and selectors before restore, delete, watch, or exec operations.
SKILL.md:44Consul API Exposed on All Network Interfaces Without Mandatory Security Controls
The consul exec examples show remote command execution across service-selected or node-selected hosts without any warning about fleet-wide command execution risk. In a skill meant to guide command execution, this materially increases the chance of unauthorized or accidental lateral-impact actions such as restarting services or running arbitrary commands on multiple nodes.
The ACL bootstrap and token-management sections expose highly sensitive credential operations, including creation, reading, cloning, and setting agent tokens, but do not warn about secret handling or privilege escalation risks. In an agent skill, this is especially dangerous because examples can lead to disclosure of root or long-lived tokens in logs, terminals, transcripts, or automation outputs.
consul snapshot restore can overwrite or roll back cluster state, including service catalog, KV data, and ACL-related state, yet the documentation provides no warning about operational impact. In a skill used by an agent, omission of that warning increases the chance of destructive recovery actions being suggested or executed without understanding the blast radius.
The consul exec examples demonstrate remote command execution across matched nodes without any warning about fleet-wide impact or the risk of targeting unintended hosts via broad selectors. In an agent skill context, this can normalize or encourage dangerous remote execution actions that may lead to service disruption or unauthorized command execution if a user follows examples uncritically.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
consul keyring <subcommand> [options]
子命令: list, install, use, remove
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
consul keyring <subcommand> [options]
子命令: list, install, use, remove
The example consul keyring install -key=<new-key> shows direct CLI use of sensitive key material, which risks exposure through shell history, process listings, agent transcripts, and logs. In an agent skill context, this is more dangerous because an automated assistant may reproduce the pattern verbatim and leak key material in observable channels.
consul keyring list
consul keyring install -key=<new-key>
consul keyring use -key=<key>
consul keyring remove -key=<old-key>
The example consul keyring use -key=<key> likewise places sensitive key material directly on the command line. This can disclose encryption keys through command history or process inspection and is particularly risky if an agent reuses or echoes the exact syntax in interactive sessions.
consul keyring list
consul keyring install -key=<new-key>
consul keyring use -key=<key>
consul keyring remove -key=<old-key>
The example consul keyring remove -key=<old-key> again normalizes supplying sensitive key material on the command line, creating avoidable exposure of retired but still sensitive keys. Even old keys may remain valid during rotation windows or reveal operational details useful to an attacker.
consul keyring list consul keyring install -key= consul keyring use -key= consul keyring remove -key=
### force-leave
This SKILL.md includes consul kv delete <key> and recursive deletion with -recurse, which can remove configuration data, but the surrounding text provides no caution about irreversibility or verifying the target prefix first. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or system integrity.
The skill documents ACL bootstrap and token operations, including generation of the root token, without any warning that these credentials grant highly sensitive cluster-wide access. In an agent setting, this can lead users or downstream automation to expose, mishandle, or overwrite privileged tokens and compromise the Consul control plane.
consul snapshot restore is a high-impact state-changing operation that can replace cluster state, reintroduce stale data, or disrupt services, yet the skill presents it as a routine command with no caution. In an agent-assisted workflow, that omission increases the risk of accidental destructive restoration against production environments.
This markdown file includes deletion operations such as consul kv delete and recursive deletion examples, but does not warn that these commands remove stored KV data and may be irreversible. Under the markdown-file criteria, behaviors affecting user data or system integrity should include an explicit warning or caution.
The watch examples wire automatic shell handlers to Consul events and state changes without warning that these commands may execute repeatedly and implicitly in response to cluster activity. This creates risk of accidental command execution, unsafe automation, and command-injection style misuse if handlers are later parameterized unsafely by downstream users.
The file begins with Chinese-language content and the remainder of the reference is documented in Chinese, with no indication that language choice is optional or region-specific. Per the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.
No suspicious patterns detected.