Back to skill

Security audit

Consul CLI

Security checks for vulnerabilities and agentic risk

Overview

This is a Consul CLI reference skill with no hidden code, but it presents several high-impact Consul administration commands without enough safety scoping or warnings.

Install only if you want a broad Consul CLI reference and will require human review before running any destructive, credential-related, remote-exec, or network-exposing command. Treat ACL SecretIDs, Consul tokens, and keyring values as secrets, avoid exposing Consul on 0.0.0.0 without strong controls, and verify backups, targets, and selectors before restore, delete, watch, or exec operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:44
Finding

Consul API Exposed on All Network Interfaces Without Mandatory Security Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (15)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The consul exec examples show remote command execution across service-selected or node-selected hosts without any warning about fleet-wide command execution risk. In a skill meant to guide command execution, this materially increases the chance of unauthorized or accidental lateral-impact actions such as restarting services or running arbitrary commands on multiple nodes.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The ACL bootstrap and token-management sections expose highly sensitive credential operations, including creation, reading, cloning, and setting agent tokens, but do not warn about secret handling or privilege escalation risks. In an agent skill, this is especially dangerous because examples can lead to disclosure of root or long-lived tokens in logs, terminals, transcripts, or automation outputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

consul snapshot restore can overwrite or roll back cluster state, including service catalog, KV data, and ACL-related state, yet the documentation provides no warning about operational impact. In a skill used by an agent, omission of that warning increases the chance of destructive recovery actions being suggested or executed without understanding the blast radius.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The consul exec examples demonstrate remote command execution across matched nodes without any warning about fleet-wide impact or the risk of targeting unintended hosts via broad selectors. In an agent skill context, this can normalize or encourage dangerous remote execution actions that may lead to service disruption or unauthorized command execution if a user follows examples uncritically.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-reference.md (reported line 886)May include surrounding context.

keyring

text
consul keyring <subcommand> [options]

子命令: list, install, use, remove

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/cli-reference.md (reported line 892)May include surrounding context.

keyring

text
consul keyring <subcommand> [options]

子命令: list, install, use, remove

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The example consul keyring install -key=<new-key> shows direct CLI use of sensitive key material, which risks exposure through shell history, process listings, agent transcripts, and logs. In an agent skill context, this is more dangerous because an automated assistant may reproduce the pattern verbatim and leak key material in observable channels.

Content

Scanner excerpt · references/cli-reference.md (reported line 893)May include surrounding context.

bash
consul keyring list
consul keyring install -key=<new-key>
consul keyring use -key=<key>
consul keyring remove -key=<old-key>

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The example consul keyring use -key=<key> likewise places sensitive key material directly on the command line. This can disclose encryption keys through command history or process inspection and is particularly risky if an agent reuses or echoes the exact syntax in interactive sessions.

Content

Scanner excerpt · references/cli-reference.md (reported line 894)May include surrounding context.

bash
consul keyring list
consul keyring install -key=<new-key>
consul keyring use -key=<key>
consul keyring remove -key=<old-key>

Credential Access

High
Category
Privilege Escalation
Confidence
82% confidence
Finding

The example consul keyring remove -key=<old-key> again normalizes supplying sensitive key material on the command line, creating avoidable exposure of retired but still sensitive keys. Even old keys may remain valid during rotation windows or reveal operational details useful to an attacker.

Content

Scanner excerpt · references/cli-reference.md (reported line 895)May include surrounding context.

consul keyring list consul keyring install -key= consul keyring use -key= consul keyring remove -key=

text

### force-leave

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This SKILL.md includes consul kv delete <key> and recursive deletion with -recurse, which can remove configuration data, but the surrounding text provides no caution about irreversibility or verifying the target prefix first. For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents ACL bootstrap and token operations, including generation of the root token, without any warning that these credentials grant highly sensitive cluster-wide access. In an agent setting, this can lead users or downstream automation to expose, mishandle, or overwrite privileged tokens and compromise the Consul control plane.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

consul snapshot restore is a high-impact state-changing operation that can replace cluster state, reintroduce stale data, or disrupt services, yet the skill presents it as a routine command with no caution. In an agent-assisted workflow, that omission increases the risk of accidental destructive restoration against production environments.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This markdown file includes deletion operations such as consul kv delete and recursive deletion examples, but does not warn that these commands remove stored KV data and may be irreversible. Under the markdown-file criteria, behaviors affecting user data or system integrity should include an explicit warning or caution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The watch examples wire automatic shell handlers to Consul events and state changes without warning that these commands may execute repeatedly and implicitly in response to cluster activity. This creates risk of accidental command execution, unsafe automation, and command-injection style misuse if handlers are later parameterized unsafely by downstream users.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file begins with Chinese-language content and the remainder of the reference is documented in Chinese, with no indication that language choice is optional or region-specific. Per the policy rule, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.