Back to skill

Security audit

Autoglm File Upload

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it uploads local files using a local bearer token and a hard-coded signing key without strong scoping or consent controls.

Review before installing. Use this only for files you intend to send to AutoGLM, avoid sensitive documents unless you trust the service and storage behavior, and do not pass returned file URLs to other tools unless you are comfortable with the uploaded content being accessible through that workflow. The publisher should add explicit consent checks, tighter file/path scoping, and remove or rotate the embedded signing key.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
upload-mix.py:14
Finding

Hard-Coded Application Signing Credential Enables Request Forgery

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
"filename": "SKILL.md",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill performs network operations, including token retrieval from a local HTTP service and file upload to an external API, but does not declare any tool scope or permission boundary. This increases the risk that an agent or user invokes network-capable behavior without clear review of what data leaves the host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description says it uploads local files but does not prominently warn that local file contents are transmitted to an external service. Users may provide sensitive documents or images without understanding that the full contents will leave the local environment and be stored remotely.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation frames the upload result as a reusable file URL/resource for downstream APIs, which can expose the contents of local files through a remotely hosted link. If the URL is accessible beyond the original session or shared with other tools, sensitive local data may be disclosed more broadly than intended.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## Token Retrieval

When the script starts, it automatically sends an HTTP GET request to the local service to retrieve a token:

| Item | Value |
|------|------|

Ssd 3

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The output instructions explicitly tell the agent to extract the uploaded file URL and pass it to downstream APIs, encouraging onward disclosure of uploaded local content. This creates a straightforward path for sensitive file contents to propagate across services with limited visibility or control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script silently retrieves a bearer token from a local HTTP service and uses it for outbound authentication without informing the user or verifying the trust boundary of that local service. In a local agent environment, this can enable unintended use of sensitive credentials and makes abuse easier if the skill is triggered without the operator understanding that local auth material will be consumed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically uploads an arbitrary local file to a remote third-party endpoint and includes an authorization token, but provides no user-facing notice, confirmation, or preview of what data is being transmitted. In an agent-skill context, this increases the risk of silent exfiltration of sensitive local files and associated credentials or session tokens when invoked by another tool or workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.