Back to skill

Security audit

Aria2 Rpc

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent aria2 remote-control helper, but its setup and examples encourage exposing an administrative RPC service and sending secrets over plaintext HTTP.

Install only if you understand aria2 RPC administration. Keep RPC bound to localhost when possible, use an SSH tunnel/VPN or HTTPS for remote access, use a strong unique secret, avoid putting secrets in command history or shared config files, and verify GIDs before remove, force-remove, or bulk cleanup commands.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/aria2_rpc.py:42
Finding

Remote RPC credentials and administrative commands may be transmitted over plaintext HTTP

Content
View full analysis
` and inserted into every JSON-RPC request body. The client accepts arbitrary HTTP or HTTPS endpoint URLs but does not warn about or reject plaintext HTTP for non-loopback destinations. Plaintext HTTP provi ...[truncated 1921 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:28
Finding

Documentation recommends exposing the privileged aria2 RPC service on all network interfaces

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:8
Finding

Third-party Python dependency is installed without version or integrity constraints

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill metadata and top-level description understate the available control surface. If the underlying script can also change global/per-task configuration, force-remove tasks, purge history, and add torrent/metalink content, users and policy engines may grant this skill broader authority than intended, creating a capability transparency and least-privilege failure. In a remote-control skill for a networked download daemon, undocumented administrative actions materially increase the risk of misuse against local or remote aria2 instances.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

md
python3 scripts/aria2_rpc.py tell-active --rpc-secret mytoken

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The code creates a requests session and performs outbound HTTP POST requests to a configurable RPC URL, which is an undeclared network capability. This is risky because the endpoint may be remote rather than local, allowing the skill to transmit commands and the optional RPC secret over the network to systems not covered by the advertised permission model.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The code creates a requests session and performs outbound HTTP POST requests to a configurable RPC URL, which is an undeclared network capability. This is risky because the endpoint may be remote rather than local, allowing the skill to transmit commands and the optional RPC secret over the network to systems not covered by the advertised permission model.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This markdown file contains user-facing instructions in Chinese, but there is no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking audience. That creates a natural-language policy concern because it forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/API_REFERENCE.md (reported line 45)May include surrounding context.

netstat -tlnp | grep 6800

检查防火墙

sudo ufw allow 6800/tcp

text

### 认证失败

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation shows passing the RPC secret directly on the command line for remote access, which can expose credentials through shell history, process listings, terminal logs, or copied transcripts. Because this skill is specifically for controlling local or remote aria2 instances, an exposed secret could let an attacker reconfigure downloads or abuse the remote service if the RPC endpoint is reachable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The documentation includes destructive remove/force-remove commands without warning about their effects, which can cause unintended deletion of download tasks or loss of queued state. In an agent skill context, concise examples are often copied verbatim, so omission of safety guidance increases the likelihood of accidental destructive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The remote connection examples show direct use of RPC URLs and shared secrets, including exporting credentials into environment variables, without any credential-handling or network-exposure warning. This can encourage insecure practices such as placing secrets in shell history, exposing RPC over untrusted networks, or connecting to aria2 instances listening on all interfaces.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The bulk-cleanup loop removes all completed/stopped items based on parsed output, with no warning about mass impact or validation of selected GIDs. In practice, users or agents could run this blindly and remove records for many tasks at once, making troubleshooting, auditing, or task recovery harder.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description limits the skill to adding downloads, querying status, pausing/resuming, and removing tasks. This file documents additional capabilities to read and modify aria2 global and per-task configuration via get-global-option, set-global-option, get-option, and set-option, which materially extend the scope beyond simple remote control operations listed in the manifest.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes remove and remove-force examples for deleting download tasks, including a note that force removal covers completed items, but it provides no caution about the destructive or potentially irreversible effect. Under the markdown-specific warning criterion, commands that can affect user data or system state should be accompanied by an explicit warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide encourages storing RPC secrets in environment variables and plaintext config files without any warning about exposure through shell history, process environments, backups, or permissive file permissions. In a skill designed to control local or remote aria2 instances, leaked credentials could allow unauthorized download management against the exposed RPC endpoint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill description says it supports adding downloads and controlling/querying tasks, but the implementation also exposes get/changeGlobalOption and get/changeOption operations that can read and modify aria2 configuration. This mismatch expands the skill's effective authority beyond what users are led to expect, enabling changes such as proxy, directory, session, timeout, or other runtime options that may alter behavior, persistence, or data routing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The guide encourages changing download and session paths without warning about permissions, overwriting existing files, or writing into sensitive directories. In a tool that manages file downloads and persistent session state, unsafe path choices can cause accidental data loss, permission issues, or unintended writes to important filesystem locations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The quick reference is written entirely in Chinese, which may impose a language constraint on users without any opt-in or explanation that the skill is intended for a Chinese-speaking audience. The policy requires either offering language/locale choice or clearly documenting and justifying the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

All headings and instructional text in the file are Chinese, which effectively forces a specific language for users without any opt-in or justification. The policy calls for flagging language or locale constraints when the skill does not offer a choice or clearly document why a specific language is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.