Back to skill

Security audit

EZ Ansible Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Ansible helper, but its generated defaults include unsafe infrastructure settings that users should review before installation.

Review and change the generated security defaults before using this skill for real infrastructure: keep SSH host key checking enabled, avoid defaulting to ~/.ssh/id_rsa, require explicit approval for root become, pin dependencies to reviewed versions or commits, store fact caches in a restricted per-project directory, and encrypt or redact any Vault values before committing them.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:352
Finding

SSH Host Authentication Disabled for Connections Using a Private Key

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:416
Finding

Generated Ansible Dependencies Are Mutable or Not Fully Pinned

Content
View full analysis
=7.0.0" - name: ansible.posix - name: community.docker version: "3.4.0" roles: - name: geerlingguy.nodejs version: "6.1.0" - src: https://github.com/org/role.git scm: git version: main name: custom_role ``` ### Technical Analysis Several generated dependencies are not tied to immutable, reviewed artifacts: - `community.general` allows any release at or above version 7.0.0. - `ansible.posix` has no version constraint. - The custom Git role tracks the mutable `main` branch. A branch can change without modification to `requirements.yml`, and an open-ended version range can resolve to newly published content that was not reviewed with the project. Ansible collections can contain executable Python modules and plugins, while roles contain tasks that perform operations with the privileges assigned to the play. This is a supply-chain integrity weakness. The fixed versions shown for `community.docker` and `geerlingguy.nodejs` reduce mutability, but versions alone do not provide artifact integrity verification. ### Attack Path 1. A generated project retains the example dependency declarations. 2. An upstream account, repository, release process, or distribution channel is compromised, or the mutable Git branch is changed. 3. A developer or CI job runs `ansible-galaxy collection install` or `ansible-galaxy role install`. 4. Dependency resolution retrieves content different from the version previously reviewed. 5. A playbook invokes a compromised module, plugin, or role. 6. The dependency executes on the controller or performs malicious tasks on managed hosts with the play's configured Ansible and `become` privileges. ### Impact Assessment A compromised collection may execute code on the Ansib ...[truncated 479 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:449
Finding

Unpinned Package Installation in Validation Instructions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:361
Finding

Ansible Facts Stored in a Predictable Shared Temporary Path

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 192)May include surrounding context.

[all:vars] ansible_user=deploy ansible_ssh_private_key_file=~/.ssh/id_rsa ansible_python_interpreter=/usr/bin/python3

text

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The sample ansible.cfg hardcodes a private key file path and also disables host key checking nearby, creating an insecure default connection posture. While not exfiltration code, this encourages users to rely on a fixed sensitive credential path and weakens SSH trust verification, making misuse or man-in-the-middle exposure more likely in copied configurations.

Content

Scanner excerpt · SKILL.md (reported line 352)May include surrounding context.

md
roles_path          = ./roles:~/.ansible/roles
collections_paths   = ./collections:~/.ansible/collections
remote_user         = deploy
private_key_file    = ~/.ssh/id_rsa
host_key_checking   = False
retry_files_enabled = False
stdout_callback     = yaml

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says to use the skill whenever the user mentions a wide range of terms and even for vague requests like "automate server setup." This trigger scope is broad enough to overlap with many general infrastructure conversations, and it does not provide exclusion conditions or negative examples to limit unintended invocation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 369)May include surrounding context.

md
[privilege_escalation]
become              = True
become_method       = sudo
become_user         = root
become_ask_pass     = False

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly advises using Vault for secrets, yet its example vault.yml contains plaintext-looking credentials and key material. Even if presented as placeholders, examples like this normalize storing secrets directly in files and may be copied into real projects, leading to accidental credential exposure in source control or logs.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

L503 says the first line of every file must be '# Managed by Ansible'. Yet examples such as L61 ('# playbooks/.yml'), L173 ('# inventory/hosts'), L198 ('# inventory/hosts.yml'), L247 ('{# templates/nginx.conf.j2 #}'), L324 ('# group_vars/all/vault.yml'), and L337 ('# group_vars/all/vars.yml') put other headers first. That is a direct contradiction between the stated rule and the actual templates the skill tells users to generate.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.