Back to skill

Security audit

ZEDEDA

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed ZEDEDA management client, but it needs Review because it has broad infrastructure authority and concrete credential-handling weaknesses.

Install only if you trust this skill with a ZEDEDA token that can read and change your edge infrastructure. Use the least-privileged ZEDEDA token possible, leave ZEDEDA_BASE_URL unset unless it is a trusted HTTPS ZEDEDA endpoint, avoid session-token lookup methods until logging redaction is fixed, and consider setting ZEDEDA_LOG_LEVEL to WARNING or ERROR to reduce routine URL logging.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/client.py:72
Finding

Bearer Token Can Be Transmitted to an Arbitrary or Plaintext Endpoint

Content
View full analysis
", method="INIT", status_code=0, ) ``` ```python def _build_url(self, path: str, query: dict[str, Any] | None = None) -> str: url = f"{self.base_url}/{path.lstrip('/')}" if query: # Drop keys whose value is None filtered = {k: v for k, v in query.items() if v is not None} if filtered: url += ("&" if "?" in url else "?") + urllib.parse.urlencode(filtered, doseq=True) return url ``` ```python url = self._build_url(path, query) headers: dict[str, str] = { "Authorization": f"Bearer {self.token}", "Accept": "application/json", } if extra_headers: headers.update(extra_headers) encoded_body: bytes | None = None if body is not None: encoded_body = json.dumps(body).encode("utf-8") headers["Content-Type"] = "application/json" safe_url = self._sanitise(url, self.token) logger.debug(">>> %s %s", method, safe_url) if encoded_body: logger.debug(" body: %s", self._sanitise(encoded_body.decode()[:500], self.token)) last_exc: Exception | None = None for attempt in range(1, MAX_RETRIES + 2): t0 = time.monotonic() try: req = urllib.request.Request( url, data=encoded_body, headers=headers, method=method.upper(), ) with urllib.request.urlopen(req) as resp: ``` ### Technical Analysis The client ...[truncated 2175 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/user_service.py:296
Finding

Session Tokens Are Disclosed in Default Application Logs

Content
View full analysis
Any: """GET /v1/sessions/token — Get session via query param.""" q = {"sessionToken.base64": session_token_base64} return self.c.get("/v1/sessions/token", query=_qp(q)) def create_user_session_self(self) -> Any: """POST /v1/sessions/token/self — Create own session token.""" return self.c.post("/v1/sessions/token/self") def get_user_session(self, session_token_base64: str) -> Any: """GET /v1/sessions/token/{sessionToken.base64}""" return self.c.get(f"/v1/sessions/token/{session_token_base64}") ``` The client logs the resulting complete URL while only sanitizing the primary API token: ```python @staticmethod def _sanitise(text: str, token: str) -> str: """Replace the bearer token in *text* with a redacted placeholder.""" if token: text = text.replace(token, "***REDACTED***") return text ``` ```python safe_url = self._sanitise(url, self.token) logger.debug(">>> %s %s", method, safe_url) if encoded_body: logger.debug(" body: %s", self._sanitise(encoded_body.decode()[:500], self.token)) last_exc: Exception | None = None for attempt in range(1, MAX_RETRIES + 2): t0 = time.monotonic() try: req = urllib.request.Request( url, data=encoded_body, headers=headers, method=method.upper(), ) with urllib.request.urlopen(req) as resp: elapsed = time.monotonic() - t0 raw = resp.read().decode("utf-8") logger.info( "<<< %s %s → %s (%.3fs)", method, ...[truncated 2877 chars]
Remediation
View remediation
str: parsed = urllib.parse.urlsplit(url) path = re.sub( r"(/v1/sessions/token/)[^/]+", r"\1***REDACTED***", parsed.path, ) return urllib.parse.urlunsplit( (parsed.scheme, parsed.netloc, path, "", "") ) ``` A structured allowlist of safe query parameter names is preferable to a denylist because future API methods may introduce additional credentials without updating the redaction rules. ]]>
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (180)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description claims a fully featured ZEDEDA edge management API client with extensive endpoint coverage across many domains. However, the actual code chunk contains only a minimal init.py comment and no executable functionality demonstrating API calls, endpoint definitions, authentication, service modules, or related behavior. Based on the provided code alone, the implemented behavior does not substantiate the declared purpose, so this is a clear description-to-code mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code chunk is narrowly scoped to application policy/app profile operations only. It wraps GET/POST/PUT/DELETE calls for /v1/apps/policies and related status, events, metrics, global, import, and tags endpoints. The declared description, however, represents the skill as a complete ZEDEDA edge management client across many domains and hundreds of endpoints. That is a material overstatement of primary purpose and covered capabilities, so the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code chunk is clearly scoped to an AppService module and its docstring explicitly says it covers 80 endpoints for edge applications and related resources. All methods are thin wrappers around application, image, artifact, datastore, volume instance, patch-envelope, and app-instance status/log/metrics endpoints. This is materially narrower than the declared description of a complete ZEDEDA edge management client spanning 473 endpoints across 11 domains. While the code is consistent with the 'application' portion of that description, it does not substantiate the broader claimed scope, so the description overstates the actual behavior of the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description portrays a full ZEDEDA edge management API client spanning 11 domains and hundreds of endpoints. The supplied code chunk is narrowly scoped to diagnostics-related operations only. It accesses diagnostics, cloud health, audit/events, metrics, and a few device status/config endpoints, but does not demonstrate the broad multi-domain functionality claimed. This is a material scope mismatch: the declared purpose significantly overstates the capabilities represented by this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description substantially overstates the code’s scope. The supplied code chunk is narrowly focused on ZEDEDA job service functionality: querying/creating/updating/deleting jobs and triggering bulk imports or bulk device/application operations. It does not implement a complete edge management client, nor does it expose the broad multi-domain functionality claimed in the description. While the code is consistent with a subset of ZEDEDA API client behavior, its actual purpose is materially narrower than declared.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes a comprehensive ZEDEDA API client spanning many domains and hundreds of endpoints. The supplied code chunk is much narrower: it defines a single NetworkService class that wraps only network-specific REST endpoints. There is no evidence in this chunk of the broader capabilities claimed in the description. This is a material scope mismatch in declared purpose versus actual behavior, even though the network portion does align with one subset of the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code is consistent with a ZEDEDA API client, but only for a specific service area: node/device management plus related brands, hardware models, PCR templates, projects, and deployments. The declared description says this is a complete ZEDEDA edge management client spanning 473 endpoints across 11 domains. That materially overstates the behavior of the supplied code chunk. There is no evidence here of application, cluster, storage, network, Kubernetes, diagnostics, or user-management functionality. No hidden or unrelated capability is present; the mismatch is that the declared purpose is much broader than the implemented scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description substantially overstates the scope of the supplied code chunk. The code is a single service wrapper named OrchestrationService and exposes roughly 37 endpoints related to cluster instances, data streams, plugins, Azure deployment policy/module lookups, and API usage tracking. That is consistent with an orchestration-domain client module, but not with a complete ZEDEDA API client spanning 473 endpoints and 11 domains. While cluster/Kubernetes-related functionality is partially present, most of the declared service domains are absent from this code chunk. This is a material description-versus-behavior mismatch in scope and primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents the skill as a complete ZEDEDA edge management API client spanning many domains and hundreds of endpoints. The supplied code chunk is much narrower: it defines a single StorageService wrapper for storage-related resources such as patch envelopes, attestation policies, and deployment policies. While this code is consistent with one subset of the broader claimed client, the description materially overstates what this chunk actually does. This is a purpose/scope mismatch rather than a hidden undeclared capability.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description is directionally aligned with the code's main purpose: this is clearly a ZEDEDA API CLI/client spanning multiple edge-management domains and calling the ZEDEDA API. However, the claim that it is a 'complete' client with '473 endpoints across 11 service domains' is not supported by this code chunk. The entrypoint registers 11 top-level services, but the visible commands are far fewer than 473 and appear to cover only selected operations in each domain. Additionally, the actual domains include 'job' and 'app-profile' services, while the description instead highlights diagnostics and user management and does not mention those two explicitly. This is a material overstatement of completeness and exact scope, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description promises a large, feature-complete ZEDEDA API client, but the supplied code chunk contains only an empty test package file with a comment. There is no implemented behavior, no API interaction, no endpoint logic, and no evidence of the stated service-domain capabilities. This is a material mismatch between declared purpose and actual code behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a broad, production-capable ZEDEDA edge management API client spanning many domains and hundreds of endpoints. The actual code chunk is narrowly scoped to unit tests for one service class, specifically app policy/app profile methods, using a mocked client to assert URL construction for about 19 methods. This is a materially different primary purpose and scope from the declared description, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a full ZEDEDA API client spanning many domains, but the supplied code chunk only contains unit tests for a single service class, AppService. The tests validate endpoint paths and HTTP methods for app-, image-, datastore-, patch-envelope-, artifact-, and volume-instance-related calls using a mocked client. This is materially different from an implemented complete multi-domain API client. While the tested methods suggest some application/storage API coverage, the chunk does not demonstrate the broad 11-domain functionality claimed in the description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code chunk is a test module (tests/test_cli.py), not the implementation of a comprehensive ZEDEDA API client. Its actual behavior is limited to unit-testing helper functions and CLI dispatch in scripts.zededa, using mocks for NodeService, UserService, and ZededaClient. While these tests are related to a ZEDEDA CLI, they do not demonstrate or implement the declared primary capability of a complete client spanning 473 endpoints and 11 domains. This is a material description-to-code mismatch in primary purpose and represented scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a broad, complete ZEDEDA API client spanning many domains and hundreds of endpoints. The actual code shown is only a test file for the diagnostic service, using MagicMock to assert endpoint construction and HTTP verb usage for roughly 21 methods. This is materially narrower in scope and a different primary purpose (testing rather than implementing or exposing the full client). While the tested endpoints are consistent with the diagnostics portion of such a client, the chunk does not match the declared breadth or function of a complete 473-endpoint, 11-domain API client.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a full-featured ZEDEDA API client with hundreds of endpoints across many domains. The actual code chunk does not implement client calls or management operations; it contains only unit tests for custom exception classes and status-code mapping. While such error handling could support an API client, this chunk’s primary purpose is testing internal error behavior, which is materially narrower and different from the declared functionality.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description claims a comprehensive ZEDEDA API client spanning many domains and hundreds of endpoints. The actual code chunk is only a Python unittest module for JobService, focused narrowly on job-related endpoints under /v1/jobs. It uses MagicMock to validate HTTP method/path behavior and does not itself provide the broad edge management capabilities stated. This is a material description-behavior mismatch in primary purpose and scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description presents a broad, full-featured ZEDEDA edge management API client spanning many service domains. However, the actual code chunk is not a general client implementation; it is a unittest module focused solely on KubernetesService behavior, using mocked HTTP methods to validate endpoint paths for about 36 Kubernetes/ZKS methods. There is no evidence in this chunk of edge node, application, storage, network, diagnostics, or user management functionality, nor anything close to 473 endpoints. This is a material scope and purpose mismatch, not just an implementation detail.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description overstates the scope and nature of this code chunk. The supplied file is a Python unittest module focused exclusively on NetworkService, with mocked HTTP methods and assertions about endpoint paths. It does not itself provide a complete ZEDEDA API client, nor does it show behavior spanning edge node, application, cluster, storage, Kubernetes, diagnostics, or user management domains. While this test file may support such a larger project, the actual behavior in the provided chunk is specifically network-service unit testing, making the declared description materially inaccurate for this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description portrays a broad, complete ZEDEDA API client spanning many domains and hundreds of endpoints. The actual code chunk is narrowly scoped test code for a single service, NodeClusterService, using mocked get/post/put/delete/patch methods to assert URL construction for cluster policy endpoints. There is no indication in this chunk of application, storage, network, Kubernetes, diagnostics, user management, or other service-domain behavior, nor of a full client implementation. This is a material description-versus-behavior mismatch in scope and primary purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The description advertises a comprehensive ZEDEDA API client spanning 11 domains and 473 endpoints. The actual code shown is only a test module (tests/test_node_service_exhaustive.py) that exercises a mocked NodeService and checks endpoint paths for about 91 methods. While these methods are consistent with a subset of ZEDEDA edge/node-management functionality, the chunk does not itself provide the complete client and does not show the broad multi-domain coverage claimed in the description. Therefore the declared description materially overstates and mischaracterizes the code chunk’s actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The description presents a broad, complete ZEDEDA API client spanning many domains and hundreds of endpoints. The actual code chunk is narrowly scoped to unit tests for a single OrchestrationService and validates endpoint construction using a mocked client. While the tested endpoints are related to part of the declared cluster/orchestration domain, the chunk’s primary purpose is testing, not implementing the full client, and it covers only a small subset of the claimed scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill is a complete ZEDEDA edge management API client spanning many domains and hundreds of endpoints. The supplied code chunk does not implement such a client; it is a Python unittest module that mocks a client and verifies that StorageService methods invoke expected storage-related API paths. Its primary purpose is testing, not providing the full API client functionality described. While the tested endpoints are ZEDEDA-related and storage/policy oriented, the chunk materially underrepresents the claimed breadth and differs in purpose from the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description overstates the scope and nature of the provided code chunk. The actual code is a unittest module focused exclusively on UserService behavior, with mocked HTTP methods and assertions about endpoint paths for user, auth, session, enterprise, role, realm, credential, and report operations. There is no evidence in this chunk of a complete ZEDEDA client spanning all 11 service domains such as edge node, application, cluster, storage, network, Kubernetes, or diagnostics. While user-management is part of the declared scope, the chunk's actual purpose is narrower and is test validation rather than implementing the full client. Therefore this is a material description-behavior mismatch.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
The primary tool is `scripts/zededa.py`. Run any command via:

Static analysis

No suspicious patterns detected.