Back to skill

Security audit

qshell-copilot

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Qiniu qshell helper, but users should handle credentials and executable installation carefully.

Install only if you intend to manage Qiniu Kodo through qshell. Prefer Homebrew or verify the official qshell release before manual installation, avoid using broad cloud-storage prompts unless Qiniu is clearly intended, use least-privilege Qiniu keys, and treat the AccessKey/SecretKey setup command as sensitive because it may be saved in shell history or logs.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:30
Finding

Qiniu SecretKey Exposed Through Command-Line Arguments

Content
View full analysis
``` ``` ### Technical Analysis The Skill instructs users to pass a long-lived Qiniu AccessKey and SecretKey directly as command-line arguments. Depending on the operating system and shell configuration, these values may be: - Recorded in plaintext shell history. - Temporarily visible through process-inspection facilities while `qshell` is running. - Captured by terminal logging, command auditing, telemetry, or diagnostic tools. - Disclosed if the user pastes the completed command into chat or support records. The network transmission of Qiniu credentials is necessary for authenticated storage management, but exposing the SecretKey through a command-line interface is not the minimum-risk method of collecting that credential. ### Attack Path 1. A user follows the authentication instructions and replaces `` with a valid Qiniu SecretKey. 2. The shell records the complete command in its history, or a local monitoring facility captures the process arguments. 3. An attacker with access to the user's account, history files, terminal logs, audit records, or applicable process-inspection interface retrieves the SecretKey. 4. The attacker configures another `qshell` instance or directly invokes Qiniu APIs with the compromised credentials. 5. The attacker performs any operation authorized by the associated Qiniu key. This path requires access to local history, logs, process metadata, or another location where the completed command was recorded. The Skill does not itself transmit the key to an unrelated third party. ### Impact Assessment Compromise could expose the Qiniu account resources permitted by the ...[truncated 512 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/install-guide.md:41
Finding

Executable Installed Without Cryptographic Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises trigger phrases broad enough to capture generic cloud-storage requests like 'upload this to my bucket' or 'list my cloud files' whenever Qiniu is merely 'configured,' which can cause the wrong provider-specific automation to run. In an agent setting, overbroad activation can lead to unintended file operations against Qiniu buckets, accidental data disclosure, or destructive actions in the wrong environment if user intent was ambiguous.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install-guide.md (reported line 38)May include surrounding context.

bash
unzip qshell-darwin-*.zip
chmod +x qshell
sudo mv qshell /usr/local/bin/

Linux

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/install-guide.md (reported line 48)May include surrounding context.

bash
unzip qshell-darwin-*.zip
chmod +x qshell
sudo mv qshell /usr/local/bin/

Linux

Static analysis

No suspicious patterns detected.