Back to skill

Security audit

Sp501lw Mqtt

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent MQTT gateway management skill, but it needs review because it controls hardware while handling MQTT credentials and traffic insecurely.

Review before installing on real hardware. Use only test or authorized gateways, avoid the default public broker credentials, assume devices.json and command output may expose passwords, and avoid untrusted networks because TLS is not implemented. Pin dependencies and confirm device IDs, topics, and rebooting configuration changes before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
sp501lw_mqtt.py:197
Finding

MQTT Credentials and Device-Control Traffic Transmitted Without TLS

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
sp501lw_mqtt.py:320
Finding

Broker Passwords Are Persisted and Returned in Plaintext

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Open-Ended Dependency Version Allows Unreviewed Future Releases

Content
View full analysis
=2.0.0 ``` The same open-ended installation constraint is also documented in `README.md:10` and `SKILL.md:567`. ### Technical Analysis The dependency constraint accepts any `paho-mqtt` release at or above version 2.0.0. This means installations performed at different times may resolve to different package versions without any source change or security review in this project. The package name appears legitimate and there is no evidence in the audited project that it intentionally installs a malicious or typosquatted dependency. The risk arises from the open-ended resolution policy: a compromised, malicious, or incompatible future release could be selected automatically. No lock file or package hash is present to provide reproducible and integrity-checked installation. ### Attack Path 1. A user or automated environment installs dependencies from `requirements.txt`. 2. The package resolver selects the newest version satisfying `paho-mqtt>=2.0.0`. 3. A future release that has not been reviewed by this project is downloaded. 4. If that release is compromised or contains exploitable behavior, its installation or runtime code executes in the Skill environment. 5. The dependency receives the privileges of the account running installation or the Skill. This path requires a compromised or unsafe dependency release, package-index compromise, or an incompatible future release; none was observed directly in the audited repository. ### Impact Assessment Potential impact depends on the privileges used to install and run the dependency. In a worst-case supply-chain compromise, dependency code could: - Read files available to the Skill process - Access stored MQTT credentials - Alter MQTT messages - Execute code with the Skill user's priv ...[truncated 245 chars]
Remediation
View remediation
``` 2. Generate a lock file that includes hashes, for example through `pip-tools`, and install with hash verification: ```bash pip-compile --generate-hashes requirements.in pip install --require-hashes -r requirements.txt ``` 3. Keep the dependency source restricted to the official package index or an organization-controlled mirror. 4. Use an automated dependency update process that performs security scanning, compatibility testing, and human review before changing the pin. 5. Keep installation documentation and Skill metadata synchronized with the locked version. 6. Run dependency installation and the Skill under a non-privileged account and isolated environment to limit supply-chain impact. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file describes actions that can change device working mode, send serial commands, and modify MQTT/serial/network/OTA settings, all of which can affect connected hardware or system availability. The README provides usage examples but does not include any caution, confirmation note, or warning about validating commands before applying them to real devices.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill metadata does not declare any tool scope or allowed-tools restrictions even though the documentation clearly indicates local file read/write behavior via devices.json and JSON import/export flows. In an agent environment, missing explicit capability scoping can lead to broader-than-expected filesystem access and makes it harder to enforce least privilege.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation includes plaintext broker credentials in a device record example without any warning that they are sensitive or should be rotated. Publishing reusable-looking usernames and passwords normalizes unsafe secret handling and may expose real infrastructure if the sample values are valid or copied into production.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The command examples pass passwords directly on the command line, which can expose secrets through shell history, process listings, logs, and terminal transcripts. This is especially risky on shared systems and agent platforms where command invocations may be captured automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documentation exposes a destructive reset capability with only minimal inline caution and no strong safeguards such as explicit confirmation workflow, recovery guidance, or access restrictions. In an agent-controlled device-management context, destructive commands can cause service disruption, configuration loss, and operational outages if invoked mistakenly or by prompt manipulation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The installation instructions use npx clawhub@latest, which is effectively an unpinned remote package execution pattern. If the upstream package is compromised or changes unexpectedly, users may execute malicious code during installation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example script embeds MQTT broker credentials directly on the command line, exposing secrets in plaintext within the file and potentially in shell history, process listings, logs, or screenshots. In an MQTT management skill that configures real devices and brokers, this can lead to unauthorized broker access, device impersonation, or interception of operational telemetry and commands if copied into production use.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The top-level docstring states that the tool supports two modes only: mqtt_tcp and modbus_rtu. Elsewhere, the implementation and CLI advertise modbus_tcp as a valid mode, so the documented intent does not match the actual behavior.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The module docstring actively enumerates supported modes and omits modbus_tcp, creating a direct contradiction with the executable logic that permits modbus_tcp configuration. This is stronger than mere incompleteness because the documentation explicitly constrains supported behavior to two modes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code defines default MQTT broker credentials and later stores per-device broker usernames and passwords in plaintext within devices.json. Anyone with local file access can recover credentials and potentially connect to brokers, read device traffic, or send unauthorized control/configuration messages to managed gateways.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description limits the skill to '串口透传' and 'Modbus RTU 数据采集' via MQTT, which aligns with mqtt_tcp and modbus_rtu. However, the code explicitly accepts and configures a third work mode, modbus_tcp, extending the operational scope beyond what the manifest says.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

SKILL.md 在 L163-L399 的命令参考中混合列出了已实现与规划中的命令,虽然有提醒,但同一文档仍详细描述了大量当前脚本未实现的能力,如设备端 MQTT/网络配置、OTA、重启、恢复出厂和信息查询。这会造成技能声明能力范围与实际可执行行为之间的偏差,属于描述与实际行为不完全一致。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The script's human-facing comments and echo messages are written entirely in Chinese, which imposes a specific language on users without any opt-in or explanation. Under the policy, locale or language constraints should either be optional for users or clearly documented as necessary for a region-specific use case.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

All user-facing comments and echo output in the script are written in Chinese, and the file provides no option or note allowing another language. This is a natural-language policy concern because the skill implicitly enforces a specific locale without user opt-in or a documented region-specific requirement.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script's comments and all user-visible output strings are written in Chinese, with no option to select another language or indication that the skill is intentionally region-specific. This can violate language/locale policy when a skill imposes a specific language without user opt-in or documented justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This shell script executes commands that register a device and switch its operating mode, which changes remote device configuration and transmits data over network topics. Although it prints step labels, it does not provide any explicit warning, confirmation, or cautionary note about modifying device state or interacting with remote MQTT topics.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
94% confidence
Finding

The dependency is specified with only a lower bound, so future installs may resolve to newer unreviewed versions of paho-mqtt. This creates supply-chain and reliability risk because a breaking or compromised upstream release could be pulled into deployments without validation.

Content

Scanner excerpt · requirements.txt (reported line 1)May include surrounding context.

text
paho-mqtt>=2.0.0

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The listen command connects to MQTT, subscribes to the device data topic, and prints received payloads directly to stdout. While the command purpose implies listening, the code does not explicitly warn users that potentially sensitive device or system data received over the network will be displayed verbatim.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.