Back to skill

Security audit

AWS S3 Bucket Audit

Security checks for vulnerabilities and agentic risk

Overview

This S3 audit skill is not malicious, but it should be reviewed because it mixes audit guidance with live AWS changes without clear permission separation or approval gates.

Install only if you are comfortable reviewing the workflow before execution. Use read-only AWS credentials for audit steps, pin and isolate Prowler installation, and require explicit approval plus change-management review before running any Access Analyzer creation or S3 put-* remediation command in production.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:37
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:37
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Complete Code Snippet:

markdown
- Prowler installed (`pip install prowler`) for automated CIS benchmark checks

Technical Analysis

The prerequisite directs users to install prowler without specifying an exact version or verifying package integrity. As a result, the installed code depends on whichever release the configured Python package index resolves at installation time.

Python package installation can execute package-controlled build and installation logic. If the package, one of its transitive dependencies, the package index, or the user's package-index configuration is compromised, following this instruction may execute unreviewed code. The absence of version and hash constraints also makes installations non-reproducible and prevents users from confirming that they received the version reviewed with this Skill.

This finding concerns the dependency installation guidance. The project itself does not contain evidence that the legitimate Prowler package is malicious.

Attack Path

  1. An attacker compromises a future Prowler release, one of its transitive dependencies, or a package source configured on the victim's system.
  2. A user follows the documented prerequisite and runs pip install prowler.
  3. Pip resolves the mutable, attacker-affected package release rather than a previously reviewed version.
  4. Package-controlled installation or runtime code executes under the identity of the user performing the installation.
  5. The malicious package gains access to resources available to that user, potentially including local files, environment variables, and AWS credentials used for the subsequent audit.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the account running pip or Prowler. In the intended ...[truncated 422 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin Prowler to an exact, reviewed version, for example:
    bash
    python3 -m pip install "prowler==<reviewed-version>"
    
  2. Maintain a lock file containing exact versions of all transitive dependencies.
  3. Require cryptographic package hashes with pip's --require-hashes option.
  4. Document and enforce a trusted Python package index rather than relying on arbitrary user configuration.
  5. Install the tool in a dedicated virtual environment or isolated container using an unprivileged account.
  6. Periodically review and deliberately update the pinned version after checking release provenance and vulnerability advisories.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/agent.py:46
Finding

AWS API Errors Are Misclassified as Authoritative Security Results

Content
View full analysis

Vulnerability Details

File Locations: scripts/agent.py:46-51, scripts/agent.py:67-85, and scripts/agent.py:88-98
Vulnerability Type: Improper exception handling causing incomplete and misleading audit results
Risk Level: Medium

Complete Code Snippets:

python
def check_public_access_block(session, bucket_name):
    """Check bucket-level public access block settings."""
    s3 = session.client("s3")
    try:
        response = s3.get_public_access_block(Bucket=bucket_name)
        config = response["PublicAccessBlockConfiguration"]
        return {
            "configured": True,
            "block_public_acls": config.get("BlockPublicAcls", False),
            "ignore_public_acls": config.get("IgnorePublicAcls", False),
            "block_public_policy": config.get("BlockPublicPolicy", False),
            "restrict_public_buckets": config.get("RestrictPublicBuckets", False),
        }
    except ClientError:
        return {"configured": False}
python
def check_bucket_policy(session, bucket_name):
    """Check bucket policy for wildcard principals."""
    s3 = session.client("s3")
    try:
        policy_str = s3.get_bucket_policy(Bucket=bucket_name)["Policy"]
        policy = json.loads(policy_str)
        issues = []
        for stmt in policy.get("Statement", []):
            principal = stmt.get("Principal", {})
            if principal == "*" or principal == {"AWS": "*"}:
                issues.append({
                    "effect": stmt.get("Effect"),
                    "action": stmt.get("Action"),
                    "condition": stmt.get("Condition", "NONE"),
                })
        return {"has_policy": True, "wildcard_issues": issues}
    except ClientError:
        return {"has_policy": False, "wildcard_issues": []}
python
def check_encryption(session, bucket_name):
    """Check if default encryption is enabled."""

...[truncated 3251 chars]
Remediation
View remediation

Remediation Suggestions

  1. Inspect the exact AWS error code before deciding that a configuration is absent:
    python
    except ClientError as exc:
        code = exc.response.get("Error", {}).get("Code")
        if code == "NoSuchBucketPolicy":
            return {
                "status": "ABSENT",
                "has_policy": False,
                "wildcard_issues": [],
            }
        return {
            "status": "UNKNOWN",
            "error_code": code,
            "error_message": exc.response.get("Error", {}).get("Message"),
        }
    
  2. Use the relevant documented absence code for each API:
    • NoSuchPublicAccessBlockConfiguration
    • NoSuchBucketPolicy
    • ServerSideEncryptionConfigurationNotFoundError
  3. Represent results with explicit states such as PRESENT, ABSENT, and UNKNOWN; never convert authorization or service errors into absence.
  4. Treat AccessDenied and other incomplete checks as audit-coverage failures. Surface them prominently in the report and assign an appropriate conservative risk level.
  5. Add report-level counts for failed and unknown checks.
  6. Return a nonzero process exit status when security-relevant checks could not be completed, unless the user explicitly allows partial reports.
  7. Log the bucket name, API operation, AWS error code, and request identifier while avoiding disclosure of credentials or other sensitive values.
  8. Add unit tests covering absence, access denial, throttling, transient service errors, and successful responses for every check.
  9. Validate the required IAM permissions before beginning the audit so missing coverage is detected early.
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
82% confidence
Finding

The skill contains operational command content that can access environment-derived account context and produce files, but it does not declare any tool scope or allowed-tools boundaries. In an agent setting, that mismatch can cause the skill to be executed with broader capabilities than the user expects, reducing transparency and increasing the chance of unintended data exposure or artifact creation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The prerequisites state a read-only permission set, but later workflow steps require write capabilities such as creating an Access Analyzer and modifying S3 bucket settings. This discrepancy can mislead users about the true privilege requirements and increase the risk that an agent is granted broader access without informed review.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is presented as an audit procedure, but this section includes mutating remediation commands that change bucket public access settings, encryption, and versioning. In practice, an agent or operator following an 'audit' skill may execute these write actions unintentionally in production, causing configuration drift, outages, or unreviewed security changes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow step is framed as listing Access Analyzer findings, but it also includes creating a new analyzer resource. Even though the action is not inherently malicious, it is a scope expansion from observation to resource creation and may incur governance, logging, or cost implications in audited accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The remediation commands directly alter live S3 security controls without an explicit warning about production impact, rollback planning, or dependency checks. Because S3 buckets may intentionally be public or integrated with applications, blindly applying these commands can disrupt services or break partner/customer access while still being executed under the guise of routine auditing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.