Back to skill

Security audit

password-manager

Security checks for vulnerabilities and agentic risk

Overview

This is a real local password manager, but it stores and exports passwords in plaintext and uses weak password generation, so users should review it before trusting it with credentials.

Install only if you understand that this is not a vault-grade password manager. Credentials, backups, and exports are plaintext local files, generated passwords rely on a weak random source, and CSV exports can expose secrets. Prefer an established encrypted password manager for real accounts unless this skill is revised to encrypt data, use a cryptographic generator, warn before exports, and restrict file permissions.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/password_manager.py:78
Finding

Credentials and backups are stored in plaintext

Content
View full analysis
bool: """保存数据文件""" try: self.data["last_updated"] = datetime.now().isoformat() # 自动备份 if self.data.get("settings", {}).get("auto_backup", True): self._create_backup() with open(self.data_path, 'w', encoding='utf-8') as f: json.dump(self.data, f, indent=2, ensure_ascii=False) return True except Exception as e: print(f"保存数据文件失败: {e}") return False def _create_backup(self) -> bool: """创建备份文件""" try: timestamp = datetime.now().strftime("%Y%m%d_%H%M%S") backup_path = self.backup_dir / f"passwords_backup_{timestamp}.json" with open(backup_path, 'w', encoding='utf-8') as f: json.dump(self.data, f, indent=2, ensure_ascii=False) return True ``` The password is inserted directly into the persisted record: ```python password_entry = { "id": str(uuid.uuid4()), "name": name, "username": username, "password": password, "category": category, "notes": notes, "created_at": datetime.now().isoformat(), "updated_at": datetime.now().isoformat(), "strength": strength } ``` ### Technical Analysis The manager places the original password directly into an in-memory dictionary and serializes the entire dictionary to JSON without encryption. Every modification can also create another plaintext copy in the backup directory. No authenticated encryption, master-password-based key derivation, operating-system keyring integration, or explicit restrictive file permissions are applied. Consequently, confidentiality depends entirely on external filesystem protections. The documentation is also inconsistent: `SKILL.md:379` describes the pa ...[truncated 1420 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/password_generator.py:87
Finding

Passwords, PINs, and passphrases use a non-cryptographic random number generator

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/password_manager.py:430
Finding

CSV export permits spreadsheet formula injection

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

声明描述的核心用途是“本地密码管理器”,重点在保存和管理账号密码数据;而提供的代码块仅实现了密码生成相关功能。两者主用途存在明显差异。虽然密码生成与密码管理同属相关领域,但它不是所声明的一组管理能力的支持性实现细节,而是另一项独立核心功能。因此应判定为描述与实际行为不匹配。

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example dialogue asks the user to provide a full password directly in chat without an immediate warning that the conversation itself may expose or retain credentials. This is dangerous because chat logs, model providers, plugins, UI history, screenshots, or shared devices can leak secrets even if the skill claims local storage.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Password entries are persisted to disk and backup files as plaintext without any user-facing notice or consent mechanism. For a tool handling account credentials, silent plaintext storage is dangerous because users may assume vault-like protection and unknowingly expose all saved secrets to anyone or any process with filesystem access.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The JSON and CSV export routines include complete plaintext passwords and write them to user-specified files without warning. This is dangerous because exports are easy to move, email, sync, or open in spreadsheet software, causing broad credential exposure well beyond the original local store.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

README 在技能信息中直接声明“语言:中文”,但未说明这是可配置选项,也未给出仅适用于特定中文区域或合规场景的理由。该表述构成了对语言/区域的硬性限制,可能违反需要用户语言选择或显式同意的组织策略。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This password-manager skill presents sensitive features like local password storage, import/export, and backup as core benefits near the top of the document, without an equally prominent up-front warning that passwords are stored unencrypted by default. In the context of a password-management tool, this is dangerous because users may trust it with highly sensitive credentials before noticing the later warning, increasing the risk of credential disclosure through local file access, backups, exports, or accidental sharing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

文档列出了多条可触发短语,如“删除测试账号”“导出我的密码”“查看统计信息”,但没有说明这些是精确触发词、示例表达,还是需要特定上下文才会生效。缺少负面示例或排除条件会让技能何时应被调用、何时不应被调用变得模糊。

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

README 在“使用方法”中将“帮我保存一个密码”列为基本操作触发语,但该表述非常通用,缺少对技能范围、目标对象或上下文的限定。类似宽泛短语容易与普通助理对话重叠,增加非预期调用该技能的风险。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill describes capabilities that require reading and writing local files, but it does not declare an explicit tool scope such as allowed-tools or permissions. This creates an authorization ambiguity where a password-handling skill may gain broader file access than users or the platform expect, which is especially risky because it processes highly sensitive credentials.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger text is very broad and may activate on ordinary conversations mentioning passwords, accounts, or saving credentials. In a password-management context, over-triggering can cause the assistant to solicit, reveal, or store sensitive credentials when the user did not intend to use this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill documents import/export of password data and local storage but does not clearly warn that these operations may expose plaintext secrets in exported files, temporary files, spreadsheets, backups, or other applications. For a password manager, failing to foreground that risk materially increases the chance of accidental credential disclosure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code file contains natural-language docstrings and printed interface text that force a specific language/locale for users. The policy allows fixed locale behavior only when the skill offers opt-in or clearly documents a justified regional constraint, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The main routine prints prompts and labels exclusively in Chinese, which imposes a language choice on users. Because there is no user language selection or stated locale justification, this is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Docstrings, comments, category names, and printed messages are written only in Chinese, which effectively forces a language choice on users and maintainers. The file does not indicate that the skill is region-specific or provide any language opt-in or alternative.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The save path automatically creates plaintext backup copies of the entire password database before writing updates. In a password-manager skill, duplicating sensitive data into additional unencrypted files expands the attack surface and increases the likelihood of compromise from local file access, cloud sync, endpoint backup systems, or forensic recovery.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The export functions write the full credential store, including plaintext passwords, to arbitrary JSON and CSV paths. In a password-manager context this is especially risky because users reasonably expect stronger protection for secrets, and exporting to plaintext materially increases the chance of credential disclosure through other local users, backups, sync tools, or accidental sharing.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file contains user-facing instructional content exclusively in Chinese, and it does not indicate that the language is optional, configurable, or limited to a specific Chinese-speaking audience. Under the stated policy, forcing a specific language without user opt-in is a natural-language locale violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.