T09 · Insecure Skill Coding Practices
- Location
confluence.sh:33- Finding
Unsafe Shell Expansion of Authentication Credentials
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Confluence skill is purpose-aligned but needs Review because it can modify remote wiki content and handles credentials with under-disclosed and unsafe shell practices.
Install only if you trust the publisher and will use a least-privilege Confluence API token over HTTPS. Avoid putting tokens directly on the command line, review create/update/upload requests before running them, and do not use highly privileged accounts until the credential handling, HTTPS enforcement, JSON construction, and temporary-file issues are fixed.
confluence.sh:33Unsafe Shell Expansion of Authentication Credentials
confluence.sh:331Predictable Shared Temporary File Enables Symlink and Race Attacks
confluence.sh:207Untrusted Page Data Is Interpolated Directly into JSON Requests
confluence.sh:41Basic Authentication Credentials Can Be Sent over Plaintext HTTP
The skill advertises shell-backed capabilities but does not declare any explicit tool scope or permissions boundary. In an agent environment, this increases the chance the skill can invoke shell actions without clear user/admin review, making its remote-write and credential-using behavior less transparent and harder to constrain.
The skill describes create, update, and attachment-upload features without clearly warning that these operations modify remote Confluence content. In an agent setting, insufficient disclosure of side effects can lead to unintended data changes, overwrites, or unauthorized content publication.
The setup instructions encourage use of a password or API token but do not emphasize that these are sensitive secrets requiring careful handling. Without guidance on least privilege, secure storage, and avoiding plaintext exposure in shells or logs, users may leak credentials or overprovision access.
The statement that credentials are 'never exposed or stored externally' is inaccurate because the skill necessarily transmits them to the remote Confluence service for authentication. This can mislead users into underestimating credential exposure risk and making unsafe trust decisions about a networked integration.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
#!/bin/bash
# Confluence REST API - curl 实现
# 用法: confluence.sh <命令> --url <url> --user <用户名> --pass <密码> [选项]
set -e
The script constructs a Basic Auth credential string from CONFLUENCE_USER and CONFLUENCE_PASS and uses it in curl requests, which transmits credentials to the configured server. While the usage text documents the parameters, there is no explicit safety warning or disclosure that the script will send credentials over the network and that the URL should be trusted and use HTTPS.
The page create and page update commands modify remote Confluence content, including replacing page bodies, but the script provides no confirmation prompt and no explicit warning that these operations will alter existing data. Although the command names imply writing, the help text does not caution that updates may overwrite content or increment page versions.
The attach command reads a local file and uploads it to Confluence using curl, which is a safety-relevant network transmission of user data. The script logs that an upload is occurring, but it does not explicitly warn in the interface or documentation that local file contents will be transmitted to the configured server and may affect remote data.
No suspicious patterns detected.