Back to skill

Security audit

Confluence Integration

Security checks for vulnerabilities and agentic risk

Overview

This Confluence skill is purpose-aligned but needs Review because it can modify remote wiki content and handles credentials with under-disclosed and unsafe shell practices.

Install only if you trust the publisher and will use a least-privilege Confluence API token over HTTPS. Avoid putting tokens directly on the command line, review create/update/upload requests before running them, and do not use highly privileged accounts until the credential handling, HTTPS enforcement, JSON construction, and temporary-file issues are fixed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
confluence.sh:33
Finding

Unsafe Shell Expansion of Authentication Credentials

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
confluence.sh:331
Finding

Predictable Shared Temporary File Enables Symlink and Race Attacks

Content
View full analysis
/dev/null || cat /tmp/attach_response.json exit 1 fi ``` ### Technical Analysis The attachment response is written to the fixed path `/tmp/attach_response.json`. The global temporary directory is normally writable by all local users. The script does not securely create the file, verify its ownership or type, assign restrictive permissions, or remove it after use. Curl follows symbolic links when opening an output path. A local attacker can therefore pre-create `/tmp/attach_response.json` as a symbolic link to another file writable by the Skill's user. Curl may then truncate and overwrite that target. The fixed name also permits race conditions and collisions between concurrent Skill executions. One process or local attacker can replace or modify the response file between curl writing it and the script reading it, causing the script to consume forged response data. Response bodies can remain on disk after execution and may contain attachment metadata or sensitive error details. ### Attack Path 1. A local attacker predicts the hardcoded path `/tmp/attach_response.json`. 2. Before an attachment upload, the at ...[truncated 1126 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
confluence.sh:207
Finding

Untrusted Page Data Is Interpolated Directly into JSON Requests

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
confluence.sh:41
Finding

Basic Authentication Credentials Can Be Sent over Plaintext HTTP

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises shell-backed capabilities but does not declare any explicit tool scope or permissions boundary. In an agent environment, this increases the chance the skill can invoke shell actions without clear user/admin review, making its remote-write and credential-using behavior less transparent and harder to constrain.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes create, update, and attachment-upload features without clearly warning that these operations modify remote Confluence content. In an agent setting, insufficient disclosure of side effects can lead to unintended data changes, overwrites, or unauthorized content publication.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The setup instructions encourage use of a password or API token but do not emphasize that these are sensitive secrets requiring careful handling. Without guidance on least privilege, secure storage, and avoiding plaintext exposure in shells or logs, users may leak credentials or overprovision access.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The statement that credentials are 'never exposed or stored externally' is inaccurate because the skill necessarily transmits them to the remote Confluence service for authentication. This can mislead users into underestimating credential exposure risk and making unsafe trust decisions about a networked integration.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · confluence.sh (reported line 2)May include surrounding context.

sh
#!/bin/bash
# Confluence REST API - curl 实现
# 用法: confluence.sh <命令> --url <url> --user <用户名> --pass <密码> [选项]

set -e

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The script constructs a Basic Auth credential string from CONFLUENCE_USER and CONFLUENCE_PASS and uses it in curl requests, which transmits credentials to the configured server. While the usage text documents the parameters, there is no explicit safety warning or disclosure that the script will send credentials over the network and that the URL should be trusted and use HTTPS.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The page create and page update commands modify remote Confluence content, including replacing page bodies, but the script provides no confirmation prompt and no explicit warning that these operations will alter existing data. Although the command names imply writing, the help text does not caution that updates may overwrite content or increment page versions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The attach command reads a local file and uploads it to Confluence using curl, which is a safety-relevant network transmission of user data. The script logs that an upload is occurring, but it does not explicitly warn in the interface or documentation that local file contents will be transmitted to the configured server and may affect remote data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.