Back to skill

Security audit

Bdpan Storage

Security checks for vulnerabilities and agentic risk

Overview

The skill’s Baidu Netdisk file features are mostly coherent, but its automatic native installer, remote self-update path, and unsafe uninstall controls need careful review before use.

Use this only if you trust the publisher and Baidu-hosted download/update endpoints. Require a human to approve first install and every update, avoid --yes for update or uninstall, do not set BDPAN_CONFIG_DIR/BDPAN_INSTALL_DIR unless you fully control the path, and do not authorize the account on shared or untrusted machines.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (5)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/update.sh:90
Finding

Remotely Controlled Archive Can Replace Active Skill Files

Content
View full analysis
/dev/null) || { log_error "Unable to connect to the configuration server" return 1 } local skills_info=$(echo "$response" | sed 's/\\u0026/\&/g' | grep -o 'version=[^"]*' | head -1 | sed 's/\\//g') local remote_url=$(query_get "$SKILLS_INFO" "url") curl -fsSL -o "$zip_path" "$remote_url" || { log_error "Failed to download the Skill update package" return 1 } local checksum=$(query_get "$SKILLS_INFO" "checksum") if [ "$actual" != "$checksum" ]; then log_error "SHA256 verification failed" return 1 fi unzip -qo "$zip_path" -d "$SKILL_DIR" || { log_error "Extraction failed" return 1 } ``` ### Technical Analysis The remote configuration endpoint controls the update package URL, version, and expected SHA-256 checksum. The script does not authenticate the configuration response with a key stored outside the remote trust boundary. Consequently, SHA-256 only confirms that the downloaded archive matches the checksum supplied by the same remote source. It does not establish publisher authenticity. An attacker able to compromise or manipulate the configuration endpoint can supply both a malicious archive and its matching checksum. The downloaded archive is extracted directly over the active Skill directory. There is no validation of: - The URL scheme or destination hostname. - Redirect destinations. - Archive member names. - Path traversal entries. - Symbolic links. - The set of files permitted to be replaced. - A signed release manifest. This permits remote replacement of `SKILL.md`, scripts, and reference files. ### Attack Path 1. An attacker compromises or gains control over the remote configuration response. 2. The response specifies an attacker-contro ...[truncated 915 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/install.sh:161
Finding

Automatic Download and Execution of a Remotely Hosted Native Installer

Content
View full analysis
/dev/null; then curl -fsSL -O "${installer_url}" elif command -v wget &> /dev/null; then wget -q "${installer_url}" fi if [ "$os" != "windows" ]; then chmod +x "${installer_name}" fi if command -v curl &> /dev/null; then curl -fsSL -o "${checksum_file}" "${CHECKSUM_URL}" 2>/dev/null && checksum_downloaded="yes" elif command -v wget &> /dev/null; then wget -q -O "${checksum_file}" "${CHECKSUM_URL}" 2>/dev/null && checksum_downloaded="yes" fi local expected_hash=$(grep -F "${installer_name}" "${checksum_file}" | awk '{print $1}') if [ "$actual_hash" = "$expected_hash" ]; then log_info "SHA256 verification passed" else exit 1 fi ./${installer_name} --yes ``` The automatic invocation is declared in `SKILL.md:37`: ```bash bash @skills/bdpan-storage/scripts/install.sh --yes ``` ### Technical Analysis When the CLI is absent, the Skill directs the Agent to invoke the installer non-interactively. The installer downloads a native executable and executes it with the Agent user's privileges. Although SHA-256 verification is mandatory, the installer and `SHA256SUMS` file are retrieved from the same CDN trust boundary. If that source is compromised, an attacker can replace both files consistently. The verification therefore detects accidental corruption but does not provide independent authenticity. Automatically executing a remote native installer during an ordinary storage request exceeds the minimum privilege necessary to explain that installation is required and request informed user approval. ### Attack Path 1. A user requests a normal Baidu Netdisk operation. 2. The Agent determines that `bdpan` is not in ...[truncated 738 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/uninstall.sh:56
Finding

Environment-Controlled Configuration Path Enables Arbitrary Recursive Deletion

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/login.sh:143
Finding

Invalid OAuth Authorization Codes Are Echoed to Terminal and Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
reference/bdpan-commands.md:404
Finding

Conflicting Documentation Permits Unattended Remote Skill Updates

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (28)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The skill also supports self-update behavior that retrieves packages from remote endpoints and installs them into the local skill directory, but this is not reflected in the primary description. Self-updating code materially increases supply-chain and code-execution risk, especially when the update path is bundled into a user-facing storage skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill also supports self-update behavior that retrieves packages from remote endpoints and installs them into the local skill directory, but this is not reflected in the primary description. Self-updating code materially increases supply-chain and code-execution risk, especially when the update path is bundled into a user-facing storage skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill also supports self-update behavior that retrieves packages from remote endpoints and installs them into the local skill directory, but this is not reflected in the primary description. Self-updating code materially increases supply-chain and code-execution risk, especially when the update path is bundled into a user-facing storage skill.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
84% confidence
Finding

The installation/update flow is a download-and-execute path, and the text itself admits checksum material is fetched from the same source as the installer. Even though a checksum-bypass flag is said to be removed, the overall mechanism remains susceptible to supply-chain compromise because same-origin checksum verification does not provide strong authenticity guarantees.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

md
**安全说明:**
- 安装器从百度 CDN(`issuecdn.baidupcs.com`)下载,SHA256 校验文件同源
- **禁止**使用 `--skip-checksum` 参数(该参数已移除)
- SHA256 校验失败时必须终止安装,不可绕过

> **安装机制风险声明:** 安装和更新过程涉及从百度官方端点(`issuecdn.baidupcs.com`、`pan.baidu.com`)下载二进制文件/压缩包并在本地执行,属于 download+execute 模式。已通过以下措施缓解风险:SHA256 校验为强制项且失败时终止、仅使用百度官方域名、更新需用户明确发起并确认。**已知局限:** SHA256SUMS 校验文件与安装器从同一 CDN 下载(同源校验),若远程主机被入侵,攻击者理论上可同时替换安装器和校验文件。建议用户在首次安装或安全敏感场景下,通过沙箱环境执行安装或手动审查下载的二进制文件。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 469)May include surrounding context.

md
|------|------|
| `--config-path <path>` | 指定配置文件完整路径(适用于 AI Agent 集成) |
| `--json` | JSON 格式输出 |
| `--no-check-update` | 禁用版本更新检查 |
| `--help` | 显示帮助 |
| `--version` | 显示版本 |

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 632)May include surrounding context.

md
import subprocess
import os

env = os.environ.copy()
env["BDPAN_CONFIG_PATH"] = "/home/user/.config/bdpan/config.json"

result = subprocess.run(

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · reference/examples.md (reported line 336)May include surrounding context.

bdpan upload "/tmp/${BACKUP_FILE}" "backup/${BACKUP_FILE}"

清理

rm "/tmp/${BACKUP_FILE}"

echo "备份完成: ${BACKUP_FILE}"

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The guide instructs users to delete a configuration file directly with rm as part of login recovery. Destructive file operations in agent-facing documentation are risky because an automated or inattentive consumer could execute them without validation, causing loss of configuration, logout state, or accidental deletion if paths are expanded or modified incorrectly.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 61)May include surrounding context.

解决方案:

bash
# 清除配置并重试
rm ~/.config/bdpan/config.json
bash scripts/login.sh

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

The documentation recommends deleting the installed binary with rm before reinstalling. While limited to a user-local path, this is still a destructive command that could remove the wrong file if copied carelessly or if the path is manipulated, and it normalizes unsafe remediation patterns in a skill that may be consumed by automation.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 255)May include surrounding context.

解决方案:

bash
# 删除现有二进制文件
rm ~/.local/bin/bdpan

# 重新安装
cd skills/bdpan-storage

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill enables shell execution but does not declare an explicit tool scope such as allowed-tools or permissions. In practice this weakens policy boundaries for a skill that can install, update, uninstall, and invoke a local CLI, making accidental or over-broad command execution harder to constrain and audit.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Using the broad trigger keyword "网盘" can cause the skill to activate for generic cloud-drive conversations rather than explicit Baidu Netdisk requests. Because the skill can invoke shell commands and potentially install software, unintended activation materially raises the chance of surprising or unsafe actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Allowing activation from unspecified "recent conversation context" creates ambiguous trigger boundaries. In a multi-turn session, that can make later commands like "share it" or "download it" invoke this shell-capable skill unexpectedly, including login, install, or remote file actions without a fresh explicit Baidu-specific request.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

创建文件夹 (mkdir)

bash
bdpan mkdir <路径>
bdpan mkdir backup/2026                      # 创建文件夹

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file presents all operational and safety instructions exclusively in Chinese, including mandatory login disclaimers and command guidance. Because the file does not offer an opt-in language choice or explain that the skill is intentionally limited to a Chinese-speaking audience, it may violate language/locale policy requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file presents the skill instructions and command reference entirely in Chinese, beginning with the title and continuing throughout the document. Because the file does not offer any language choice or opt-in, it can violate a language/locale policy that requires user-selectable language behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

Requiring login through bash scripts/login.sh introduces general shell-script execution into a skill whose main purpose is file management. Even if intended for a safer auth flow, this widens the attack surface because agents may be induced to run local scripts rather than a narrowly scoped tool interface.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented uninstall capability deletes authentication state, configuration, and the installed binary, which exceeds the declared scope of a cloud-storage file-management skill. In an agent setting, exposing destructive host-level lifecycle operations increases the chance of unintended denial of service or misuse beyond user-requested file actions.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 573)May include surrounding context.

}

text

### mv/cp/rename/mkdir 命令输出

```json
{

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · reference/bdpan-commands.md (reported line 573)May include surrounding context.

}

text

### mv/cp/rename/mkdir 命令输出

```json
{

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples normalize uploading, sharing, and transferring files to/from Baidu Netdisk without any confirmation step or privacy warning, even though these actions can expose sensitive local data or import untrusted external content. In an agent skill context, example-driven behavior strongly influences how the agent operates, so omission of safeguards can lead to accidental data disclosure or unsafe handling of third-party files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file-management and backup examples include state-changing operations such as move, copy, rename, mkdir, and cleanup of temporary backup artifacts, but they do not instruct the agent to warn the user about write/destructive effects or confirm risky actions. In practice, this can cause unintended overwrites, remote reorganization, or loss of local temporary data, especially when an autonomous agent follows examples literally.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

该故障排除文档几乎全部以中文编写,并在示例与说明中默认中文输出,但未说明这是面向特定中文区域用户的限定文档,也未提供其他语言选项。按规则,强制特定语言而无用户选择或明确合理性说明,属于自然语言层面的语言/locale 策略问题。

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 303)May include surrounding context.

安装所需依赖(特定于发行版):

bash
# Debian/Ubuntu
sudo apt-get install libc6

# Fedora/RHEL
sudo dnf install glibc

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 306)May include surrounding context.

安装所需依赖(特定于发行版):

bash
# Debian/Ubuntu
sudo apt-get install libc6

# Fedora/RHEL
sudo dnf install glibc

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · reference/troubleshooting.md (reported line 347)May include surrounding context.

bash
# 检查配置文件是否存在及权限
ls -la ~/.config/bdpan/

# 检查登录状态和 Token 有效期
bdpan whoami

Static analysis

No suspicious patterns detected.