Back to skill

Security audit

Bambu Printer

Security checks for vulnerabilities and agentic risk

Overview

This printer-control skill is not clearly malicious, but it packages a real printer credential and uses insecure FTPS for upload, download, and deletion.

Do not install this published version as-is. Rotate the exposed printer access code, remove credentials from the skill and script fallbacks, load secrets from a private local source, enable certificate validation or certificate pinning for FTPS, and add clear confirmation for delete operations before using it on a real printer.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
config.json:3
Finding

Hardcoded Printer Credentials Expose Administrative File Operations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ftp.sh:40
Finding

FTPS Server Authentication Is Disabled for All File Operations

Content
View full analysis
&1 ``` ```bash exec $CURL -T "$local_file" --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${remote_dir}${filename}" 2>&1 ``` ```bash exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" -o "$local_path" "${BASE_URL}${remote_path}" 2>&1 ``` ```bash exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" -Q "DELE $remote_path" "${BASE_URL}/" 2>&1 ``` ```bash $CURL -s --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${path}" 2>&1 | \ awk '/^-/{total += $5; count++} END {printf "File count: %d, total size: %.1f MB\n", count, total/1024/1024}' ``` ### Technical Analysis Every FTPS request passes curl's `--insecure` option. This disables validation of the server's TLS certificate, including certificate-chain and hostname verification. TLS encryption alone does not establish the identity of the remote server. Without peer verification, an active attacker in a suitable network position can present an arbitrary certificate and impersonate the printer. The client will accept that certificate and transmit the FTPS authentication credentials and operation data to the attacker's endpoint. This affects every supported operation: directory listing, upload, download, deletion, and size calculation. Download responses and directory listings can also be forged, while uploaded files and credentials can be captured. ### Attack Path 1. An attacker obtains a network interception position on the printer's LAN or another network segment between the Skill host and the printer. 2. The attacker redirects or intercepts traffic intended for `192.168.1.68:990`, such as through ARP spoofing, routing compromis ...[truncated 1221 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (15)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior does not accurately bound what the skill can do: it includes remote deletion, arbitrary upload/download, and incomplete implementation of stated status/timelapse features. This mismatch is dangerous because users or orchestration agents may grant trust based on a narrower description while the actual capability enables broader file manipulation on the printer.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill embeds a live printer IP, serial number, and access code directly in documentation, exposing credentials for a network-reachable device. Anyone with access to the skill can potentially connect to the printer over FTPS/MQTT, access files, or interfere with its operation, making this a clear secret disclosure issue.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Using curl --insecure disables TLS certificate validation for the FTPS connection, allowing a man-in-the-middle attacker on the network to impersonate the printer endpoint. Because the command also sends credentials, an attacker could intercept authentication data and tamper with file listings or other responses.

Content

Scanner excerpt · scripts/ftp.sh (reported line 37)May include surrounding context.

sh
list|ls)
    path="${1:-/}"
    [[ "$path" != /* ]] && path="/$path"
    exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${path}" 2>&1
    ;;

  upload|put)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Uploading with curl --insecure permits TLS interception and endpoint spoofing during file transfer. An attacker could capture printer credentials, alter uploaded print files in transit, or redirect uploads to a malicious service, which is especially risky in a 3D-printer control context where modified models/G-code can affect device behavior.

Content

Scanner excerpt · scripts/ftp.sh (reported line 50)May include surrounding context.

sh
fi
    filename=$(basename "$local_file")
    echo "⬆️ 上传 $filename 到 ${remote_dir}..."
    exec $CURL -T "$local_file" --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${remote_dir}${filename}" 2>&1
    ;;

  download|get)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Downloading with curl --insecure disables server authentication, so a network attacker can spoof the FTPS server and supply malicious or falsified files. This can expose credentials and result in untrusted files being written locally, increasing risk if those files are later opened or used in downstream workflows.

Content

Scanner excerpt · scripts/ftp.sh (reported line 62)May include surrounding context.

sh
local_path="$local_path/$filename"
    fi
    echo "⬇️ 下载 $remote_path 到 $local_path..."
    exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" -o "$local_path" "${BASE_URL}${remote_path}" 2>&1
    echo "✅ 下载完成: $local_path"
    ;;

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Issuing delete commands over an FTPS session with --insecure allows a man-in-the-middle attacker to impersonate the printer and influence or observe destructive operations while harvesting credentials. In this skill context, the command is destructive, so spoofed or intercepted sessions can lead to unauthorized file deletion or misdirected operator actions.

Content

Scanner excerpt · scripts/ftp.sh (reported line 70)May include surrounding context.

sh
remote_path="${1:?需要指定远程文件路径}"
    [[ "$remote_path" != /* ]] && remote_path="/$remote_path"
    echo "🗑️ 删除 $remote_path"
    exec $CURL -s --insecure --connect-timeout 10 -u "$AUTH" -Q "DELE $remote_path" "${BASE_URL}/" 2>&1
    ;;

  size|info)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Even for size/info operations, curl --insecure enables server spoofing and credential interception because the client no longer authenticates the FTPS endpoint. An attacker can falsify inventory information, mislead operators about printer contents, and obtain access credentials for later abuse.

Content

Scanner excerpt · scripts/ftp.sh (reported line 76)May include surrounding context.

sh
size|info)
    path="${1:-/}"
    [[ "$path" != /* ]] && path="/$path"
    $CURL -s --insecure --connect-timeout 10 -u "$AUTH" "${BASE_URL}${path}" 2>&1 | \
      awk '/^-/{total += $5; count++} END {printf "文件数: %d, 总大小: %.1f MB\n", count, total/1024/1024}'
    ;;

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents direct shell-based execution (bash, perl, curl) but does not declare any tool scope or allowed-tools restrictions. That creates an unnecessary trust gap: an agent may invoke broad shell access to operate on files and network resources without an explicit permission boundary, increasing the chance of misuse or unintended command execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The natural-language content of the skill is entirely in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-speaking or region-specific context. Per SQP-3, forcing a specific language without user opt-in is a policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown describes a delete operation against remote printer files, but it provides no warning that the action can remove files from the device and may be irreversible. Under SQP-2 for markdown files, behaviors affecting user data or system integrity should be accompanied by explicit warnings.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
77% confidence
Finding

The manifest describes a printer-control skill focused on Bambu P1S file management, connection status, and timelapse access. Line L22 states that operations are performed through generic system tools such as curl, perl, and ruby, which introduces broader execution-capable dependencies not justified by the stated purpose in this file's documented intent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The file embeds user-facing descriptions and operational messages in Chinese, starting with the header comments and continuing through help output. Because the skill does not provide an opt-in language choice or indicate that it is intentionally limited to Chinese users, this is a natural-language locale policy issue.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Manifest 说明提到“文件管理(FTPS)”、文件列表、上传下载 gcode/3mf 文件和查看延时摄影,但未提及删除远程文件。此脚本额外提供 delete/rm/del 并执行 FTPS DELE 操作,属于比描述更具破坏性的能力扩展。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The help text shown to users is exclusively in Chinese, which forces a specific language for interaction. Under the policy, language restrictions should either be optional for the user or clearly justified as a region-specific constraint.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The natural-language note is written only in Chinese, which imposes a specific language on users without offering any language choice or documenting a justified locale restriction. This matches the policy category for language or locale violations in natural-language content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.