Back to skill

Security audit

Plex

Security checks for vulnerabilities and agentic risk

Overview

This is a simple Plex command reference that uses a Plex token as expected, but users should prefer HTTPS and avoid exposing the token in URLs where possible.

Install only if you are comfortable giving the agent access to your Plex server. Configure PLEX_SERVER with HTTPS where available, keep PLEX_TOKEN private, consider using the X-Plex-Token header instead of a query string, and revoke the token if it may have been exposed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:11
Finding

Plex authentication token exposed through plaintext transport and URL query parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:11, 19, 24, 30, 35, 40, 45, 50, 55
Vulnerability Type: Credential exposure through insecure transport and query-string authentication
Risk Level: Medium

Vulnerable Code

bash
# SKILL.md:11
- `PLEX_SERVER`: Your Plex server URL (e.g., `http://192.168.1.100:32400`)

# SKILL.md:19
curl -s "$PLEX_SERVER/?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

# SKILL.md:24
curl -s "$PLEX_SERVER/library/sections?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

# SKILL.md:30
curl -s "$PLEX_SERVER/library/sections/1/all?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

# SKILL.md:35
curl -s "$PLEX_SERVER/search?query=SEARCH_TERM&X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

# SKILL.md:40
curl -s "$PLEX_SERVER/library/recentlyAdded?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

# SKILL.md:45
curl -s "$PLEX_SERVER/library/onDeck?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

# SKILL.md:50
curl -s "$PLEX_SERVER/status/sessions?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

# SKILL.md:55
curl -s "$PLEX_SERVER/clients?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"

Technical Analysis

The documented configuration explicitly permits an unencrypted http:// Plex server URL. Every documented API request also expands the sensitive PLEX_TOKEN environment variable directly into the request URL as the X-Plex-Token query parameter.

If HTTP is used, the authentication token and returned Plex data are transmitted without transport encryption. An attacker with visibility into the local network, a compromised gateway, or a malicious proxy can inspect the request and recover the token. Such an attacker may also alter responses in transit.

Even when HTTPS is used, placing credentials in a query string increases their exposure. Complete URLs can be retained by Plex access logs, re ...[truncated 1630 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require PLEX_SERVER to use https:// and reject plaintext HTTP endpoints before making requests.
  2. Keep TLS certificate verification enabled. Do not introduce curl -k or --insecure.
  3. Send the token through Plex's authentication header instead of the URL query string:
    bash
    curl --fail-with-body --silent --show-error \
      -H "Accept: application/json" \
      -H "X-Plex-Token: $PLEX_TOKEN" \
      "$PLEX_SERVER/library/sections"
    
  4. Where local process-argument confidentiality is required, avoid placing the token directly in command-line arguments. Use a permission-restricted curl configuration or another secret-injection mechanism that does not expose the token in the process command line.
  5. Validate PLEX_SERVER against an explicit set of trusted HTTPS hosts to reduce accidental token disclosure to an attacker-controlled endpoint.
  6. Ensure reverse proxies and application logs do not record authentication headers or sensitive query parameters.
  7. Store PLEX_TOKEN only in a protected secret store or environment with appropriately restricted access. Never print it in logs or diagnostic output.
  8. Revoke and rotate any token that may previously have been transmitted over plaintext HTTP or retained in URL logs.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.