Back to skill

Security audit

check-ai-credits

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed read-only balance checker that uses local provider credentials to query AI billing endpoints and keeps an optional local trend log.

Install only if you are comfortable letting the skill read AI provider API keys, Codex/Grok CLI auth files, and CodexBar usage data to check balances. Use --no-log if you do not want balance snapshots written locally for trend history.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (55)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Even if implementation details are not visible here, the skill text states it reads environment variables and .env files to resolve credentials while declaring no tool scope. That combination is security-relevant because users may invoke a seemingly simple balance tool without being warned it performs local secret discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Even if implementation details are not visible here, the skill text states it reads environment variables and .env files to resolve credentials while declaring no tool scope. That combination is security-relevant because users may invoke a seemingly simple balance tool without being warned it performs local secret discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even if implementation details are not visible here, the skill text states it reads environment variables and .env files to resolve credentials while declaring no tool scope. That combination is security-relevant because users may invoke a seemingly simple balance tool without being warned it performs local secret discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
87% confidence
Finding

Even if implementation details are not visible here, the skill text states it reads environment variables and .env files to resolve credentials while declaring no tool scope. That combination is security-relevant because users may invoke a seemingly simple balance tool without being warned it performs local secret discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Even if implementation details are not visible here, the skill text states it reads environment variables and .env files to resolve credentials while declaring no tool scope. That combination is security-relevant because users may invoke a seemingly simple balance tool without being warned it performs local secret discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Even if implementation details are not visible here, the skill text states it reads environment variables and .env files to resolve credentials while declaring no tool scope. That combination is security-relevant because users may invoke a seemingly simple balance tool without being warned it performs local secret discovery.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Even if implementation details are not visible here, the skill text states it reads environment variables and .env files to resolve credentials while declaring no tool scope. That combination is security-relevant because users may invoke a seemingly simple balance tool without being warned it performs local secret discovery.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 63)May include surrounding context.

md
4. CodexBar CLI (macOS menu-bar app) for web-session providers
5. Interactive fallback: the tool prints the login URL and exits non-zero

Security rules baked into the code: OAuth access tokens are never refreshed or
rewritten (re-refreshing would rotate the CLI's own refresh token and log you
out), secrets are never echoed in any output mode, and there is no telemetry.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/check-ai-credits/README.md (reported line 63)May include surrounding context.

md
4. CodexBar CLI (macOS menu-bar app) for web-session providers
5. Interactive fallback: the tool prints the login URL and exits non-zero

Security rules baked into the code: OAuth access tokens are never refreshed or
rewritten (re-refreshing would rotate the CLI's own refresh token and log you
out), secrets are never echoed in any output mode, and there is no telemetry.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

This function is explicitly designed to access secrets from environment variables, which commonly include API keys and tokens. In an agent skill context, generic credential access is dangerous because any downstream code that can call this helper may extract unrelated secrets from the host runtime, not just the credits APIs needed for normal operation.

Content

Scanner excerpt · skills/check-ai-credits/src/core/env.ts (reported line 9)May include surrounding context.

ts
return process.env.HERMES_HOME ?? join(homedir(), ".hermes");
}

/** Read one key from the process env, then $HERMES_HOME/.env (never exported). */
export function hermesEnv(name: string): string | undefined {
  const fromProcess = Bun.env[name];
  if (fromProcess) return fromProcess;

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Reading $HERMES_HOME/.env directly expands the skill's reach beyond process-scoped configuration into local secret files, which may contain credentials for many unrelated services. This broad local file-based secret access materially increases the blast radius if the skill or a dependent module is abused, because secrets can be harvested from disk even when not exported into the process environment.

Content

Scanner excerpt · skills/check-ai-credits/src/core/env.ts (reported line 14)May include surrounding context.

ts
const fromProcess = Bun.env[name];
  if (fromProcess) return fromProcess;
  try {
    const lines = fs.readFileSync(join(hermesHome(), ".env"), "utf8").split("\n");
    for (const raw of lines) {
      const line = raw.trim();
      if (!line.startsWith(`${name}=`)) continue;

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The code path starting at this location establishes a mechanism to fetch secrets from runtime environment variables and a local private .env file. That is a credential access capability, and in an agent skill context it is dangerous because it allows the skill to consume locally stored API keys or tokens that may belong to multiple services, increasing blast radius if the skill is compromised or over-privileged.

Content

Scanner excerpt · src/core/env.ts (reported line 9)May include surrounding context.

ts
return process.env.HERMES_HOME ?? join(homedir(), ".hermes");
}

/** Read one key from the process env, then $HERMES_HOME/.env (never exported). */
export function hermesEnv(name: string): string | undefined {
  const fromProcess = Bun.env[name];
  if (fromProcess) return fromProcess;

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

This line reads $HERMES_HOME/.env directly from disk and parses out named entries, which is direct access to a private credential store. In the context of a credit-checking skill, that capability is especially sensitive because it can harvest API keys for many providers from a central file, and any downstream bug or malicious modification could expose them.

Content

Scanner excerpt · src/core/env.ts (reported line 14)May include surrounding context.

ts
const fromProcess = Bun.env[name];
  if (fromProcess) return fromProcess;
  try {
    const lines = fs.readFileSync(join(hermesHome(), ".env"), "utf8").split("\n");
    for (const raw of lines) {
      const line = raw.trim();
      if (!line.startsWith(`${name}=`)) continue;

Credential Access

High
Category
Privilege Escalation
Confidence
81% confidence
Finding

Although this specific line is in the error-handling/return path, it is part of the same secret-loading routine that silently attempts to read a private .env file. Silent fallback behavior can make credential access harder to audit and detect, increasing the chance that sensitive local secrets are consumed without clear user awareness.

Content

Scanner excerpt · src/core/env.ts (reported line 22)May include surrounding context.

ts
if (value) return value;
    }
  } catch {
    // .env missing or unreadable — treated as "not set"
  }
  return undefined;
}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.zh-CN.md (reported line 62)May include surrounding context.

md
tokens?: { access_token?: string; account_id?: string };
}

/** Read-only: the access token is used as-is; NEVER refreshed (refreshing would
 *  rotate the Codex CLI's own refresh token and log the user out). */
export const codexProvider: Provider = {
  id: "codex",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/check-ai-credits/README.zh-CN.md (reported line 62)May include surrounding context.

md
tokens?: { access_token?: string; account_id?: string };
}

/** Read-only: the access token is used as-is; NEVER refreshed (refreshing would
 *  rotate the Codex CLI's own refresh token and log the user out). */
export const codexProvider: Provider = {
  id: "codex",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/check-ai-credits/src/providers/codex.ts (reported line 23)May include surrounding context.

ts
tokens?: { access_token?: string; account_id?: string };
}

/** Read-only: the access token is used as-is; NEVER refreshed (refreshing would
 *  rotate the Codex CLI's own refresh token and log the user out). */
export const codexProvider: Provider = {
  id: "codex",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/providers/codex.ts (reported line 23)May include surrounding context.

ts
tokens?: { access_token?: string; account_id?: string };
}

/** Read-only: the access token is used as-is; NEVER refreshed (refreshing would
 *  rotate the Codex CLI's own refresh token and log the user out). */
export const codexProvider: Provider = {
  id: "codex",

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/check-ai-credits/src/core/env.ts (reported line 22)May include surrounding context.

ts
});

describe("hermesEnv", () => {
  test("reads from $HERMES_HOME/.env when not in process env", () => {
    delete process.env.CAIC_TEST_KEY_DO_NOT_USE;
    fs.writeFileSync(path.join(tmp, ".env"), `${KEY}="from-file-value"\nOTHER=1\n`, "utf8");
    process.env.HERMES_HOME = tmp;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/check-ai-credits/test/env.test.ts (reported line 16)May include surrounding context.

ts
});

describe("hermesEnv", () => {
  test("reads from $HERMES_HOME/.env when not in process env", () => {
    delete process.env.CAIC_TEST_KEY_DO_NOT_USE;
    fs.writeFileSync(path.join(tmp, ".env"), `${KEY}="from-file-value"\nOTHER=1\n`, "utf8");
    process.env.HERMES_HOME = tmp;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/check-ai-credits/test/env.test.ts (reported line 23)May include surrounding context.

ts
});

describe("hermesEnv", () => {
  test("reads from $HERMES_HOME/.env when not in process env", () => {
    delete process.env.CAIC_TEST_KEY_DO_NOT_USE;
    fs.writeFileSync(path.join(tmp, ".env"), `${KEY}="from-file-value"\nOTHER=1\n`, "utf8");
    process.env.HERMES_HOME = tmp;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · skills/check-ai-credits/test/env.test.ts (reported line 33)May include surrounding context.

ts
});

describe("hermesEnv", () => {
  test("reads from $HERMES_HOME/.env when not in process env", () => {
    delete process.env.CAIC_TEST_KEY_DO_NOT_USE;
    fs.writeFileSync(path.join(tmp, ".env"), `${KEY}="from-file-value"\nOTHER=1\n`, "utf8");
    process.env.HERMES_HOME = tmp;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test/env.test.ts (reported line 16)May include surrounding context.

ts
});

describe("hermesEnv", () => {
  test("reads from $HERMES_HOME/.env when not in process env", () => {
    delete process.env.CAIC_TEST_KEY_DO_NOT_USE;
    fs.writeFileSync(path.join(tmp, ".env"), `${KEY}="from-file-value"\nOTHER=1\n`, "utf8");
    process.env.HERMES_HOME = tmp;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test/env.test.ts (reported line 23)May include surrounding context.

ts
});

describe("hermesEnv", () => {
  test("reads from $HERMES_HOME/.env when not in process env", () => {
    delete process.env.CAIC_TEST_KEY_DO_NOT_USE;
    fs.writeFileSync(path.join(tmp, ".env"), `${KEY}="from-file-value"\nOTHER=1\n`, "utf8");
    process.env.HERMES_HOME = tmp;

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · test/env.test.ts (reported line 33)May include surrounding context.

ts
});

describe("hermesEnv", () => {
  test("reads from $HERMES_HOME/.env when not in process env", () => {
    delete process.env.CAIC_TEST_KEY_DO_NOT_USE;
    fs.writeFileSync(path.join(tmp, ".env"), `${KEY}="from-file-value"\nOTHER=1\n`, "utf8");
    process.env.HERMES_HOME = tmp;

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
skills/check-ai-credits/src/core/codexbar.ts:11

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/core/codexbar.ts:11