Back to skill

Security audit

Mulerouter

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent media-generation API wrapper, but it needs Review because its local-file upload and custom-endpoint handling can expose sensitive files or API credentials if misused or attacker-influenced.

Install only if you trust the workspace and understand that prompts, media, and the API key go to MuleRouter, MuleRun, or any custom endpoint you configure. Avoid custom base URLs unless you control them, do not run it in directories with untrusted .env files, keep the API key out of source control, and only pass explicit non-sensitive image files as image inputs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
core/image.py:43
Finding

Arbitrary Local File Disclosure Through Image Parameters

Content
View full analysis
bool: """Check if a string value is a local file path.""" if not isinstance(value, str): return False if value.startswith(("http://", "https://", "data:")): return False path = Path(value) return path.exists() and path.is_file() def file_to_base64(file_path: str) -> str: """Convert a local file to base64 data URI. Args: file_path: Path to the local file Returns: Base64 data URI string (e.g., "data:image/png;base64,...") """ path = Path(file_path) mime_type, _ = mimetypes.guess_type(str(path)) if mime_type is None: mime_type = "image/png" with open(path, "rb") as f: data = base64.b64encode(f.read()).decode("utf-8") return f"data:{mime_type};base64,{data}" ``` ```python def convert_image_value(value: Any) -> Any: """Convert image parameter value, handling local file paths. Args: value: Parameter value (string or list of strings) Returns: Converted value with local files as base64 data URIs """ if isinstance(value, str): if is_local_file(value): return file_to_base64(value) return value elif isinstance(value, list): return [convert_image_value(v) for v in value] return value ``` ```python def process_image_params(body: dict[str, Any]) -> dict[str, Any]: """Process request body, converting local file paths to base64. Args: body: Request body dictionary Returns: Processed body with image params converted """ result = body.copy() for key in IMAGE_PARAM_NAMES: if key in result: result[key] = conver ...[truncated 2726 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
core/config.py:105
Finding

Bearer Credential and Media Disclosure Through Unrestricted Custom API Endpoints

Content
View full analysis
httpx.Client: """Lazy-initialize and return HTTP client.""" if self._client is None: self._client = httpx.Client( base_url=self.config.base_url, timeout=httpx.Timeout(self.config.timeout), headers={ "Authorization": f"Bearer {self.config.api_key}", "Content-Type": "application/json", "User-Agent": USER_AGENT, "X-Agent-Sk ...[truncated 2885 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (36)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a full media-generation/editing skill supporting text-to-image, image-to-image, text-to-video, image-to-video, and video editing workflows. However, the supplied code chunk contains only configuration management utilities. It loads environment variables, validates site/base URL selection, requires an API key, and returns configuration data. There is no code for generating, editing, uploading, transforming, or downloading images/videos, nor any calls to MuleRouter/MuleRun endpoints. While configuration code could support such a skill, this chunk by itself does not actually implement the declared primary functionality, so the description does not accurately represent the behavior of the supplied code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description promises an operational multimodal generation/editing skill. However, this code chunk is purely infrastructural: it stores metadata about model endpoints and supports registration/querying of those endpoints. While such a registry could support the declared skill as an internal component, this chunk by itself does not perform the claimed core behavior. Therefore, the supplied code does not accurately represent the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The declared description presents a full-featured multimodal media generation/editing skill spanning multiple APIs and models. The actual code chunk is only package initialization logic that dynamically imports one endpoint module for registration. This is materially narrower and different from the declared purpose. While this snippet may be part of a larger implementation, based on the supplied code alone, the description overstates the demonstrated behavior and references external APIs and capabilities not present here.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill generates and edits images/videos using MuleRouter or MuleRun multimodal APIs. However, the supplied code does not perform any generation, editing, transformation, or API inference calls. Its primary function is administrative/discovery: loading provider model registrations and listing available models/providers from a registry, optionally filtered by site/provider/output type. This is a materially different purpose from the declared end-user media-generation functionality, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill generates and edits images/videos using AI models via MuleRouter/MuleRun. However, the provided code does not implement or exercise any media-generation behavior. It only tests configuration logic for API keys, site/base URL selection, environment-variable loading, validation, and help text. This is a materially different primary purpose from the declared multimedia functionality, so the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a multimodal generation/editing skill for images and videos using external APIs. The actual code chunk contains only tests for a registry system that stores and filters model endpoint metadata. While the test data references image output and 'mulerouter' availability, that is only metadata used in unit tests and does not implement the advertised functionality. This is a material mismatch in primary purpose and actual capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says the skill generates and edits images/videos through multimodal APIs. However, the supplied code does not perform any media generation, editing, API invocation, or transformation. It is only test code for a core task module that interprets asynchronous task responses and statuses such as pending, completed, succeeded, and failed. While the tests reference image/video result URLs, that is incidental to parsing response payloads and does not implement the declared multimedia functionality. Therefore the code chunk's primary purpose is materially different from the declared purpose.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

The documentation instructs users to place API keys in a plaintext .env file in the working directory. While common, this increases the chance of accidental exposure through source control, directory sharing, backups, or other local tooling in agent environments that may inspect workspace files.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

export MULEROUTER_API_KEY="your-api-key"

text

**Option C: Create .env file**

Create `.env` in the current working directory:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 58)May include surrounding context.

python
if env_file:
        load_dotenv(env_file)
    else:
        env_path = Path(".env")
        if env_path.exists():
            load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_config.py (reported line 148)May include surrounding context.

python
if env_file:
        load_dotenv(env_file)
    else:
        env_path = Path(".env")
        if env_path.exists():
            load_dotenv(env_path)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

*Either MULEROUTER_BASE_URL or MULEROUTER_SITE must be set.

.env File Example

env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

*Either MULEROUTER_BASE_URL or MULEROUTER_SITE must be set.

.env File Example

env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 50)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 53)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 86)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 93)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 101)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 153)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 154)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 156)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 160)May include surrounding context.

python
*Either `MULEROUTER_BASE_URL` or `MULEROUTER_SITE` must be set.

### .env File Example

```env
# Option 1: Use custom base URL (takes priority)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/REFERENCE.md (reported line 15)May include surrounding context.

*Either MULEROUTER_BASE_URL or MULEROUTER_SITE must be set.

.env File Example

env
# Option 1: Use custom base URL (takes priority)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill advertises and instructs use of environment-variable access and outbound network/API usage, but declares no explicit tool scope or permissions. In an agent setting, this can cause overbroad execution authority and make it harder for reviewers or policy layers to constrain secret access and external data transmission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation encourages passing local image files or remote image URLs to an external API, but does not clearly warn that the content will be transmitted off-system to third-party infrastructure. In a multimodal skill, this creates a meaningful privacy and data-handling risk, especially if users provide sensitive local media.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This endpoint is explicitly designed to accept user-supplied image and video URLs and send them to Alibaba's external generation API, but the file shows no mechanism to inform users that referenced media may be transmitted to a third party. That creates a real privacy and data-handling risk, especially if users provide private or internal URLs, sensitive media, or signed links under the assumption processing is local or first-party only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.