Back to skill

Security audit

MuleRouter

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated media-generation purpose, but it can send the user's API key and uploaded media to an arbitrary configured endpoint without host or HTTPS validation.

Review this skill before installing. Use MULEROUTER_SITE=mulerouter or MULEROUTER_SITE=mulerun, avoid custom MULEROUTER_BASE_URL values unless you fully trust the endpoint, and only pass local image paths you intentionally want uploaded.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
core/config.py:109
Finding

API Credentials and Media Data Can Be Transmitted to an Untrusted or Cleartext Endpoint

Content
View full analysis
httpx.Client: """Lazy-initialize and return HTTP client.""" if self._client is None: self._client = httpx.Client( base_url=self.config.base_url, timeout=httpx.Timeout(self.config.timeout), headers={ "Authorization": f"Bearer {self.config.api_key}", "Content-Type": "application/json", "Us ...[truncated 3094 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
core/image.py:87
Finding

Extension-Only Image Validation Allows Arbitrary Local File Content to Be Uploaded

Content
View full analysis
str ...[truncated 3446 chars]
Remediation
View remediation
MAX_IMAGE_BYTES: raise ValueError("Image exceeds the maximum allowed size.") ``` 3. Restrict local-file access to explicit user-approved roots or require confirmation showing the normalized path before uploading. 4. Continue resolving symlinks before authorization checks, but replace broad string-prefix logic with `Path.relative_to()`-based containment checks. 5. Prefer an allowlist of upload directories over an expanding denylist of sensitive directories. 6. Open files defensively and, where supported, mitigate time-of-check/time-of-use and symlink replacement races. 7. Add tests for: - Non-image content carrying `.png` or `.jpg` suffixes. - Oversized files. - Symlinks into sensitive locations. - Files outside approved upload roots. - Valid images whose extension does not match their detected content type. ]]>
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a multimodal generation/editing skill that can create or transform images and videos using specific APIs and models. The actual code chunk is purely infrastructural: it defines enums and dataclasses for model metadata and a singleton registry for registering and listing endpoints. There is no execution of generation tasks, no request construction, no media transformation logic, and no external API access. This is a materially different primary purpose from the declared one, so the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The declared description presents a user-facing multimodal generation/editing skill covering multiple capabilities and providers. The supplied code chunk, however, is only package initialization code that dynamically imports one model file for registration. While importing sora2/generation.py may support a larger system related to video generation, this chunk itself does not implement the declared media-generation behavior or the stated MuleRouter/MuleRun integrations. That makes the observed behavior materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents this skill as an image/video generation and editing capability using multimodal APIs. However, the supplied code does not generate, edit, or transform any media, nor does it call model inference endpoints. Its primary function is inventory/inspection of registered models: importing provider packages so they register themselves, loading environment settings, filtering registry entries, and printing available models or providers. This is a materially different primary purpose from the declared behavior, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents an AI media generation/editing skill, but the provided code only exercises configuration logic for API keys, site selection, base URL precedence, environment variable loading, and validation behavior. This is not merely a supporting implementation detail of the advertised functionality; the chunk’s actual purpose is configuration testing, with no media processing, no API invocation for generation/editing, and no image/video capabilities present. Therefore the description does not accurately represent this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose centers on multimodal media generation/editing via external APIs, but the provided code only contains tests for helper functions that sanitize image paths and convert local image files into base64 data URIs. While such helpers could support an image-generation pipeline, the chunk itself does not implement or exercise generation, editing, video handling, model selection, or API calls to MuleRouter/MuleRun. The actual behavior is an image input preprocessing/security utility test suite, not a media generation skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill generates or edits images and videos using multimodal APIs. However, the supplied code is only test code for a registry component. It validates internal data structures and registration/query behavior for model endpoints; there is no implementation of generation, transformation, editing, or outbound API usage. This is a materially different primary purpose, so the description does not accurately represent the code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a skill whose main function is generating and editing images/videos through multimodal APIs. However, the provided code is only a test module for core.task behavior. It validates task status enums and parsing of API-like responses, including image/video result URLs, but does not itself perform media generation, editing, transformation, or API invocation. This is a materially different primary purpose, so the description does not accurately represent the supplied code chunk.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
92% confidence
Finding

This file implements outbound HTTP networking via httpx.Client, including authentication headers and configurable base_url, but the only reported control context is that this network capability is not covered by declared permissions. In an agent-skill environment, undeclared network access is security-relevant because it can enable unexpected external communication, data exfiltration, or calls to attacker-controlled endpoints if configuration is manipulated.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
75% confidence
Finding

The skill uses 'env' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 10)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 53)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 56)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 59)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 94)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 101)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 109)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 161)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 162)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 164)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/config.py (reported line 168)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/image.py (reported line 73)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/image.py (reported line 95)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · core/image.py (reported line 97)May include surrounding context.

python
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/REFERENCE.md (reported line 15)May include surrounding context.

md
from dotenv import dotenv_values

# Only load environment variables with this prefix from .env files
_ENV_PREFIX = "MULEROUTER_"

Lp1

High
Category
MCP Least Privilege
Confidence
55% confidence
Finding

The skill uses 'file_write' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.