Back to skill

Security audit

reCameraV2

Security checks for vulnerabilities and agentic risk

Overview

This documentation-only skill is coherent with reCamera administration, but it gives agents broad device-management, network-scanning, credential-handling, terminal, and destructive-action guidance without enough safety scoping.

Install only if you intend to let an agent administer reCamera devices. Before use, restrict it to devices and subnets you own or are authorized to manage, prefer HTTPS for all authenticated traffic, avoid exposing tokens in scripts or browser JavaScript, and require explicit confirmation before rebooting, resetting, formatting storage, deleting files/models, upgrading firmware, or opening terminal access.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:32
Finding

Reusable Authentication Token Transmitted Over Plaintext HTTP

Content
View full analysis
"}') TOKEN=$(echo "$RESPONSE" | grep -oP 'Set-Cookie:.*token=\K[^;]+') # ALL subsequent requests must carry the token cookie curl -s -X GET http://{ip}/cgi-bin/entry.cgi/system/device-info \ -H "Cookie: token=$TOKEN" ``` The unsafe requirement is also reinforced by `API_REFERENCE.md:47`, which directs clients to reuse the JWT cookie without requiring TLS: ```text On success, the response header includes `Set-Cookie` with the JWT token. All subsequent requests must include `Cookie: token={jwt_token}`. ``` ### Technical Analysis The Skill logs in and sends subsequent authenticated requests using unencrypted `http://` connections. Although the login password is RSA-encrypted, the returned JWT is a reusable bearer credential. Possession of the token is sufficient to authenticate, so application-layer encryption of the password does not protect the session after login. An attacker capable of observing local network traffic can read the `Set-Cookie` response or a later `Cookie: token=...` request and replay the token. An active network attacker could also modify plaintext responses or requests. The browser guidance at `SKILL.md:43-45` additionally recommends checking `document.cookie` for the token. This assumes that the authentication cookie is script-readable rather than `HttpOnly`, increasing exposure if the device web interface contains a cross-site scripting vulnerability. ### Attack Path 1. A user or agent follows the Skill and logs in to a reCamera device over plaintext HTTP. 2. An attacker obtains a network-adjacent position, such as access ...[truncated 1609 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill lists destructive operations such as reboot, factory reset, storage control/formatting, and model deletion as routine API actions without strong cautionary language or confirmation requirements. In an autonomous agent setting, this creates a real risk of accidental service disruption, data loss, or irreversible device state changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown API reference describes reboot and factory-reset endpoints, including the reset confirmation flow, but it does not warn users that reboot interrupts service and factory reset may irreversibly erase configuration or user data. For markdown files, SQP-2 applies when behavior affecting user data or system integrity is described without an explicit warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The storage control section documents FORMAT and REMOVE_FILES_OR_DIRECTORIES actions, which are destructive and can permanently delete user data, but the markdown does not include a clear warning about irreversible data loss. Under SQP-2 for markdown files, destructive behaviors should be disclosed explicitly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

  1. Extract token from response: On success (iStatus: 0, iAuth: 1), the HTTP response contains a Set-Cookie header like Set-Cookie: token=<jwt_value>; Path=/; .... You MUST capture the token value from this header.
  2. Persist token for session: Store the extracted token value. All subsequent HTTP requests for this session must include the header: Cookie: token=<jwt_value>

For curl / shell scripts:

bash
# Login and capture token from Set-Cookie header
RESPONSE=$(curl -s -D - -X POST http://{ip}/cgi-bin/entry.cgi/system/login \

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill goes beyond passive API documentation and prescribes active subnet-wide host discovery using ARP, ping sweeps, or nmap. That behavior can cause unauthorized network probing if invoked automatically by an agent, especially because the playbook frames scanning as a mandatory workflow rather than requiring explicit user confirmation and scope validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The device discovery workflow instructs subnet probing without any caution about authorization, network impact, or the fact that scanning may violate policy. In an agent context, omission of those guardrails increases the chance the skill will be used to probe networks the user does not own or intend to test.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting terminal and log WebSocket endpoints without warning about privilege, sensitive data exposure, or command execution risk is dangerous because these interfaces may provide shell access or reveal credentials, tokens, and system internals. In an agent skill, presenting them as ordinary endpoints can normalize unsafe use and lead to accidental remote administration or leakage.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The line explicitly says week display is always in English, which imposes a locale/language constraint with no opt-in, alternative, or documented justification. SQP-3 applies to natural-language policy violations across all file types, including markdown documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.