Back to skill

Security audit

Trakt

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward Trakt.tv helper, but users should be careful with the npm install and OAuth secret setup.

Install only if you trust the trakt-cli npm package and avoid running the install with elevated privileges. Prefer a safer secret-entry method if the CLI supports one, and check that ~/.trakt.yaml is readable only by your user account.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:18
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

OAuth Client Secret Passed Through Command-Line Arguments

Content
View full analysis
--client-secret ` 3. Visit the URL shown and enter the device code 4. Credentials saved to `~/.trakt.yaml` ``` ### Technical Analysis The setup procedure instructs users to place the Trakt OAuth client secret directly in a command-line argument. After placeholder substitution, the complete secret may be retained in shell history. Depending on the operating system and local monitoring configuration, process arguments may also be observable through process-listing utilities, audit systems, terminal capture, session recording, or diagnostic logs. The instructions additionally state that credentials are written to `~/.trakt.yaml`, but the audited file does not document restrictive permissions, encryption, or other storage protections. Because the CLI implementation is not included in the project, insecure file permissions cannot be confirmed; the verified issue is the explicit command-line handling of the client secret. ### Attack Path 1. The user creates a Trakt application and receives a client ID and client secret. 2. The user replaces the documented placeholders with the real values and executes the command. 3. The shell records the expanded command in its history, or a local process-monitoring, logging, or session-capture mechanism records its arguments. 4. Another local user, administrator, support-data recipient, or party with access to synchronized shell history retrieves the exposed secret. 5. The party uses the client credentials to impersonate or abuse the registered Trakt application, subject to Trakt's OAuth controls and any additional credentials required for user-level access. ### Impact Assessm ...[truncated 708 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.