Back to skill

Security audit

Cloudinary Cli

Security checks for vulnerabilities and agentic risk

Overview

The skill is plausibly for Cloudinary uploads, but it builds/runs unreviewed local project code and stores Cloudinary API secrets in a plaintext project file without adequate controls.

Install only if you trust and have inspected the local ./cmd/cli Go project that this skill will build and run. Prefer a secret manager or ephemeral environment variables; if you use cmd/cli/.env, keep it out of version control, restrict permissions to the current user, and rotate the Cloudinary API secret if it may have been shared or committed.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/upload.sh:32
Finding

Unsafe dotenv parsing permits uncontrolled environment injection and credential exposure

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:22
Finding

Cloudinary API secret is directed to a predictable plaintext project file without required access controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The documented behavior claims the skill uploads files to Cloudinary, but the provided workflow first installs/builds a local Go-based CLI and the analyzed content does not substantiate the advertised network/upload behavior. This kind of description-behavior mismatch is dangerous because users may authorize local build/execution and credential entry under false assumptions, increasing the chance of unintended code execution or secret exposure.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/upload.sh (reported line 16)May include surrounding context.

sh
fi

CLI_BIN="$PROJECT_ROOT/cloudinary-cli"
ENV_FILE="$PROJECT_ROOT/cmd/cli/.env"

if [ ! -f "$CLI_BIN" ]; then
    echo "CLI not found. Running installer..."

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases include broad generic language such as common image-upload wording, which can cause the skill to activate in situations the user did not specifically intend. Unintended invocation is risky here because activation can lead to installation steps, credential prompts, and execution of local scripts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs storing Cloudinary API credentials, including the secret, in a local .env file without warning about secret-handling risks, file permissions, or persistence. This is dangerous because secrets may be left on disk, accidentally committed, read by other local processes, or exposed through logs and workspace sharing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code file reads and exports sensitive credentials, including CLOUDINARY_KEY and CLOUDINARY_SECRET, from a local .env file and then invokes a CLI that will use them. While the script documents which variables are required, it does not provide any warning or disclosure that sensitive credentials are being loaded and used, which is the kind of operation this rule covers.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.