Back to skill

Security audit

Bbs Bot

Security checks for vulnerabilities and agentic risk

Overview

This forum skill is mostly coherent, but it handles real account credentials and public posting with several under-protected flows that users should review before installing.

Install only if you are comfortable giving the skill access to a real forum account. Avoid using command-line passwords, do not run the quick-start example against a public forum without reviewing it, protect ~/.bbsbot/config.json, and do not use custom baseUrl values unless you fully trust the endpoint. Treat the config command output as sensitive until secrets are redacted.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
src/api/client.js:10
Finding

Credentials and Bearer Tokens Can Be Sent to Arbitrary or Plaintext Endpoints

Content
View full analysis
{ if (this.token) { config.headers.Authorization = `Bearer ${this.token}`; } return config; }, (error) => Promise.reject(error) ); } ``` ```javascript // src/api/client.js:68-90 async register(userData) { const response = await this.client.post('/auth/register', userData); // Save token if provided in response if (response.token) { this.token = response.token; } return response; } async login(credentials) { const response = await this.client.post('/auth/login', credentials); // Save token if (response.token) { this.token = response.token; } return response; } ``` ```javascript // src/utils/config.js:35-62 const envMappings = { BBS_BOT_BASE_URL: 'baseUrl', BBS_BOT_USERNAME: 'username', BBS_BOT_PASSWORD: 'password', BBS_BOT_EMAIL: 'email', BBS_BOT_DISPLAY_NAME: 'displayName', BBS_BOT_TOKEN: 'token', BBS_BOT_TIMEOUT: 'timeout', BBS_BOT_RETRY_ATTEMPTS: 'retryAttempts', BBS_BOT_RETRY_DELAY: 'retryDelay' }; for (const [envVar, configKey] of Object.entries(envMappings)) { if (process.env[envVar]) { // Convert string to number for numeric ...[truncated 3516 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
index.js:201
Finding

Configuration Command Discloses Passwords and Authentication Tokens

Content
View full analysis
{ console.log('Current configuration:'); console.log(JSON.stringify(config, null, 2)); }); ``` ```javascript // src/utils/config.js:35-62 const envMappings = { BBS_BOT_BASE_URL: 'baseUrl', BBS_BOT_USERNAME: 'username', BBS_BOT_PASSWORD: 'password', BBS_BOT_EMAIL: 'email', BBS_BOT_DISPLAY_NAME: 'displayName', BBS_BOT_TOKEN: 'token', BBS_BOT_TIMEOUT: 'timeout', BBS_BOT_RETRY_ATTEMPTS: 'retryAttempts', BBS_BOT_RETRY_DELAY: 'retryDelay' }; for (const [envVar, configKey] of Object.entries(envMappings)) { if (process.env[envVar]) { // Convert string to number for numeric values if (['timeout', 'retryAttempts', 'retryDelay'].includes(configKey)) { config[configKey] = parseInt(process.env[envVar], 10); } else { config[configKey] = process.env[envVar]; } } } ``` ### Technical Analysis The `config` command serializes and prints the complete merged configuration object. That object can contain a plaintext `password` loaded from the configuration file or `BBS_BOT_PASSWORD`, as well as a bearer token loaded from the file or `BBS_BOT_TOKEN`. No redaction or field filtering is applied before writing the data to standard output. Although `saveConfig()` removes passwords before programmatic writes, the documentation permits manually storing a password in the configuration file, and environment-based passwords are included in the in-memory configuration. Tokens are intentionally persisted and are also printed without masking. Terminal output can be captured by CI systems, shell transcripts, support logs, monitoring tools, or an AI Agent's command/tool history. This creates a ...[truncated 1022 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:25
Finding

Passwords Are Accepted and Documented as Command-Line Arguments

Content
View full analysis
', 'Username') .requiredOption('-e, --email ', 'Email address') .requiredOption('-p, --password ', 'Password') ``` ```javascript // index.js:48-56 program .command('login') .description('Login and get token') .requiredOption('-u, --username ', 'Username or email') .requiredOption('-p, --password ', 'Password') .action(async (options) => { try { const result = await apiClient.login({ identifier: options.username, password: options.password }); ``` ```bash # SKILL.md:53-56 bbsbot register --username testuser --email test@example.com --password pass123 --name "测试用户" # 登录 bbsbot login --username testuser --password pass123 ``` ```json // manifest.json:74-75 "bbsbot register --username ai_assistant --email ai@example.com --password pass123 --name \"AI Assistant\"", "bbsbot login --username ai_assistant --password pass123", ``` ### Technical Analysis Both registration and login require the password to be supplied as a command-line option. Command-line arguments are unsuitable for secrets because they may be: - Stored in shell history. - Visible in process listings while the command is running. - Recorded by process-monitoring or endpoint-management software. - Captured in CI logs or automation diagnostics. - Preserved in Agent command histories. The Skill documentation and manifest explicitly encourage this usage. The network transmission of a password is required for password-based authentication, but exposing that password in local process metadata is unnecessary and ...[truncated 923 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
examples/quick-start.js:30
Finding

Quick-Start Example Automatically Registers an Account with Predictable Credentials

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
Findings (32)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 55)May include surrounding context.

  1. Set up development environment:
    bash
    cp .env.example .env
    # Edit .env with your configuration
    

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 56)May include surrounding context.

  1. Set up development environment:

    bash
    cp .env.example .env
    # Edit .env with your configuration
    
  2. Link the skill for development:

Self-Modification

High
Category
Rogue Agent
Confidence
85% confidence
Finding

Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.

Content

Scanner excerpt · CONTRIBUTING.md (reported line 106)May include surrounding context.

md
### Writing Documentation
- Update README.md for user-facing changes
- Update SKILL.md for skill-specific documentation
- Add JSDoc comments for all functions and classes
- Include examples for new features
- Update CHANGELOG.md for all releases

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The configuration section instructs users to place usernames, passwords, and bearer tokens in environment variables and a local JSON file, but lacks a prominent warning about secret exposure. This is especially risky because both persistent plaintext credentials and reusable tokens can be harvested from config files, backups, environment dumps, support bundles, or misconfigured file permissions, enabling account compromise.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill is presented as a forum interaction skill, but the documentation also instructs reading and writing local configuration files in the user's home directory and persisting authentication tokens. This mismatch weakens user consent and security review because operators may approve a forum-posting skill without realizing it also handles local credential storage and filesystem modification.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 149)May include surrounding context.

md
- `POST /topics` - 创建帖子
- `GET /topics/{id}` - 获取帖子详情
- `PATCH /topics/{id}` - 更新帖子
- `DELETE /topics/{id}` - 删除帖子

### 回复相关 API
- `GET /posts` - 获取回复列表(可筛选)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 155)May include surrounding context.

md
- `GET /posts` - 获取回复列表(可筛选)
- `POST /posts` - 创建回复
- `PATCH /posts/{id}` - 更新回复
- `DELETE /posts/{id}` - 删除回复

## 使用示例

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The README promotes automation features such as scheduled tasks and auto-replying without clearly warning about spam, runaway posting loops, moderation violations, or accidental publication. In the context of a forum-posting skill, this increases the chance that users deploy unattended actions that can flood communities or post unintended content at scale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The registration and login examples demonstrate direct credential handling on the command line without warning that shell history, process listings, CI logs, or shared terminals can expose passwords. Because this skill operates on real accounts, unsafe example usage can lead to credential compromise and account takeover.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The README explicitly claims '密码加密存储' as a security feature, yet the documented example config stores both password and token in plaintext in ~/.bbsbot/config.json. This is dangerous because users may trust the security claim and persist secrets locally without applying OS-level protections, increasing the risk of credential theft from local compromise, backups, logs, or accidental file exposure.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill documents use of environment variables for credentials and token-based authentication, but the manifest declares no explicit tool scope or permissions. In an agent setting, missing scope declarations can cause the skill to access sensitive runtime environment data without clear review boundaries, increasing the chance of credential misuse or overbroad execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation exposes destructive delete operations for topics and posts without any warning that they are irreversible or should require confirmation. In an agent-driven workflow, this increases the risk of accidental or unsafe content deletion on a live external service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The examples automate account registration, posting, monitoring, and replying against a live external forum without warning that these actions will publish content under a real account. This can lead to spam, unwanted account creation, or accidental external actions when users or agents run copied examples verbatim.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
76% confidence
Finding

The skill documentation indicates persistence of login state and tokens in local configuration, which creates a reusable authenticated session on disk. If the file is stored insecurely, read by other local processes, or reused by unattended automation, an attacker could hijack the forum account and perform authenticated actions.

Content

Scanner excerpt · SKILL.md (reported line 288)May include surrounding context.

md
# 批量发布测试帖子
for i in {1..3}; do
    bbsbot topic create \
        --title "测试帖子 $i" \
        --content "这是第 $i 个测试帖子" \
        --category 2

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example automatically registers an account when credentials are absent and then persists the returned authentication token locally, without prominently warning the user that it will create an account and store authentication material on disk. In a skill setting, this can lead to unintended account creation, silent credential persistence, and later misuse of the saved token by other local processes or users if file protections are weak.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The example performs a real write operation by creating a public forum topic as part of a quick-start flow, with no explicit confirmation, dry-run mode, or strong warning that running the script will post publicly. In an agent-skill context, examples are often copied or executed directly, so this can cause unintended spam, reputational harm, or policy violations on the target forum.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The config command prints the entire loaded configuration object directly to stdout, which can expose sensitive values such as saved authentication tokens or other secrets to the terminal, logs, shell history capture tools, or calling processes. In a CLI skill that stores login state, this is a real information disclosure issue because users may invoke the command for debugging and unintentionally leak credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest presents user-facing descriptions in Chinese while other user-facing metadata is in English, but it does not state that the skill is region-specific or give users a language/locale option. This can violate a language/locale policy when a skill implicitly forces one language for part of the experience without opt-in.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The register method transmits user registration data to a remote endpoint, which may include personal or account information, but there is no visible confirmation, logging, or warning text in this file about that data transfer. This is a safety-relevant network operation involving user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The login method sends user-supplied credentials over the network via an HTTP POST, but this code provides no confirmation prompt, visible logging, or user-facing warning about transmitting sensitive authentication data. While network access is part of an API client, this file does not itself disclose that sensitive credentials will be sent to a remote service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
73% confidence
Finding

The description and the rest of the README consistently present the skill in Chinese, and examples use Chinese-language content and display names, but there is no statement that the skill is intentionally Chinese-only or that users can choose another language. This can be a locale-policy issue when a skill appears to assume a specific language without opt-in or justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
67% confidence
Finding

The natural-language instructions, labels, and examples are presented entirely in Chinese, and the document does not indicate that another language is supported or that Chinese is an optional locale. Per SQP-3, forcing a specific language without user opt-in can be a policy concern unless the locale restriction is clearly justified.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency uses a caret range instead of an exact pinned version, which allows different installs over time to resolve to different axios releases. This weakens build reproducibility and can unintentionally pull in a newly introduced vulnerable or compromised package version, especially important for a network-facing forum automation skill.

Content

Scanner excerpt · package.json (reported line 33)May include surrounding context.

json
},
  "homepage": "https://github.com/yourusername/bbs-bot-skill#readme",
  "dependencies": {
    "axios": "^1.6.0",
    "commander": "^11.0.0",
    "dotenv": "^16.3.0",
    "jsonwebtoken": "^9.0.0",

Unverifiable Dependency: axios has 16 known advisory(ies) (CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The commander dependency is specified with a version range rather than an exact version, so installations are not fully reproducible. While not an immediate exploitable flaw by itself, this increases supply-chain risk by allowing unreviewed upstream releases to be installed.

Content

Scanner excerpt · package.json (reported line 34)May include surrounding context.

json
"homepage": "https://github.com/yourusername/bbs-bot-skill#readme",
  "dependencies": {
    "axios": "^1.6.0",
    "commander": "^11.0.0",
    "dotenv": "^16.3.0",
    "jsonwebtoken": "^9.0.0",
    "yaml": "^2.3.0"

Static analysis

No suspicious patterns detected.