Back to skill

Security audit

Agent-to-Owner File Bridge

Security checks for vulnerabilities and agentic risk

Overview

This file-sharing skill is not clearly malicious, but it asks agents to run mutable external server code and expose a public upload bridge, so it should be reviewed carefully before installation.

Install only if you are comfortable with an agent sending selected workspace files to a server and, in autonomous mode, running external bridge code and opening a public tunnel. Prefer manual mode with your own HTTPS endpoint, provide the API key only through an authorization header or secure secret channel, avoid query-string keys and plain HTTP, confirm each exact file and destination before upload, and do not use the list or delete operations without explicit intent.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:68
Finding

Unpinned Remote Code Retrieval and Local Execution

Content
View full analysis
"To run the bridge server I will: (1) copy `server.py` from the open-source repo, (2) generate an API key and save it to `.env` in my workspace, (3) start the server on port 5000. May I proceed?" - Only proceed if the user says yes. **Step 3b — Get user confirmation before opening the tunnel:** > "To make the server reachable I will open a temporary public tunnel (via localtunnel or localhost.run). This creates a public URL pointing at my local port 5000. The link expires when my session ends. May I open the tunnel?" - Only proceed if the user says yes. - After tunnel is open, tell the user: *"The tunnel URL is [URL]. This link is temporary and will stop working when this session ends."* ``` The same behavior is reinforced in `api_instructions.txt`, lines 7-9: ```text 3. If the user wants you to host it, clone/copy server.py, run it, and expose it using a zero-auth free tunnel (e.g., `localtunnel` or `localhost.run`). ``` ### Technical Analysis The skill instructs the agent to copy executable `server.py` code from an external GitHub repository and run it locally. The project does not bundle the referenced server implementation, pin an immutable commit, specify a cryptographic digest, or require source verification before execution. Consequently, the effective code executed by the skill can change after the reviewed skill package has been published. The repository owner, a compromised repository account, or an attacker who compromises the upstream ...[truncated 1816 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
api_instructions.txt:17
Finding

API Credentials Permitted in Query Parameters and Form Fields

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
api_instructions.txt:22
Finding

Cleartext HTTP Permitted for API Credentials and File Uploads

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (11)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 7)May include surrounding context.

md
version: "3.0.2"
compatibility: "Requires: Python 3.8+ (autonomous mode only), pip, optionally Node.js for localtunnel. All autonomous-mode actions (server start, tunnel, key generation) require explicit user approval before execution."
env:
  API_KEY: "Secret key for authenticating with the bridge server. In Manual Mode: provided by the user from their own hosted server. In Autonomous Mode: generated by the agent and stored in .env in the agent workspace — user must explicitly approve this step. Rotate or delete after each temporary session."
  SERVER_URL: "Base URL of the bridge server (e.g. https://your-domain.com/upload/ or http://IP:5000). Provided by the user or set after the tunnel is opened."
tags:
  - file-upload

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly tell the agent to run a file-sharing server in its workspace and expose it through a zero-auth public tunnel. That creates an internet-accessible service without authentication or scope restrictions, which can expose uploaded files and potentially any weaknesses in the hosted server to unauthorized third parties.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Mandating a zero-auth tunnel as the default publication method creates an insecure-by-default deployment pattern. Even if temporary, any unauthenticated public endpoint can be discovered or shared, allowing unauthorized parties to access files or interact with the service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The trigger guidance is broad enough that normal requests like 'share this with me,' 'send me the output,' or 'give me a link' may invoke the skill in situations where the user did not intend network transfer. In a skill whose main function is exporting workspace data to a hosted server, overbroad activation materially raises the chance of accidental disclosure.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill states that every sensitive step is explicitly user-confirmed, but the workflow says that if a Server URL and API key are already configured, the agent may skip onboarding and proceed directly to upload. This creates a trust-boundary mismatch where previously stored credentials can be reused silently, enabling unintended data exfiltration to an already-configured endpoint.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a simple file-sharing/upload bridge, but its documented API also exposes file listing and deletion operations. That expands the effective capability of the skill beyond the declared user-facing purpose, increasing the risk that an agent or downstream workflow could enumerate or remove previously uploaded files without the user understanding that this behavior exists.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The self-hosting instructions are open-ended and could cause the agent to clone, run, and publicly expose infrastructure with little guidance on boundaries, data handling, or authorization. Ambiguous operational instructions in an agent skill increase the risk of unsafe autonomous actions that exceed the user's intended file-sharing request.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The workflow instructs the agent to solicit and use a user-provided server URL and API key, which increases the chance of secret handling through the agent channel and accidental retransmission or logging. In a file-transfer skill, collecting credentials is especially sensitive because the skill also performs outbound network operations using those secrets.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The API surface goes beyond simple upload/share and includes file listing, rich viewing, ZIP inspection, and deletion. In the context of an agent tool meant only to transfer outputs to an owner, these extra capabilities broaden access to stored data and increase the chance of unintended disclosure, overreach, or destructive actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documented deletion endpoint enables destructive actions but does not require confirmation, explain retention implications, or set expectations for user approval. In an agent workflow, this raises the risk of accidental or unauthorized deletion of shared files or evidence the user expected to keep.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · api_instructions.txt (reported line 81)May include surrounding context.

text
Payload (JSON): {"files": ["filename.zip"]}

Example:
requests.post(url + "?action=delete", json={"files": ["file1.zip"]}, headers=headers)

Static analysis

No suspicious patterns detected.