Back to skill

Security audit

提供文件管理服务,并通过文件管理服务进行传输文件

Security checks for vulnerabilities and agentic risk

Overview

This file-transfer skill has a coherent purpose, but it ships a real-looking bearer credential and uses unsafe network and download defaults that require careful review before installation.

Install only after replacing scripts/.env with your own least-privileged AppKey, rotating the exposed key if it was ever valid, using HTTPS for any non-local endpoint, binding the service to localhost unless remote access is intentionally hardened, verifying any downloaded FileManager binary by pinned version and checksum, and choosing explicit safe download paths.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/.env:1
Finding

Hardcoded FileManager Bearer Credential in Distributed Configuration

Content
View full analysis
`. 5. The attacker performs the upload, download, information retrieval, or sharing operations granted to the key. ### Impact Assessment The attacker receives the same FileManager API privileges assigned to the exposed key. Depending on server-side authorization, this can include: - Uploading attacker-controlled files. - Downloading stored files by ID. - Creating public share links. - Reading file metadata. - Modifying remarks or other API-accessible state. - Consuming storage and network resources. The exact scope is limited by the server-si ...[truncated 123 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/filemanager_transfer.py:38
Finding

Bearer Credentials and File Contents Can Be Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/filemanager_transfer.py:195
Finding

Server-Controlled Download Filename Allows Arbitrary Path Writes

Content
View full analysis
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:12
Finding

Instructions Retrieve and Execute an Unpinned, Unverified Remote Binary

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/install-and-start.md:25
Finding

FileManager Service Is Configured to Listen on All Network Interfaces

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/filemanager_transfer.py (reported line 14)May include surrounding context.

python
from urllib import error, parse, request

SCRIPT_DIR = Path(__file__).resolve().parent
ENV_PATH = SCRIPT_DIR / ".env"


class FriendlyError(Exception):

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
70% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/filemanager_transfer.py (reported line 40)May include surrounding context.

python
fail(f"配置文件格式错误:{ENV_PATH} 第 {index} 行缺少等号")
            key, value = line.split("=", 1)
            values[key.strip()] = value.strip().strip('"').strip("'")
    values.update({k: v for k, v in os.environ.items() if k.startswith("FILEMANAGER_")})
    return values

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/filemanager_transfer.py (reported line 69)May include surrounding context.

python
pass
    hints = {
        400: "请求参数不正确,请检查文件、远程目录、分享密码或备注。",
        401: "认证失败,请检查 scripts/.env 中的 FILEMANAGER_APPKEY 是否正确。",
        403: "权限不足,当前 AppKey 不允许执行该操作。",
        404: "接口、远程目录或文件 ID 不存在。上传时请确认远程目录已存在;下载时请确认文件 ID 正确。",
        413: "文件超过服务端允许的上传大小。",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill describes capabilities that involve reading environment configuration, transferring files, and accessing remote services, but it does not declare any explicit tool scope or permission boundaries. This can lead to overbroad execution in hosts that rely on metadata for least-privilege enforcement, increasing the chance of unintended file access, network exfiltration, or secret exposure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The activation criteria are broad: the skill applies whenever files move between the user and the agent environment, including downloading from user-provided links and handling remote transfer workflows. Without clear trigger boundaries or consent checks, the skill may be invoked in situations involving sensitive files or untrusted URLs, increasing the risk of accidental data movement or unsafe downloads.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The instructions direct the agent to upload, share, and download files through a transfer service, but they do not require an explicit privacy or data-transfer warning before moving user data off the local environment. This is dangerous because users may not realize their files are being sent to a remote FileManager service, potentially exposing sensitive content through storage, sharing links, or retention on that service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation configures FILEMANAGER_BASE_URL to use plain HTTP and shows Bearer-token authenticated requests over that channel without any warning. This can expose the AppKey and transferred file contents to interception or modification if the service is accessed over a non-local or untrusted network.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api.md (reported line 15)May include surrounding context.

列出目录内容。

text
curl -H "Authorization: Bearer $APPKEY" "http://localhost:8080/api/files?path=/"

POST /api/files/upload?path=/target

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The markdown describes operations that affect user data, including uploading files, downloading files, and modifying file remarks, but it does not include any caution about overwriting, exposing, or changing user-managed content. Under the markdown criteria, behaviours that can affect user data should be accompanied by explicit warnings.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The installation guide explicitly instructs operators to bind the FileManager service to 0.0.0.0 on all platforms, which exposes the service on all network interfaces rather than limiting it to local access. In a file-transfer skill that also uses an AppKey, this unnecessarily broadens the attack surface and can permit unintended remote access if host firewalls, reverse proxies, or authentication are weak or misconfigured.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide not only exposes the service on all interfaces but does so without an explicit warning that this makes the file service reachable from other hosts. Because this skill is meant for transferring files, operators may follow the instructions as-is and unintentionally publish a sensitive file-management endpoint to a broader network, increasing the risk of unauthorized access or data exposure.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

SQP-3 covers natural-language policy violations such as forcing a specific language without user opt-in. This file presents all user-facing instructions in Chinese and does not indicate that the language is optional or that the skill is intentionally limited to a Chinese-speaking context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file presents all troubleshooting instructions in Chinese and does not indicate that the user can choose another language or that the skill is intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The download command writes server-provided content directly to a caller-chosen or server-influenced filesystem path without any confirmation, overwrite protection, or safety checks. In an agent setting, this can silently modify local files, overwrite existing data, or place untrusted files in sensitive locations if the output path or derived filename is not carefully controlled.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The natural-language content of the skill is written entirely in Chinese and does not indicate that another language can be used if the user prefers. This can be a language/locale policy issue when the skill is used in broader environments without explicit user opt-in to Chinese.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

All user-facing instructional content in this skill file is written in Chinese, with no indication that the skill is region-specific or that users may choose another language. Under the language/locale policy, forcing a specific language without opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

For markdown files, SQP-2 applies when the skill description omits warnings about behaviors that could affect user data or system integrity. L50 states that omitting --output causes the script to write into the current directory, but the document does not add any caution about this local write behavior or advise users to choose a safe destination.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

Natural-language strings throughout the file, including errors, help text, and status output, are fixed to a single language. The policy requires avoiding forced language or locale constraints unless the skill offers user choice or clearly documents a justified region-specific limitation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
references/transfer-script.md:17