Back to skill

Security audit

Runcloud Skill

Security checks for vulnerabilities and agentic risk

Overview

This Runcloud skill is mostly transparent, but it includes high-impact authenticated infrastructure write actions that are framed too lightly as safe or non-destructive.

Review before installing. Use a least-privilege Runcloud token if possible, treat all POST examples as production changes, and require explicit server, web app, service, or cron identifiers plus confirmation before running deployments, restarts, cron tests, or SSL changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The trigger description is broad enough that a generic mention of Runcloud or server health could invoke the skill even when the user did not intend to operate on infrastructure. Overbroad triggering increases the chance of unintended API calls, especially in a skill that contains authenticated write actions such as deployments, cron tests, service restarts, and SSL changes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

This command transmits an authenticated POST to an external service to restart a server-side service, which is a real state-changing operation with availability implications. In the context of an agent skill, external transmission is expected, but it remains dangerous because a mistaken or over-broad invocation could disrupt production services using a token with broad workspace privileges.

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

Restart a service

bash
curl -s -X POST -H "$AUTH" -H "Content-Type: application/json" \
  -d '{"action":"restart"}' \
  "$RC/servers/{serverId}/services/{serviceRealName}/action" | jq
# serviceRealName examples: nginx-rc, apache2-rc, mysql, redis-server, supervisor

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill asserts these POST actions are non-destructive and 'safe', but the SSL deployment endpoint changes live web application configuration and can affect certificate state, HTTP/HSTS behavior, and service availability. Mislabeling a state-changing operation as non-destructive can cause an agent or operator to invoke it with less scrutiny than warranted.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The notes claim the skill omits resource-creation and similar risky endpoints, yet it includes a POST that provisions/applies SSL configuration to a web app. This inconsistency weakens operator trust boundaries and may lead downstream systems to authorize a write action under the assumption the skill is read-only or low-risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This POST sends authenticated configuration data to deploy/apply SSL settings on a web application, altering security and serving behavior. In a production environment, incorrect execution could break TLS configuration, change HTTP/HSTS behavior, or trigger certificate-related outages; the skill context makes this more dangerous because it frames the action as safe/non-destructive.

Content

Scanner excerpt · SKILL.md (reported line 164)May include surrounding context.

Deploy Let's Encrypt SSL

bash
curl -s -X POST -H "$AUTH" -H "Content-Type: application/json" \
  -d '{"provider":"letsencrypt","enableHttp":true,"enableHsts":false,"ssl_protocol_id":1}' \
  "$RC/servers/{serverId}/webapps/{webappId}/ssl" | jq

Static analysis

No suspicious patterns detected.