Back to skill

Security audit

Bcrypt Generate

Security checks for vulnerabilities and agentic risk

Overview

This password-hashing skill has a coherent purpose, but its instructions handle passwords through unsafe inline shell commands that can expose secrets or execute injected input.

Review before installing. Do not use this skill with real production passwords as written. A safer version should read the password from standard input, parse rounds as an integer, avoid shell interpolation, validate hashes, and avoid temporary files or command lines that contain secrets.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:22
Finding

Command and Python Code Injection Through Unsafely Interpolated Inputs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:22
Finding

Plaintext Password Exposure Through Process Command Lines and Temporary Scripts

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
SKILL.md:43
Finding

Unpinned Third-Party Dependency Installation Instruction

Content
View full analysis
&1 ``` If it fails with `ModuleNotFoundError`, tell the user: > "This skill requires the Python `bcrypt` package. Install with: `pip3 install bcrypt`." ``` ### Technical Analysis The installation instruction uses an unpinned package name without a reviewed version, hash verification, lock file, or explicitly approved package index. Dependency resolution therefore depends on mutable package-index state and local `pip` configuration. The project does not itself execute this installation command, so exploitation requires a user or operator to follow the recommendation. Nevertheless, installation can run package build or installation logic with the invoking user's privileges, and an unverified dependency source weakens supply-chain integrity and reproducibility. ### Attack Path 1. The `bcrypt` module is unavailable. 2. The skill advises the user to run `pip3 install bcrypt`. 3. The user executes the command in an environment whose package source or local `pip` configuration is compromised or untrusted. 4. Package content is downloaded without project-provided version and hash verification. 5. Malicious or unexpectedly changed installation content executes with the installing user's privileges. ### Impact Assessment If dependency resolution is compromised, malicious installation code could obtain the permissions of the user running `pip`, including access to that user's files, environment variables, credentials, and Python environment. The practical risk is reduced because `bcrypt` is a legitimate package name and installation is advisory rather than automatic, but the documented process lacks integrity and reproducibility controls. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

md
> "This skill requires the Python `bcrypt` package. Install with: `pip3 install bcrypt`."

5. If `python3` is not found at all, tell the user:
   > "This skill requires `python3`. Install with: `brew install python3` (macOS) or `sudo apt install python3` (Linux)."

6. Present the hash output on its own line. For verification, report clearly: "Password MATCHES the hash" or "Password does NOT match the hash."

Static analysis

No suspicious patterns detected.