Back to skill

Security audit

dotenv — Node.js Environment Variable Loader

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly normal dotenv documentation, but it includes an unverified remote installer command that could execute whatever the remote site serves.

Review this skill before installing. The dotenv guidance itself is ordinary, but avoid running the `curl ... | sh` dotenvx installer; prefer package-manager installation such as npm or Homebrew, and do not let an agent print, commit, or upload real `.env` values or private keys.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:188
Finding

Unverified Remote Installer Executed Directly by Shell

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 188
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code

bash
curl -fsS https://dotenvx.sh/ | sh

Technical Analysis

The installation instruction downloads a remote script from https://dotenvx.sh/ and immediately pipes it into sh. The fetched content is not version-pinned, inspected, or verified using a cryptographic signature or checksum before execution.

Although HTTPS protects the connection in transit, it does not guarantee that the server will continue serving the same reviewed payload. Compromise of the website, hosting account, deployment pipeline, or other distribution infrastructure could cause this command to execute attacker-controlled shell instructions. The payload would execute with all permissions available to the user running the command.

This behavior is not required for the Skill's declared dotenv management functionality. The same section already provides package-manager alternatives through npm and Homebrew, making direct remote shell execution avoidable.

Attack Path

  1. An attacker compromises the dotenvx.sh distribution endpoint or its publishing infrastructure.
  2. The attacker replaces or modifies the installer response with malicious shell commands.
  3. A user or AI agent follows the installation instructions in SKILL.md.
  4. curl retrieves the current attacker-controlled response.
  5. The pipe passes the response directly to sh without prior inspection or integrity verification.
  6. The malicious commands execute with the invoking user's privileges.

Impact Assessment

Successful exploitation permits arbitrary command execution under the invoking account. Depending on that account's permissions and local environment, an attacker could:

  • Read environment files, API keys, source code, and other accessible credentials.
  • Modify project files or user configuration.
  • Install additional malware or ...[truncated 387 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh installation option.
  2. Prefer the existing package-manager alternatives:
    bash
    npm install -g @dotenvx/dotenvx
    # or
    brew install dotenvx
    
  3. Pin an explicit package version where reproducibility is required, and use the package manager's lockfile or integrity mechanisms.
  4. If a standalone installer is indispensable:
    • Download it as a separate file.
    • Use a version-specific immutable URL.
    • Verify a publisher-provided cryptographic signature or trusted checksum.
    • Inspect the downloaded script before execution.
    • Execute it without elevated privileges unless a documented operation strictly requires them.
  5. Document the files, directories, and permissions the installer is expected to modify.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (38)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

gitignore
# .gitignore
.env
.env.local
.env.*.local

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

gitignore
# .gitignore
.env
.env.local
.env.*.local

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The skill recommends installing software via a remote shell pipeline (curl ... | sh), which executes code fetched over the network without prior verification. In a skill context, users may copy-paste this command directly, creating a strong supply-chain and remote code execution risk if the host, transport, or distribution mechanism is compromised.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

or

brew install dotenvx

or

curl -fsS https://dotenvx.sh/ | sh

text

### Variable Expansion

Chaining Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

Piping remote content directly into sh is a classic chaining-abuse pattern because it combines network retrieval and immediate execution in a single step. This removes opportunities for review and makes it easy for an attacker controlling or intercepting the fetched content to run arbitrary commands on the user's machine.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

or

brew install dotenvx

or

curl -fsS https://dotenvx.sh/ | sh

text

### Variable Expansion

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 12)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 193)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 272)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 8)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 72)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 80)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 85)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 99)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 104)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 113)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api-reference.md (reported line 211)May include surrounding context.

ts
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 79)May include surrounding context.

md
interface DotenvConfigOptions {
  /**
   * Path to the .env file
   * @default path.resolve(process.cwd(), '.env')
   */
  path?: string

Static analysis

No suspicious patterns detected.