Back to skill

Security audit

Use undici for HTTP requests, fetch, connection pooling, proxies, Mock testing, interceptors, caching.

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Undici helper skill with no bundled executable behavior, though its proxy examples should be used carefully.

Before installing, treat this as quick-reference documentation. Prefer per-request dispatchers unless you intentionally want process-wide behavior, avoid hardcoding proxy credentials, and use protected secret storage and TLS-protected proxy endpoints for authenticated proxies.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:143
Finding

Proxy Authentication Credentials Transmitted over Cleartext HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 143-146
Vulnerability Type: Plaintext transmission of authentication credentials
Risk Level: Medium

js
const proxyAgent = new ProxyAgent({
  uri: 'http://proxy:8080',
  token: `Basic ${Buffer.from('user:pass').toString('base64')}`
});

Technical Analysis

The proxy authentication example combines Basic authentication with an unencrypted http:// proxy connection. Base64 encoding is reversible and provides no confidentiality. If a user adapts this example with real credentials, the proxy authorization token may be exposed to an attacker capable of observing traffic between the client and the proxy.

Authentication through a proxy is necessary for the Skill's declared proxy functionality, but transmitting reusable credentials without TLS exceeds acceptable minimum-security requirements. The example also encourages placing a username and password directly in source code, which may expose them through source control, logs, diagnostics, or copied configuration.

Attack Path

  1. A user copies the documented example and replaces user:pass with valid proxy credentials.
  2. The application connects to the configured proxy using unencrypted HTTP.
  3. An attacker with access to the local network, an intermediate gateway, or another on-path position captures the proxy authentication traffic.
  4. The attacker extracts and Base64-decodes the Basic authentication token.
  5. The attacker reuses the recovered credentials to authenticate to the proxy, subject to the proxy's network exposure and access controls.

Impact Assessment

Successful exploitation can disclose the proxy username and password and permit unauthorized use of the associated proxy account. The resulting scope is limited to the privileges assigned to those credentials, but it may include use of proxy resources, consumption of network quotas, access to destinations restricted to authent ...[truncated 303 chars]

Remediation
View remediation

Remediation Suggestions

  • Use a TLS-protected proxy endpoint such as https://proxy.example:8080 and validate its certificate.

  • Do not embed usernames or passwords directly in source code or documentation examples. Load credentials from a secret manager or protected environment variable.

  • Explicitly state that Base64 is encoding rather than encryption and that Basic credentials must not be sent over an untrusted cleartext connection.

  • Prefer short-lived, narrowly scoped proxy tokens where supported.

  • Avoid printing proxy configuration objects or authentication headers in logs.

  • Provide a hardened example, such as:

    js
    import { ProxyAgent } from 'undici';
    
    const proxyToken = process.env.PROXY_AUTH_TOKEN;
    if (!proxyToken) {
      throw new Error('PROXY_AUTH_TOKEN is required');
    }
    
    const proxyAgent = new ProxyAgent({
      uri: 'https://proxy.example:8080',
      token: `Bearer ${proxyToken}`
    });
    
  • Ensure the secret-bearing environment variable is injected through a protected deployment mechanism rather than committed to a repository.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger scenario is broad enough to activate this skill for generic HTTP or fetch-related requests, increasing the chance it is selected outside its intended scope. Because this skill discusses powerful networking features like global dispatchers, proxies, and mocking, over-selection can cause the agent to introduce unnecessary network-capable patterns or unsafe configuration guidance in unrelated contexts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill provides examples for authenticated proxy use and setting a global dispatcher without warning that all subsequent HTTP traffic may be rerouted through the proxy and that embedded credentials may be exposed via code, logs, or misconfiguration. In an agent setting, this is risky because users may copy these patterns directly, unintentionally sending sensitive requests through untrusted infrastructure or changing process-wide network behavior.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.