Back to skill

Security audit

Operator

Security checks for vulnerabilities and agentic risk

Overview

This skill is clearly for managing Operator fleets, but it grants broad control and stores/sends powerful credentials without enough safeguards.

Install only if you trust Operator with broad control over your agent fleet. Before use, restrict permissions on ~/.operator and its config file, keep operatorAppUrl pinned to a trusted HTTPS Operator origin, and require explicit confirmation before deletes, restarts, secret grants, file writes, automations, webhooks, or other lasting changes.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:55
Finding

Operator API key stored without restrictive filesystem permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:55-60
Vulnerability Type: Insecure storage of bearer credentials
Risk Level: Medium

Vulnerable Code

bash
mkdir -p ~/.operator
python3 -c "
import json
config = {'operatorApiKey': 'THE_KEY', 'operatorAppUrl': 'https://www.operator.io'}
with open('$HOME/.operator/config.json', 'w') as f:
    json.dump(config, f, indent=2)

Technical Analysis

The instructions store the Operator bearer API key in a plaintext JSON file but do not set restrictive permissions on either ~/.operator or ~/.operator/config.json.

mkdir -p and Python's default file-creation behavior rely on the user's current umask. With a common 022 umask, the directory can be created as 0755 and the configuration file as 0644, allowing other local accounts to read the API key. The instructions also do not verify that the path is owned by the current user, is not a symbolic link, and has safe existing permissions.

This credential handling is particularly sensitive because the documented API supports instance lifecycle operations, configuration changes, workspace file access, secret grants, automations, and webhooks.

Attack Path

  1. The user follows the login instructions.
  2. The commands create ~/.operator/config.json under a permissive umask.
  3. The plaintext operatorApiKey becomes readable by another local account or process.
  4. The attacker copies the bearer token.
  5. The attacker submits authenticated requests to the Operator API.
  6. The attacker performs whichever fleet-management operations are authorized to that API key.

An attacker who can prepare an unsafe existing path may also attempt symbolic-link or ownership-based manipulation when the file is written.

Impact Assessment

Theft of the key can provide remote access to the user's Operator account within the key's authorization scope. Potential consequences include:

  • Listing, crea ...[truncated 414 chars]
Remediation
View remediation

Remediation Suggestions

  • Create the credential directory with mode 0700, for example:

    bash
    install -d -m 700 "$HOME/.operator"
    
  • Create the credential file atomically with mode 0600.

  • Set a restrictive umask, such as 077, before creating credential files.

  • Verify that the directory and file are owned by the current user.

  • Refuse to read or overwrite symbolic links and files with unsafe ownership or permissions.

  • Prefer an operating-system credential store or keychain over a plaintext JSON file.

  • If a file must be used, separate sensitive credentials from non-sensitive configuration.

  • Document API-key rotation and immediate revocation procedures for suspected disclosure.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:70
Finding

Configurable API origin can receive the Operator bearer token without validation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:70-92 and repeated at SKILL.md:120-122
Vulnerability Type: Bearer-token disclosure through an unvalidated endpoint
Risk Level: High

Vulnerable Code

bash
OPERATOR_KEY=$(python3 -c "import json; c=json.load(open('$HOME/.operator/config.json')); print(c.get('operatorApiKey',''))")
OPERATOR_URL=$(python3 -c "import json; c=json.load(open('$HOME/.operator/config.json')); print(c.get('operatorAppUrl','https://www.operator.io'))")
bash
curl -s "$OPERATOR_URL/api/cli/health" \
  -H "Authorization: Bearer $OPERATOR_KEY"
bash
curl -sN "$OPERATOR_URL/api/chat" \
  -H "Authorization: Bearer $OPERATOR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"messages":[{"role":"user","parts":[{"type":"text","text":"YOUR_MESSAGE_HERE"}]}]}' \

The same authorization pattern is used for follow-up chat requests:

bash
curl -sN "$OPERATOR_URL/api/chat" \
  -H "Authorization: Bearer $OPERATOR_KEY" \
  -H "Content-Type: application/json" \

Technical Analysis

Both the bearer credential and destination URL are loaded from the same user-editable configuration file. The instructions then attach the bearer token to requests sent to the configured URL without validating:

  • The URL scheme.
  • The destination hostname.
  • The effective port.
  • Whether the destination belongs to an approved Operator origin.
  • Whether redirects remain on the approved origin.

Consequently, modification or poisoning of operatorAppUrl can redirect authenticated requests to an attacker-controlled server. The first subsequent health or chat request would disclose the Authorization: Bearer header.

Although configurable endpoints may be useful for legitimate self-hosted deployments, sending the same production credential to an arbitrary configured origin exceeds safe minimum-privilege credential handling. Any alternate deployment should use a ...[truncated 1688 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin requests to an explicit trusted HTTPS origin such as https://www.operator.io.
  • If alternate deployments are required, maintain a strict allowlist of normalized scheme, hostname, and port combinations.
  • Reject plaintext HTTP and URLs containing user information or unexpected components.
  • Disable redirects or validate every redirect destination before forwarding an authorization header.
  • Store endpoint configuration separately from credentials so modification of one trust domain does not automatically compromise the other.
  • Use separate, narrowly scoped credentials for each approved deployment origin.
  • Validate ownership and permissions of the configuration file before reading it.
  • Consider certificate or public-key pinning where operationally supportable.
  • Rotate the API key immediately if it may have been transmitted to an untrusted endpoint.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises destructive capabilities like delete, restart, reconfigure, and secret-management but does not require explicit confirmation, dry-run behavior, or safety checks. Because the downstream Operator manager performs multi-step operations internally from natural-language requests, the absence of confirmation guidance makes accidental or prompt-induced destructive actions more likely.

Content

No source excerpt is available for this finding.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

  1. After the user confirms they've logged in, poll for the API key:
bash
curl -s "https://www.operator.io/api/cli/poll?session=SESSION_ID"

The response will contain operatorApiKey when auth is complete.

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

To continue a conversation (for follow-up requests), include the id field. The chat ID is returned in the stream's start event:

bash
curl -sN "$OPERATOR_URL/api/chat" \
  -H "Authorization: Bearer $OPERATOR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"id":"CHAT_ID","messages":[{"role":"user","parts":[{"type":"text","text":"YOUR_FOLLOWUP"}]}]}' \

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger guidance is broad enough that the skill may activate on vague mentions like 'Operator' or 'fleet', causing the agent to enter a high-privilege management workflow without clear user intent. In a skill that can delete, reconfigure, message agents, and manage secrets, accidental invocation materially increases the chance of unintended sensitive actions or disclosure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

  1. After the user confirms they've logged in, poll for the API key:
bash
curl -s "https://www.operator.io/api/cli/poll?session=SESSION_ID"

The response will contain operatorApiKey when auth is complete.

Session Persistence

Medium
Category
Rogue Agent
Confidence
95% confidence
Finding

The skill persists a bearer API key to ~/.operator/config.json, creating a durable credential that can be reused by other local processes, users, backups, or malware if file permissions are weak. Long-lived local token storage meaningfully increases compromise impact because the key can authenticate to a fleet-management API with broad administrative capabilities.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

  1. Save the credentials:
bash
mkdir -p ~/.operator
python3 -c "
import json
config = {'operatorApiKey': 'THE_KEY', 'operatorAppUrl': 'https://www.operator.io'}

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The skill sends arbitrary natural-language requests and follow-up context to a remote Operator chat API that can manage fleet resources, which means sensitive operational data, prompts, instance identifiers, logs, or secrets-adjacent content may be transmitted off-host. In this context the transmission is intentional, but it expands trust to a remote AI control plane and can expose sensitive data if requests are not scoped or sanitized.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

To continue a conversation (for follow-up requests), include the id field. The chat ID is returned in the stream's start event:

bash
curl -sN "$OPERATOR_URL/api/chat" \
  -H "Authorization: Bearer $OPERATOR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"id":"CHAT_ID","messages":[{"role":"user","parts":[{"type":"text","text":"YOUR_FOLLOWUP"}]}]}' \

Session Persistence

Medium
Category
Rogue Agent
Confidence
90% confidence
Finding

The documented capabilities include writing workspace files, managing secrets access, and creating automations/webhooks, which can establish durable persistence or recurring control within managed agent environments. In a fleet-management skill, these are especially sensitive because they enable long-lived post-action changes beyond a single chat interaction.

Content

Scanner excerpt · SKILL.md (reported line 165)May include surrounding context.

md
The manager has tools for:

- **Instances**: list, create, delete, restart, clone, get details, check capacity, get logs
- **Config**: update instance configuration (JSON patch), deploy skills, list/read/write workspace files
- **Agents**: message a running agent, check latest session activity
- **Secrets**: list user secrets, grant/revoke instance access
- **Automations**: list, create, update, delete scheduled cron automations

Static analysis

No suspicious patterns detected.