Back to skill

Security audit

us3-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real UCloud file uploader, but its public file uploads and credential-bearing requests need review because the configured bucket host is not validated as UCloud.

Review this before installing. Use only a dedicated, least-privilege UCloud key restricted to the intended bucket, verify US3_BUCKET is exactly the expected UCloud US3 bucket domain, and do not upload secrets, personal data, or confidential files unless public access is intended. Prefer a revised version that validates allowed UCloud hostnames and updates the old dependency stack.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
upload.mjs:91
Finding

Unvalidated Bucket Domain Allows Upload Redirection to an Attacker-Controlled Host

Content
View full analysis

Vulnerability Details

File Location: upload.mjs, lines 91-117; the SDK upload path is also affected at lines 177-200
Vulnerability Type: Unvalidated network destination and credential forwarding
Risk Level: High

js
// Extract bucket name and proxy suffix
const bucketName = bucket.split('.')[0];
const proxySuffix = bucket.substring(bucketName.length + 1);

console.error(`[DEBUG] Bucket: ${bucketName}, Proxy: ${proxySuffix}`);

const contentType = 'application/octet-stream';
const contentMD5 = '';
const date = new Date().toUTCString();

// Generate authorization signature
const signature = generateSignature('PUT', bucketName, objectKey, contentType, contentMD5, date, privateKey);
const authorization = `UCloud ${publicKey}:${signature}`;

console.error(`[DEBUG] Authorization generated, date: ${date}`);

const options = {
  hostname: `${bucketName}.${proxySuffix}`,
  port: 443,
  path: `/${objectKey}`,
  method: 'PUT',
  headers: {
    'Authorization': authorization,
    'Content-Type': contentType,
    'Content-Length': fileSize,
    'Date': date,
  },
  timeout: 120000, // 120 second timeout
};

The same unvalidated value reaches the SDK configuration:

js
// Extract bucket name from full domain
// Format: bucket-name.region.ufileos.com -> bucket-name
const bucketName = bucket.split('.')[0];

// Extract proxy suffix (e.g., "cn-sh2.ufileos.com")
const proxySuffix = bucket.substring(bucketName.length + 1);

// Create HTTP request for PUT operation
const httpRequest = new ufile.HttpRequest(
  'PUT',
  '/' + objectKey,
  bucketName,
  objectKey,
  filepath
);

// Create auth client
const authClient = new ufile.AuthClient(httpRequest, {
  'ucloud_public_key': publicKey,
  'ucloud_private_key': privateKey,
  'proxy_suffix': proxySuffix
});

Technical Analysis

US3_BUCKET is accepted directly from the environment and is treated a ...[truncated 2654 chars]

Remediation
View remediation

Remediation Suggestions

  1. Parse US3_BUCKET as a hostname and reject malformed values, URL schemes, ports, paths, credentials, IP literals, localhost names, and unrelated domains.
  2. Enforce an explicit allowlist of approved UCloud US3 domain suffixes and regions. Compare normalized DNS labels rather than using a simple string-suffix check.
  3. Store the bucket name and service endpoint as separate configuration values. Validate the bucket name against a restrictive pattern and select the endpoint from a fixed internal mapping of approved regions.
  4. Do not derive a credential-bearing request destination from one unrestricted environment variable.
  5. Apply the same validation before both the direct HTTPS path and the SDK path.
  6. Use least-privilege UCloud credentials restricted to the intended bucket and required upload operations.
  7. Add automated tests confirming rejection of attacker-controlled domains, deceptive suffixes, IP addresses, malformed hostnames, and unexpected regions.
  8. Fail closed when endpoint validation is unsuccessful, and avoid logging authentication headers or signatures.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Known Vulnerable Dependency: form-data==2.3.3 — 2 advisory(ies): CVE-2025-7783 (form-data uses unsafe random function in form-data for choosing boundary); CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

Critical
Category
Supply Chain
Confidence
95% confidence
Finding

form-data 2.3.3 is an outdated multipart builder with advisories for unsafe boundary generation and CRLF injection via unescaped multipart field names. Because this skill uploads files to object storage and likely constructs multipart/form-data requests through transitive dependencies, malformed attacker-influenced field names or predictable boundaries could enable request manipulation, data corruption, or downstream injection against receiving services.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: underscore==1.13.7 — 1 advisory(ies): CVE-2026-27601 (Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS)

High
Category
Supply Chain
Confidence
80% confidence
Finding

underscore 1.13.7 is reported to allow unlimited recursion in functions like _.flatten and _.isEqual, which can cause denial of service on maliciously deep structures. This is only exploitable if the skill processes attacker-controlled nested inputs with those functions, but the vulnerable version is present in the dependency tree.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill requires access to sensitive environment variables for cloud credentials but does not declare an explicit tool scope such as permissions or allowed-tools. This weakens least-privilege controls and makes the skill's secret access less visible to reviewers and operators, increasing the chance of unintended credential exposure or overbroad execution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This skill uploads files to a public bucket and generates directly accessible URLs, but the documentation does not prominently warn users before use that uploaded content will be publicly exposed. That creates a real risk of accidental disclosure of sensitive files, especially because the skill is user-invocable and positioned as a generic file-sharing helper.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
- `US3_PUBLIC_KEY` - UCloud Public Key (Token)
  - `US3_PRIVATE_KEY` - UCloud Private Key
  - `US3_BUCKET` - Bucket domain (e.g., xqm.cn-sh2.ufileos.com)
  - `US3_ENDPOINT` - API endpoint (e.g., https://api.ucloud.cn/)

## Usage

Abandoned Dependency: request is unmaintained and no longer receives security updates

Medium
Category
Supply Chain
Confidence
98% confidence
Finding

request is abandoned and no longer receives security fixes, which materially increases long-term exposure because newly discovered flaws in a network-facing upload skill will remain unpatched. This is especially concerning here because the skill's core behavior depends on outbound HTTP interactions with storage services.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: ajv==6.12.6 — 1 advisory(ies): CVE-2025-69873 (ajv has ReDoS when using `$data` option)

Low
Category
Supply Chain
Confidence
81% confidence
Finding

The lockfile pins ajv 6.12.6, which is reported vulnerable to ReDoS when the $data option is enabled. In a package-lock.json alone we cannot confirm runtime use of $data, but the vulnerable version is present and could enable denial of service if attacker-controlled schemas or inputs reach ajv in that mode.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.5.3 — 2 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2025-15284 (qs's arrayLimit bypass in its bracket notation allows DoS via memory exhaustion)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

qs 6.5.3 has reported denial-of-service issues involving crafted inputs that trigger excessive processing or memory use. This matters if the package parses attacker-controlled query strings or form bodies; in this lockfile alone exploitability is contextual, but the vulnerable version is present.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: request==2.88.2 — 1 advisory(ies): CVE-2023-28155 (Server-Side Request Forgery in Request)

Low
Category
Supply Chain
Confidence
91% confidence
Finding

request 2.88.2 is deprecated and has a known SSRF issue. For a skill whose purpose is uploading files and generating public URLs, any code path that lets users influence destination URLs, redirects, or proxy-related options could turn this into network access to unintended internal or metadata endpoints.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: tough-cookie==2.5.0 — 1 advisory(ies): CVE-2023-26136 (tough-cookie Prototype Pollution vulnerability)

Low
Category
Supply Chain
Confidence
78% confidence
Finding

tough-cookie 2.5.0 is reported vulnerable to prototype pollution. In this skill's context the risk is lower because an uploader to object storage may not heavily process attacker-supplied cookie jars, but if untrusted cookie data is parsed, object pollution could cause logic errors or unsafe property resolution.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: uuid==3.4.0 — 1 advisory(ies): CVE-2026-41907 (uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided)

Low
Category
Supply Chain
Confidence
69% confidence
Finding

uuid 3.4.0 carries a reported bounds-check issue in certain versioned UUID functions when a caller provides a buffer. The vulnerable package is present, but exploitability depends on specific API usage that is not visible from the lockfile, so the practical risk in this skill appears limited.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

The dependency uses a caret range, which allows newer matching versions to be installed over time rather than a single immutable version. This can introduce supply-chain risk through unexpected upstream changes, regressions, or compromised releases, though the package file alone does not show active exploitation.

Content

Scanner excerpt · package.json (reported line 13)May include surrounding context.

json
"author": "",
  "license": "ISC",
  "dependencies": {
    "mime": "^1.6.0",
    "ufile": "^0.0.15"
  }
}

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
90% confidence
Finding

The ufile dependency is specified with a caret range, allowing automatic adoption of later compatible releases. Because this skill uploads files to cloud object storage, compromise or malicious changes in the storage client library could affect confidentiality, integrity, or destination of uploaded data, making the supply-chain exposure somewhat more sensitive in context.

Content

Scanner excerpt · package.json (reported line 14)May include surrounding context.

json
"license": "ISC",
  "dependencies": {
    "mime": "^1.6.0",
    "ufile": "^0.0.15"
  }
}

Static analysis

No suspicious patterns detected.