Back to skill

Security audit

logicx-skill-test

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent LogicX account-integration purpose, but it handles passwords and tokens in unsafe ways and can send authentication headers outside the intended service scope.

Review this carefully before installing. Prefer browser binding only, do not send your password to the agent, avoid using the default HTTP endpoint for any real account, and treat any saved LogicX token file as sensitive. The publisher should require HTTPS, reject absolute untrusted URLs, stop collecting passwords through chat or command arguments, and provide a clear token-clearing flow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/logicx_api.sh:107
Finding

Authentication Headers Can Be Forwarded to an Arbitrary Host

Content
View full analysis
Remediation
View remediation
&2 exit 1 ;; esac ``` 2. Allowlist only `/api/health` and explicitly supported `/api/proxy/*` routes. 3. Canonicalize and validate paths before combining them with the base URL; reject traversal components, fragments, control characters, and unexpected query strings. 4. Validate that the final URL uses HTTPS and that its normalized host and port exactly match the configured LogicX origin. 5. Attach authentication headers only after endpoint classification. Do not attach either credential to health checks or any destination outside the trusted origin. 6. Rotate the agent service key and invalidate potentially exposed user tokens after deploying the fix. 7. Add regression tests proving that absolute URLs, alternate ports, user-info syntax, and untrusted hosts are rejected without making a request. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
scripts/logicx_api.sh:9
Finding

Passwords and Bearer Tokens Are Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/logicx_api.sh:135
Finding

Password Login Exposes Credentials Through Process Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
of the user. All API calls go through the frontend proxy (`/api/proxy/*`). Use `scripts/logicx_api.sh` for every request — never write ad-hoc `curl` commands.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill explicitly instructs the agent to solicit the user's username and password in chat as part of the password-login fallback. This is dangerous because chat channels are not appropriate secret-entry mechanisms; credentials may be stored in logs, exposed to operators or downstream systems, and normalized as acceptable phishing-like behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The example explicitly tells users they can send their username and password to the agent in chat, normalizing direct credential disclosure to an intermediary. This creates a credential-harvesting risk, expands exposure to logs/transcripts, and bypasses safer first-party authentication flows such as browser-based login.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directly encourages the user to disclose account credentials so the agent can authenticate on their behalf, which is a classic unsafe design pattern for credential interception and misuse. In this skill's context, the agent subsequently accesses account, order, payment, and account-action endpoints, making compromised credentials especially sensitive.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The password login example demonstrates collecting and transmitting raw user credentials through the agent workflow without any warning or secure-handling boundary. Even if sent to a legitimate backend, this exposes secrets to chat history, agent memory, operator visibility, and accidental logging.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The default base URL uses plain HTTP to a raw IP address, yet the script supports password login and transmits bearer-style credentials and user tokens in headers. That exposes secrets to interception or modification by any network attacker on the path, enabling account compromise and session hijacking.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The URL normalizer explicitly permits any absolute http:// or https:// URL, allowing callers to bypass the intended LogicX proxy scope and direct authenticated requests to arbitrary destinations. In this skill context, that is especially dangerous because the script automatically attaches the agent service key and, when present, the user token, creating a clear SSRF/exfiltration path to attacker-controlled hosts.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes shell scripts (logicx_api.sh, check_link_status.sh) but does not declare an explicit tool scope such as permissions or allowed-tools. That increases the chance an agent can execute shell capabilities more broadly than intended, weakening least-privilege controls and making misuse or prompt-driven command execution harder to constrain.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
79% confidence
Finding

The skill persists authentication state by auto-saving link_code, install_id, and later user tokens to ~/.config/logicx/skill-state.json. Session persistence on disk can expose account tokens to other local processes or users if file permissions, lifecycle management, rotation, and clearing behavior are not tightly controlled.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
# LogicX Skill

Interact with the LogicX platform on behalf of the user. All API calls go through the frontend proxy (`/api/proxy/*`). Use `scripts/logicx_api.sh` for every request — never write ad-hoc `curl` commands.

## Rules

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill tells users they can provide their username and password directly in chat for fallback login, but gives no privacy or handling warning. Collecting credentials through chat exposes highly sensitive secrets to logging, transcript retention, model processing, and accidental disclosure, making credential compromise more likely.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The instruction to persist the returned user_token omits any warning that the token is a bearer credential that grants user-scoped access to account, order, and payment actions. In a skill environment, telling an agent to persist such a token without storage restrictions can lead to insecure retention in plaintext memory, logs, or shared state, enabling account takeover if the token is exposed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation instructs the agent to collect and transmit a user's email and password to an API but does not warn that these are highly sensitive credentials, nor does it constrain when this flow should be used. In an agent context, this increases the risk that the skill prompts users to disclose account passwords directly to the agent, creating credential exposure risk through logs, telemetry, prompt history, or mishandling by downstream components.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The script requires LOGICX_AGENT_SERVICE_KEY and then invokes another script to call the agent/link/status API, but it provides no user-facing notice that a privileged credential will be used for a network request. Aside from a terse requirement comment, there is no confirmation, warning, or disclosure about credential use or outbound status check behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script automatically loads and saves the user authentication token to a local state file without explicit user consent or warning. Even with chmod 600, storing reusable tokens on disk increases exposure to token theft from local compromise, backups, misconfigured home directories, or accidental reuse across sessions.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/logicx_api.sh (reported line 60)May include surrounding context.

sh
dir="$(dirname "$LOGICX_STATE_FILE")"
  mkdir -p "$dir"
  printf '%s\n' "$content" > "$LOGICX_STATE_FILE"
  chmod 600 "$LOGICX_STATE_FILE" 2>/dev/null || true
}

# Save user_token (replaces any existing state — bind is complete)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill specifies a fixed Chinese response template for the login flow, which imposes a language choice on users without opt-in. This is a natural-language policy issue because the file does not indicate that the skill is region-specific or that users can choose another language.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The comment specifies activation based on the user saying the Chinese phrase "我登录好了", which imposes a language-specific trigger with no indication of alternatives or user choice. This is a natural-language locale constraint and may violate language/locale policy when not explicitly optional or justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The usage text instructs that when the user says the Chinese phrase 我登录好了, the skill should run another script. This hard-codes a specific language trigger in natural-language instructions without indicating alternatives or user choice, which is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.