Back to skill

Security audit

Cloud Upload Tencent

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but its upload and sharing instructions can expose local files or cloud credentials if followed carelessly.

Use this only for files you intentionally want to upload to Tencent COS. Prefer private buckets and short-lived presigned URLs, avoid public-read/write buckets, use narrowly scoped temporary credentials, and do not enter SecretKey values directly on a command line. Install dependencies in an isolated environment with reviewed pinned versions where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:45
Finding

Unpinned Runtime Dependencies Allow Mutable Supply-Chain Code

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:45, SKILL.md:77, and SKILL.md:93
Vulnerability Type: Unpinned third-party package installation
Risk Level: Medium

Complete Vulnerable Snippets:

bash
# Install Tencent Cloud COS CLI
# pip installation (Python 3.6+)
pip3 install cos-python-sdk-v5
bash
# Install the coscmd CLI tool
pip3 install coscmd
powershell
# Install the SDK
pip install cos-python-sdk-v5

Technical Analysis

The Skill instructs users to install cos-python-sdk-v5 and coscmd from the configured Python package index at runtime without pinning exact versions or verifying package hashes. Consequently, the installed code is mutable and may differ from the dependency version that was reviewed during this audit.

This does not establish that the named packages are currently malicious. The security weakness is that future package releases, a compromised package publisher, a compromised package index, or an unsafe index configuration could cause unreviewed code to be installed and executed. Python packages may execute code during installation, and their modules execute within the calling Python process when imported.

Attack Path

  1. An attacker compromises a dependency publisher, distribution channel, or package-index configuration.
  2. The attacker publishes or serves a malicious version of cos-python-sdk-v5 or coscmd.
  3. A user follows the Skill and runs an unpinned pip command.
  4. pip resolves the current mutable package release rather than a previously reviewed version.
  5. Malicious code executes during installation, command invocation, or module import.
  6. The payload operates with the privileges of the user running pip or Python and may access Tencent COS credentials available in the process environment.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the installing user's privileg ...[truncated 347 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin each dependency to an explicitly reviewed version, such as package==X.Y.Z.
  • Store dependencies in a lock file or version-controlled requirements file.
  • Record and enforce cryptographic hashes with pip --require-hashes.
  • Install only from an explicitly trusted package index over authenticated TLS.
  • Review dependency provenance, release signatures, maintainers, and transitive dependencies.
  • Install into a dedicated virtual environment under a non-administrative account.
  • Use automated dependency monitoring, but require review before updating pinned versions.
  • Apply the same controls consistently to the macOS, Linux, and Windows installation instructions.

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:79
Finding

Tencent COS Secret Key Exposed Through Command-Line Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:79-80
Vulnerability Type: Sensitive credential exposure through process arguments and shell history
Risk Level: High

Complete Vulnerable Snippet:

bash
# Configuration (interactive)
coscmd config -a SECRET_ID -s SECRET_KEY -b BUCKET -r REGION

Technical Analysis

The documented command places the Tencent COS Secret ID and Secret Key directly in command-line arguments. Despite the comment describing configuration as interactive, the example passes both credentials on the command line.

Once placeholders are replaced with real credentials, the resulting command may be retained in shell history, terminal transcripts, command audit logs, CI logs, support bundles, or process-monitoring telemetry. On systems whose process visibility permits it, another local process may also inspect command-line arguments while coscmd is running.

The credentials are long-lived cloud authentication material unless separately constrained. Their practical authority is determined by the associated Tencent Cloud identity policy rather than by this command.

Attack Path

  1. A user replaces SECRET_ID and SECRET_KEY with valid Tencent COS credentials.
  2. The user executes the documented coscmd config command.
  3. The shell, terminal, process monitor, audit subsystem, or automation log records the command and its arguments.
  4. A local attacker, log reader, backup operator, telemetry recipient, or other unauthorized party retrieves the exposed values.
  5. The attacker authenticates to Tencent Cloud using the recovered credentials.
  6. The attacker performs COS operations permitted by the credential policy, potentially including object listing, reading, uploading, replacement, deletion, or access-control changes.

Impact Assessment

The attacker obtains the same Tencent Cloud permissions granted to the exposed identity. With narrowly scoped upload-only credential ...[truncated 365 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not place secret keys in command-line arguments.
  • Prefer an interactive credential prompt that suppresses terminal echo, if supported by the tool.
  • Otherwise, use a protected credential file or a platform secret manager and ensure permissions restrict access to the intended account.
  • Use short-lived Tencent Cloud security tokens instead of long-lived static keys wherever possible.
  • Grant only the minimum required bucket, prefix, and operation permissions.
  • Disable shell history around unavoidable sensitive commands and ensure logs redact secrets; this is defense in depth rather than a substitute for safe credential input.
  • Rotate any credentials previously entered through exposed command lines and review cloud audit logs for unauthorized use.
  • Update the documentation so its description and example accurately reflect a secret-safe interactive workflow.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:69
Finding

Documentation Recommends Public Bucket Access for Shareable Links

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:69-71
Vulnerability Type: Unsafe cloud storage access-control guidance
Risk Level: Medium

Complete Vulnerable Snippet:

bash
# Generate a sharing link (valid for 3600 seconds)
# Configure the bucket in the Tencent Cloud COS console as public-read/private-write or public-read/write
# URL format: https://{bucket}.cos.{region}.myqcloud.com/{key}

Related guidance also recommends public-read buckets for permanent links at SKILL.md:131, SKILL.md:147, and SKILL.md:160. The document warns at SKILL.md:161 not to make sensitive files public, but the public-read/write recommendation remains unsafe.

Technical Analysis

Public-read access removes authentication requirements for object retrieval. Public-read/write access is substantially more dangerous because unauthenticated parties may also be able to upload, replace, or otherwise manipulate content, depending on the exact COS policy.

The comment states that a sharing link is valid for 3,600 seconds, but the shown URL is an ordinary public object URL rather than a demonstrated presigned URL. If bucket access remains public, the URL is not inherently limited to 3,600 seconds. This discrepancy can cause users to believe access will expire when it may remain available until the bucket policy or object is changed.

The risk is configuration-dependent and requires a user to apply the documented public access setting. No evidence shows that the project itself changes a bucket policy automatically.

Attack Path

  1. A user follows the Skill and configures a bucket as public-read or public-read/write.
  2. The user uploads an object and distributes or exposes its direct COS URL.
  3. The URL is copied, logged, indexed, guessed, or otherwise obtained by an unintended party.
  4. Under public-read, the party retrieves the object without authentication and potentially after the expected 3,600-second period.

...[truncated 734 chars]

Remediation
View remediation

Remediation Suggestions

  • Remove the public-read/write recommendation entirely.
  • Keep buckets private by default and generate cryptographically signed URLs with explicit, short expiration periods.
  • Provide working SDK examples that generate presigned URLs rather than presenting a public URL as time-limited.
  • If public hosting is an explicit requirement, isolate public assets in a dedicated bucket with no sensitive content.
  • Scope any public policy as narrowly as possible and prohibit unauthenticated write access.
  • Enable bucket-policy checks, access logging, object versioning, and alerts for policy changes.
  • Clearly distinguish permanent public URLs from expiring presigned URLs in the output template and decision tree.
  • Periodically audit bucket ACLs and policies for unintended anonymous access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill description promotes uploading files and generating public share links without an explicit warning that doing so may expose sensitive local data to third-party cloud storage or to the public internet. In this context, the omission is security-relevant because the primary function of the skill is data egress and possible public dissemination.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger conditions are broad enough to activate on common requests involving backups, downloads, or sharing files, which can cause the agent to invoke cloud-upload behavior without sufficiently explicit user intent. In the context of a skill that uploads local files and can create public links, overbroad triggering increases the risk of unintended data transfer or exposure.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This code performs a direct upload of a local file to remote cloud storage, which is a classic data exfiltration primitive if invoked on sensitive files or under ambiguous user intent. The skill context makes this more dangerous because it is explicitly designed to move local files off-host and later discusses public access and sharing, increasing the chance of unintended disclosure.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
client = CosS3Client(config)

# 上传
response = client.upload_file(
    Bucket=bucket,
    Key='filename.txt',
    LocalFilePath='/local/path/file.txt'

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The Windows example also uploads an arbitrary local file to Tencent COS, creating the same cloud exfiltration capability as the Linux/macOS example. Because the skill is cross-platform and intended for general file sharing, the presence of this primitive across environments broadens the attack surface for accidental or unauthorized data transfer.

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
)
client = CosS3Client(config)

response = client.upload_file(
    Bucket=os.getenv('TENCENT_COS_BUCKET'),
    Key='filename.txt',
    LocalFilePath='C:\path\to\file.txt'

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

L085 将该步骤描述为“生成分享链接”,但 L086 的命令名是 generate-download-link,语义上是下载链接而非通用分享链接。结合文档其余部分对“公有读永久链接”和“预签名链接”的区分,这里属于文档表述与实际操作含义不一致。

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.