Back to skill

Security audit

kosmi dj

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly aligned with Kosmi browser automation, but it handles credentials and long-running automation in ways users should review before installing.

Review before installing. Use only a trusted Kosmi room URL, avoid putting reusable passwords in the plugin .env, prefer an already-authenticated encrypted session, and do not run the loop under cron or unattended until the .env loading, URL validation, and /tmp PID/FIFO handling are fixed.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kosmi-connect.sh:35
Finding

Credentials Can Be Submitted to an Untrusted Browser Origin

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kosmi-connect.sh:27
Finding

Configuration Files Are Executed as Arbitrary Shell Code

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/kosmi-loop.sh:46
Finding

Predictable Shared Temporary Files Permit PID, FIFO, and Symlink Abuse

Content
View full analysis
/dev/null)" || true if [[ -n "$OLD_PID" ]] && kill -0 "$OLD_PID" 2>/dev/null; then echo "[kosmi-dj-loop] Stopping existing loop (PID $OLD_PID)..." kill "$OLD_PID" 2>/dev/null || true sleep 1 fi fi echo $$ > "$PID_FILE" cleanup() { rm -f "$PID_FILE" "$STATUS_FILE" # Don't remove FIFO — other processes may be writing to it echo "[kosmi-dj-loop] Stopped." } trap cleanup EXIT write_status() { echo "{\"state\":\"$1\",\"video\":\"${2:-}\",\"timestamp\":\"$(date -Iseconds)\",\"pid\":$$}" > "$STATUS_FILE" } ``` ```bash # Create FIFO if it doesn't exist if [[ ! -p "$QUEUE_FIFO" ]]; then mkfifo "$QUEUE_FIFO" fi ``` ### Technical Analysis The loop uses fixed names in the globally shared `/tmp` directory. It does not create a private directory, verify file ownership, reject symbolic links, set explicit restrictive permissions, or lock the PID file. The PID value is trusted solely because it appears in `/tmp/kosmi-dj-loop.pid`. The script checks whether that PID exists but never verifies that it belongs to another `kosmi-loop.sh` instance. A pre-created or manipulated PID file can therefore cause the script to signal an unrelated process that the current user is allowed to terminate. The status file is overwritten through a predictable path, creating symlink or file-redirection risk where platform protections do not block the ope ...[truncated 1923 chars]
Remediation
View remediation
/cmdline` or another platform-appropriate process identity to confirm it is the expected loop. 7. Validate that PID-file contents contain exactly one safe positive integer. 8. Generate status data with `jq -n --arg` so URLs and other strings are encoded as valid JSON. 9. Validate queued URLs against an explicit scheme and hostname policy before processing them. 10. Remove the FIFO during cleanup when the owning loop created it, or implement a separate authenticated queue service. ]]>

T06 · System Persistence

Warning
Location
SKILL.md:107
Finding

Documentation Encourages Unmanaged Cross-Session Scheduling

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Package Is Installed Globally from the npm Registry

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (16)

Context Leakage

High
Category
Data Exfiltration
Confidence
85% confidence
Finding

Code or instructions that leak agent conversation context to external services, potentially exposing sensitive user interactions.

Content

Scanner excerpt · references/kosmi-ui-map.md (reported line 54)May include surrounding context.

md
| Role | Name Pattern(s) | Purpose |
|---|---|---|
| textbox | `message`, `chat`, `type a message` | Chat input box |
| button | `send` | Send chat message |
| button | `apps`, `add`, `+`, `media` | Open the apps/media modal |
| link | `app`, `add media` | Alternative apps trigger |
| button | `settings`, `gear` | Room settings |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/kosmi-connect.sh (reported line 5)May include surrounding context.

sh
# =============================================================================
# kosmi-connect.sh — Connect to a Kosmi room via agent-browser
#
# Reads .env from plugin root, opens the room URL, handles nickname/login
# prompts, and verifies the agent is in the room.
#
# Usage:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/kosmi-snapshot-debug.sh (reported line 19)May include surrounding context.

sh
# =============================================================================
# kosmi-connect.sh — Connect to a Kosmi room via agent-browser
#
# Reads .env from plugin root, opens the room URL, handles nickname/login
# prompts, and verifies the agent is in the room.
#
# Usage:

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The script automatically loads and sources a .env file from the plugin root, which may contain credentials such as KOSMI_EMAIL and KOSMI_PASSWORD. Sourcing a file executes shell syntax, so if an attacker can modify .env they can achieve arbitrary code execution in the script's context, and the script also broadens exposure of secrets by auto-importing them into the environment for browser automation.

Content

Scanner excerpt · scripts/kosmi-connect.sh (reported line 25)May include surrounding context.

sh
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"

# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The combination of checking for ${PLUGIN_ROOT}/.env and then sourcing it means the script trusts a local file as executable shell input. In this skill context, that is more dangerous because the script handles authentication credentials and drives a browser session, so a poisoned .env could both steal secrets and alter automation behavior.

Content

Scanner excerpt · scripts/kosmi-connect.sh (reported line 27)May include surrounding context.

sh
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
  set -a
  # shellcheck disable=SC1090

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

Referencing the plugin root specifically to load a top-level .env file creates a path to broad secret access that is not necessary for basic Kosmi DJ automation. In this skill context, the loop script is intended to control browser playback, so reaching into shared plugin configuration increases the chance that unrelated API keys or tokens are exposed to this process and any subprocesses it launches.

Content

Scanner excerpt · scripts/kosmi-loop.sh (reported line 30)May include surrounding context.

sh
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"

# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The code conditionally loads .env from disk and then sources it, which can expose credentials and execute attacker-controlled shell content if that file is altered. Because the script subsequently invokes other programs and helper scripts, any exported secrets from .env may propagate beyond the immediate process boundary, amplifying the blast radius.

Content

Scanner excerpt · scripts/kosmi-loop.sh (reported line 32)May include surrounding context.

sh
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
  set -a
  # shellcheck disable=SC1090

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

Referencing and loading the repository-level .env gives this script access to credentials and sensitive configuration unrelated to playing a video in Kosmi. In this skill context, that capability is unjustified and increases risk because browser automation scripts often invoke external tools and may leak environment data through child processes, debugging, or future modifications.

Content

Scanner excerpt · scripts/kosmi-play.sh (reported line 23)May include surrounding context.

sh
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"

# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The conditional block around .env existence is part of a flow that sources and exports all values from that file, effectively granting this simple playback script credential access. Because the skill's purpose is narrow UI automation, loading shared secrets is disproportionate and creates unnecessary exposure if the script or its dependencies mis-handle environment variables.

Content

Scanner excerpt · scripts/kosmi-play.sh (reported line 25)May include surrounding context.

sh
# ---------------------------------------------------------------------------
# Load .env
# ---------------------------------------------------------------------------
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
  set -a
  # shellcheck disable=SC1090

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/kosmi-snapshot-debug.sh (reported line 20)May include surrounding context.

sh
PLUGIN_ROOT="$(cd "$SCRIPT_DIR/../../.." && pwd)"

# Load .env for session name
ENV_FILE="${PLUGIN_ROOT}/.env"
if [[ -f "$ENV_FILE" ]]; then
  set -a
  # shellcheck disable=SC1090

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly instructs operators to store Kosmi room URLs, login credentials, and persistent browser session settings in a .env file and to rely on reusable session state, but it does not warn users that these values are sensitive or that persistent sessions may retain authenticated access. In a browser-automation skill, this increases the chance of accidental credential exposure, misuse of stored sessions, or unintended access to a private room if the environment or session store is shared.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation explicitly recommends persistent browser sessions that store cookies, localStorage, and sessionStorage on disk. In the context of a browser-automation skill for joining and controlling Kosmi rooms, this can retain authentication tokens and room access state across runs, increasing the risk of credential theft, unintended account reuse, or privacy leakage if the host system is shared or compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example shows a password being passed directly on the command line to agent-browser fill, which can expose secrets via shell history, process listings, logs, or terminal recording. In an automation skill, users may copy this pattern into scripts or operational environments, causing accidental credential disclosure beyond the immediate browser interaction.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sources a repository-root .env file and exports all variables into its environment even though this loop only appears to need a narrowly scoped session name. Sourcing .env as shell code is dangerous because it executes arbitrary shell syntax if the file is modified, and exporting every variable also broadens credential exposure to child processes such as agent-browser and helper scripts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script sources a plugin-wide .env file and exports all variables into its environment even though its stated purpose is only to automate Kosmi video playback. Sourcing .env executes shell syntax from that file and unnecessarily exposes unrelated secrets or configuration to this process and any subprocesses, expanding the blast radius if the script, logs, or called tools are compromised.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill describes an auto-loop/background mode that continues until interrupted and writes a PID file, but it does not prominently warn users that the process may keep running autonomously after the initiating interaction. In this context, that can lead to unintended ongoing browser activity, repeated room interaction, resource consumption, and confusion about how to stop the automation.

Content

No source excerpt is available for this finding.