Back to skill

Security audit

TrainingPeaks

Security checks for vulnerabilities and agentic risk

Overview

This TrainingPeaks skill is purpose-aligned but should be reviewed carefully because it asks users to handle and persist a live browser session cookie with limited security warnings.

Install only if you are comfortable giving the skill access to your TrainingPeaks account data. Treat the Production_tpAuth cookie like a password: do not paste it into shared chats, logs, screenshots, shell history, or CI output, and remove ~/.trainingpeaks credentials when you no longer need the skill.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/tp.py:718
Finding

Long-Lived TrainingPeaks Credentials Exposed Through Command Arguments and Plaintext Storage

Content
View full analysis
str | None: """Get cookie from env var or file.""" env = os.environ.get("TP_AUTH_COOKIE") if env: return env.strip() if COOKIE_FILE.exists(): return COOKIE_FILE.read_text().strip() return None def store_cookie(cookie: str) -> None: ensure_config_dir() COOKIE_FILE.write_text(cookie.strip()) # Restrict permissions try: COOKIE_FILE.chmod(0o600) except OSError: pass ``` ```python def save_token_cache(access_token: str, expires_at: float) -> None: ensure_config_dir() TOKEN_FILE.write_text(json.dumps({ "access_token": access_token, "expires_at": expires_at, })) try: TOKEN_FILE.chmod(0o600) except OSError: pass ``` ```python def exchange_cookie_for_token(cookie: str) -> dict: """Exchange Production_tpAuth cookie for OAuth token. Returns the full JSON response from /users/v3/token. """ url = f"{TP_API_BASE}{TOKEN_ENDPOINT}" headers = { "Cookie": f"Production_tpAuth={cookie}", "Accept": "application/json", } status, data = _http_request(url, "GET", headers) ``` ```python # auth p_auth = sub.add_parser("auth", help="Authenticate with a Production_tpAuth cookie") p_auth.add_argument("cookie", help="Value of the Production_tpAuth cookie") ``` The documented invocation also places the secret directly on the command line: ```bash python3 scripts/tp.py auth "" ``` ### Technical Analysis The `Production_tpAuth` value is a browser-session credential. The Skill accepts it as a positional command-line argument, which can expose it t ...[truncated 3503 chars]
Remediation
View remediation
"` example with a hidden-input authentication flow. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises and relies on sensitive capabilities including network access, shell execution, environment-variable access, and file read/write, yet it does not declare any explicit tool scope or permission boundaries. That makes the effective privilege surface opaque to users and host systems, increasing the risk that an agent can access local secrets, persist credentials, or make unintended outbound requests beyond what a user expects from the skill description alone.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to extract a live authentication cookie from their browser and store it locally, then exchanges it for a bearer token, but it does not prominently warn that these are equivalent to account credentials and can enable full account access if exposed. In this context, the danger is elevated because the skill handles real user fitness/account data and encourages persistence of long-lived session material in files and environment variables, which are common leak paths in shells, logs, backups, and CI systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The CLI accepts the TrainingPeaks authentication cookie as a positional command-line argument, which can expose the secret through shell history, process listings, audit logs, and agent telemetry. Because this skill uses cookie-based authentication instead of a scoped API key, disclosure of the cookie can enable full account access and retrieval of highly sensitive personal fitness and profile data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The profile command supports --json and prints the full API response, which includes personal information such as email and athlete identifiers. The code performs this disclosure without any warning in the help text or runtime output about the sensitivity of the data being emitted to the terminal or logs.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.