Back to skill

Security audit

Cloak

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated purpose, but it handles passwords and API keys by sending them to a third-party service with limited disclosure about that trust boundary.

Review this carefully before installing. Use it only if you trust cloak.opsy.sh to receive and handle the secret value, and prefer organization-approved or self-hosted secret-sharing tools for production, administrative, cloud, or high-value credentials. Confirm create, retrieve, and delete actions explicitly because reads and deletes can permanently consume the secret.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Error
Location
SKILL.md:23
Finding

Plaintext Secrets Transmitted to an External Third-Party Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 23–26
Vulnerability Type: External transmission and potential exfiltration of sensitive credentials
Risk Level: High

bash
curl -s -X POST https://cloak.opsy.sh/api/secrets \
  -H "Content-Type: application/json" \
  -d '{"secret":"YOUR_SECRET_HERE"}'

Technical Analysis

The Skill instructs the agent to place API keys, passwords, tokens, or other secrets directly into a JSON request body and transmit that body to the external service https://cloak.opsy.sh.

Although the Skill describes the resulting links as encrypted, the audited project contains only SKILL.md. It provides no client-side encryption implementation, cryptographic design, service implementation, or other evidence demonstrating that the secret is encrypted before reaching the remote server. Based on the documented command, the remote API receives the secret value as plaintext application data inside the HTTPS request.

TLS protects data in transit from passive network observers but does not prevent the destination service, its operators, application logs, monitoring systems, or an attacker who compromises the service from accessing the submitted value.

Attack Path

  1. A user invokes the Skill to share a password, API key, token, or similar credential.
  2. The agent substitutes the sensitive value into the secret property of the JSON request body.
  3. curl sends the value to cloak.opsy.sh.
  4. The external service processes or stores the secret and returns a retrieval identifier and key.
  5. A malicious service operator, compromised server, exposed application log, or attacker with access to the service infrastructure obtains the submitted secret.
  6. The acquired credential is used against the system or account for which it is valid.

Impact Assessment

The exposed privileges depend on the submitted secret. Potential consequences include:

  • Unauthorized access to user, service, database, cloud, or admin ...[truncated 533 chars]
Remediation
View remediation

Remediation Suggestions

  1. Do not send plaintext secrets to an unverified or unapproved third-party service.
  2. Implement authenticated client-side encryption before transmission so the server receives ciphertext only.
  3. Generate and retain the encryption key exclusively on the client. If a URL fragment is used, ensure the fragment is never transmitted to the server.
  4. Use a reviewed authenticated-encryption construction, such as AES-GCM or XChaCha20-Poly1305, through a mature cryptographic library.
  5. Publish and independently review the client implementation and cryptographic protocol rather than relying on an undocumented encryption claim.
  6. Use an organization-approved or self-hosted endpoint with appropriate access controls, audit logging, retention limits, and incident-response procedures.
  7. Prevent plaintext secrets from appearing in shell history, process arguments, debug output, application logs, telemetry, or temporary files.
  8. Obtain explicit user confirmation before transferring any credential to an external service and clearly identify the destination and trust boundary.
  9. Apply short expiration periods and one-time retrieval only as defense-in-depth; these controls do not replace client-side encryption.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

export DB_PASSWORD=$(curl -s -H "X-Cloak-Key: KEY" "https://cloak.opsy.sh/api/secrets/ID" | jq -r .secret)

To file

curl -s -H "X-Cloak-Key: KEY" "https://cloak.opsy.sh/api/secrets/ID" | jq -r .secret > .env.local

text

## Delete without reading

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger "share a secret" is broad natural language that could match many ordinary conversations and cause the skill to activate when a user did not explicitly intend to send sensitive data to this tool. In this skill’s context, accidental activation is especially risky because the skill is designed to handle credentials and transmit them to an external service.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The single-word trigger "cloak" is highly ambiguous and likely to collide with unrelated mentions, making unintended invocation plausible. Because the skill can send or retrieve secrets, accidental activation can lead to disclosure, deletion, or one-time consumption of sensitive data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This command instructs the agent or user to transmit raw secret material to an external third-party service over the network. Even if the service is intended for secure secret sharing, sending credentials off the local system increases exposure to provider compromise, logging, misdelivery, policy violations, and loss of control over highly sensitive data.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

Create a secret

bash
curl -s -X POST https://cloak.opsy.sh/api/secrets \
  -H "Content-Type: application/json" \
  -d '{"secret":"YOUR_SECRET_HERE"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Although the document mentions self-destruction and one-read behavior elsewhere, the operational section does not give a clear, explicit warning immediately around retrieval and deletion that these actions are destructive and irreversible. In a one-time secret workflow, missing that warning can cause accidental secret destruction or premature consumption, breaking recovery and potentially causing service disruption.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The quick-reference section normalizes the external upload of secrets with a concise copy-paste command, reducing friction for transmitting credentials to a third-party service. In practice this can encourage unsafe use, especially if an agent follows the pattern automatically without surfacing the trust and exfiltration implications to the user.

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
| Action | Command |
|--------|---------|
| Create | `curl -s -X POST .../api/secrets -H "Content-Type: application/json" -d '{"secret":"..."}'` |
| Retrieve | `curl -s -H "X-Cloak-Key: KEY" ".../api/secrets/ID"` |
| Delete | `curl -s -X DELETE -H "X-Cloak-Key: KEY" ".../api/secrets/ID"` |
| To env var | `export VAR=$(curl -s -H "X-Cloak-Key: KEY" ".../api/secrets/ID" \| jq -r .secret)` |

Static analysis

No suspicious patterns detected.