Back to skill

Security audit

Grocy Inventory

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its Grocy inventory purpose, but it publishes a Grocy API key and includes live commands that can change inventory records.

Review before installing. The Grocy API key shown in the skill should be treated as compromised and rotated or removed, and the skill should use a user-provided secret such as an environment variable. Only allow inventory-changing actions after explicit user confirmation, especially consume, open, transfer, add, inventory audit, and battery charge operations.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:10
Finding

Hardcoded Grocy API Key in Skill Configuration

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–13
Vulnerability Type: Hardcoded authentication secret
Risk Level: High

Vulnerable Code

markdown
## Configuration

| Variable | Value |
|----------|-------|
| URL | `http://localhost:14611` |
| API Key | `mz43yGJzBKfwZdSOwG5EdnKPRrKnCbkGrEFbxXYv2JF61tQ9Mj` |

Technical Analysis

The Skill stores a reusable Grocy API key directly in a versioned Markdown file. Any user, process, distribution recipient, archive, or log with access to the Skill package can recover the credential without authentication.

The key is intended for use in the GROCY-API-KEY request header. The documented Grocy interface includes read operations and state-changing operations such as consuming, opening, transferring, adding, and inventory-auditing products. Consequently, the exposed value is not merely configuration metadata; it is an authentication credential capable of authorizing access within the permissions assigned to the key.

The configured service uses unencrypted HTTP. Its loopback address limits direct network exposure, but it does not protect requests from untrusted local processes or from an attacker who obtains a request-forwarding, proxying, or server-side request forgery capability that can reach the host's loopback interface.

Attack Path

  1. An attacker obtains read access to the Skill package, a repository copy, an archive, or another artifact containing SKILL.md.
  2. The attacker extracts the plaintext API key from line 13.
  3. The attacker gains a request execution path on the Grocy host or another capability that can reach http://localhost:14611.
  4. The attacker sends requests containing:
    http
    GROCY-API-KEY: mz43yGJzBKfwZdSOwG5EdnKPRrKnCbkGrEFbxXYv2JF61tQ9Mj
    
  5. The attacker invokes Grocy endpoints allowed by the key, potentially reading inventory information or modifying stock and battery records.

Exploitat ...[truncated 885 chars]

Remediation
View remediation

Remediation Suggestions

  1. Revoke and rotate the exposed API key immediately; removal from the current file does not invalidate copies already distributed.
  2. Replace the literal credential with a runtime reference such as $GROCY_API_KEY.
  3. Load the secret from a protected environment variable, operating-system credential store, or dedicated secret manager.
  4. Remove the credential from repository history, release archives, cached artifacts, logs, and documentation where feasible.
  5. Restrict access to secret-bearing configuration with least-privilege file permissions.
  6. Assign the replacement key only the minimum Grocy permissions required by the Skill, if Grocy's authorization model supports scoped credentials.
  7. Keep the service bound to a trusted interface and prevent untrusted workloads from accessing the loopback endpoint.
  8. Use HTTPS with certificate validation if the API is ever exposed beyond a strictly trusted loopback context.
  9. Add automated secret scanning to development and release workflows to block future committed credentials.
  10. Use placeholders rather than real credentials in all examples and documentation.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill embeds a live Grocy API key directly in documentation, exposing a reusable secret to anyone who can read the skill file. Because the skill targets a local self-hosted inventory service and includes examples for authenticated state-changing operations, disclosure of this credential can enable unauthorized access and modification of household inventory data.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Publishing the API key in plain text without any secrecy controls or warning normalizes unsafe handling of credentials and makes accidental reuse or leakage likely. An attacker or untrusted skill consumer could use the key to query stock, batteries, and invoke write endpoints such as consume, open, transfer, or charge actions.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

Check Stock (Fridge/Pantry)

bash
curl -s -H "GROCY-API-KEY: $API_KEY" "$URL/api/stock"

Lookup Details by Barcode

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The document enumerates multiple state-changing Grocy endpoints such as add, consume, transfer, inventory, and open without any explicit warning that these actions modify live inventory data. In an agent skill context, this increases the chance that an LLM or user will treat the examples as safe read-only operations and unintentionally alter stock records on the local Grocy instance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example curl command performs a real stock consumption action against the live local Grocy service and is presented without a warning that running it will decrement inventory. In a skill/reference file, executable examples can be copied by users or incorporated by an agent, making accidental modification of household inventory data more likely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/grocy-api.md (reported line 113)May include surrounding context.

Example: Consume Milk via Barcode

bash
curl -s -X POST -H "GROCY-API-KEY: your-api-key" \
  -H "Content-Type: application/json" \
  -d '{"amount": 1, "transaction_type": "consume", "location_id": 6}' \
  "http://localhost:14611/api/stock/products/by-barcode/8998009010620/consume"

Static analysis

No suspicious patterns detected.