Back to skill

Security audit

codropshiping-product-search

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised product search, but it asks for an API token on the command line and sends it to an underdocumented test endpoint.

Review before installing. Use only a low-privilege, revocable Codrop token, avoid placing production secrets directly in command lines, and confirm that test-codrop.cargosoon.online is the intended endpoint for your account before running searches.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/product-search.js:14
Finding

Authentication Token Exposed Through Command-Line Arguments and Sent to a Hard-Coded Test Endpoint

Content
View full analysis
--token= ``` ```markdown - `--token=`: **(Required)** Your authentication token for the Codrop API. ``` The script reads that argument and sends it as an HTTP header to a hard-coded testing hostname: ```js const keyword = args.keyword; const token = args.token; ``` ```js const options = { hostname: 'test-codrop.cargosoon.online', path: '/api/shipping/Goods/ProductSearchKeywordQuery', method: 'POST', headers: { 'Content-Type': 'application/json', 'Content-Length': Buffer.byteLength(postData), 'token': token } }; ``` ### Technical Analysis Passing credentials through command-line arguments is an insecure secret-handling practice. Depending on the operating system and execution environment, command arguments may be exposed through: - Shell command history. - Process inspection utilities and process metadata. - Monitoring, telemetry, or diagnostic systems that record process invocations. - CI/CD logs, wrapper scripts, or terminal session recordings. The recovered token may remain useful after the process terminates because it is an API credential rather than an ephemeral value generated exclusively for the process. The token is subsequently transmitted over HTTPS to the hard-coded hostname `test-codrop.cargosoon.online`. HTTPS provides transport confidentiality and server authentication when certificate validation succeeds, but it does not prevent prior local disclosure through process arguments. Moreover, `SKILL.md` refers only to the generic “Codrop API” and does not identif ...[truncated 1541 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to supply an authentication token on the command line and includes a realistic token example, but provides no warning about credential sensitivity. Command-line secrets are commonly exposed through shell history, process listings, logs, screenshots, and CI output, which can lead to token disclosure and unauthorized API access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This code constructs an outbound HTTPS POST request and includes the provided token in the request headers. While the script requires the token argument, it does not include any confirmation prompt, warning comment, or user-facing notice that credentials and search input will be sent to a remote host.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.