Back to skill

Security audit

Tencent Cloud COS

Security checks for vulnerabilities and agentic risk

Overview

This Tencent Cloud storage skill is mostly disclosed and purpose-aligned, but it bundles broad cloud mutation authority with risky credential persistence, weak local encryption, arbitrary endpoint overrides, and non-reproducible dependency installation.

Review before installing. Use only a tightly scoped Tencent Cloud sub-account or short-lived STS credentials, avoid root or broad permanent keys, avoid --persist unless necessary, do not rely on .env.enc as strong secret storage, and do not set custom Domain, ServiceDomain, or Protocol unless you have verified the destination. Consider running dependency installation separately in a low-privilege environment before exporting cloud credentials.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cos_node.mjs:97
Finding

Unvalidated COS SDK Endpoint Overrides Can Redirect Authenticated Requests

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/lib/ci_client.mjs:84
Finding

Persisted Credentials Are Encrypted with Publicly Derivable Key Material

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
package.json:11
Finding

Non-Reproducible Dependency Installation Permits Unreviewed Lifecycle Code

Content
View full analysis
&1 | tail -3) ok "项目依赖安装完成" ``` ### Technical Analysis The project does not include a lockfile, and the Tencent COS SDK is declared with a caret version range. Setup invokes `npm install`, allowing npm to resolve a later compatible release and new transitive dependency versions that were not part of the audited package. The installation command also leaves npm lifecycle scripts enabled. Lifecycle scripts from the direct dependency or any transitive dependency can execute arbitrary local code during setup with the privileges of the user running the Skill. At that time, Tencent credentials may already exist in process environment variables because setup explicitly expects credentials to be exported before execution. No malicious dependency was identified in the audited files. The vulnerability is the non-reproducible installation process and its exposure to a future registry, maintainer-account, or transitive-package compromise. ### Attack Path 1. A compatible future version of the SDK or one of its transitive dependencies is compromised, or its maintainer account publishes a malicious update. 2. Because the dependency uses `^2.14.0` and no reviewed lockfile is present, a later setup resolves the compromised version. 3. `scripts/setup.sh --from-env` runs `npm install` while Tencent credentials may be present in the environment. 4. npm executes a malicious `preinstall`, `install`, or `postinstall` lifecycle script. 5. The malicious code reads environment variables, project files, or user-accessible files and can transmit them or modify the local installatio ...[truncated 741 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (103)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · .gitignore (reported line 1)May include surrounding context.

text
.env
.env.enc
.env.enc.bak

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description emphasizes COS/CI service workflows, but the skill also performs local environment setup, dependency installation, credential persistence, encryption/decryption handling, and project file modification. This mismatch is security-relevant because users or orchestrators may approve the skill expecting cloud operations, while the skill also changes the local workstation state and manages sensitive secrets.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 154)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 243)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 607)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 700)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 946)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 1009)May include surrounding context.

md
- `scripts/cos_node.mjs`:COS 存储、写操作、处理作业和通用 CI 能力。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 156)May include surrounding context.

md
- `scripts/preview_gen.mjs`:检索结果的本地批量签名与 HTML 预览生成。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

md
- `scripts/preview_gen.mjs`:检索结果的本地批量签名与 HTML 预览生成。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 178)May include surrounding context.

md
除了入口拦截,`scripts/lib/ci_client.mjs` 的 `cosRequest` 与 `scripts/cos_node.mjs` 的 `cosRequestPromise` 会在请求层再次拒绝 DELETE 请求,双重兜底避免绕过。需要调整隐藏列表时,修改其中的 `STRICT_HIDDEN_ACT

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The skill documents a persistent mode that writes Tencent cloud credentials to a local .env file for later automatic reuse. Persisting high-value API secrets on disk expands the attack surface to local compromise, accidental disclosure, backup leakage, and misuse by other tools in the same workspace, even if the file is chmod 600 and gitignored.

Content

Scanner excerpt · SKILL.md (reported line 236)May include surrounding context.

默认模式:凭证仅存于当前 session,关闭终端后需重新 export

{baseDir}/scripts/setup.sh --from-env

持久化模式:凭证写入项目本地 .env 文件,下次自动读取

{baseDir}/scripts/setup.sh --from-env --persist

text

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The feature table exposes credential-management actions that operate on local .env and .env.enc files, confirming that this skill includes functionality to materialize and manipulate secrets on disk. Combining cloud-admin capabilities with local secret handling in one skill makes accidental exposure and abuse more likely, especially if users invoke operational features without realizing local credentials may also be processed.

Content

Scanner excerpt · SKILL.md (reported line 912)May include surrounding context.

md
| | `upload` → 指向知识库桶 | "上传到知识库" → 上传文档 |
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |

## 安全注意事项

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The documented decrypt capability can restore encrypted credential storage back into plaintext .env form, reintroducing secrets onto disk after they were protected. This weakens the overall secret-handling posture because any workflow that needs decryption can leave recoverable plaintext credentials in the project workspace where other processes or users may access them.

Content

Scanner excerpt · SKILL.md (reported line 913)May include surrounding context.

md
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |

## 安全注意事项

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The custom encryption design derives the key from hostname, username, and project path, which are relatively low-entropy, predictable attributes rather than a true secret or hardware-backed key. Even though the goal is local protection, this scheme may provide weaker-than-expected security and encourages reliance on homegrown secret storage instead of standard secret-management mechanisms.

Content

Scanner excerpt · SKILL.md (reported line 947)May include surrounding context.

md
- 密钥派生:`SHA-256(hostname + username + 项目绝对路径)`
- **加密文件绑定当前机器和用户**,拷贝到其他机器/用户无法解密
- 如需还原明文:`node scripts/cos_node.mjs decrypt-env`
- 清理凭证:`rm -f .env .env.enc`

**其他安全要求**:
- **永远不要在对话中回显** SecretId/SecretKey

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 159)May include surrounding context.

md
| 服务 | 开通 action | 请求 | 关闭 action | 请求 |
| --- | --- | --- | --- | --- |
| 数据万象绑定 | `create-ci-bucket` | `PUT /`,CAM `ci:CreateCIBucket` | `delete-ci-bucket` | `PUT /?unbind`,CAM `ci:DeleteCIBucket` |
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 159)May include surrounding context.

md
| 服务 | 开通 action | 请求 | 关闭 action | 请求 |
| --- | --- | --- | --- | --- |
| 数据万象绑定 | `create-ci-bucket` | `PUT /`,CAM `ci:CreateCIBucket` | `delete-ci-bucket` | `PUT /?unbind`,CAM `ci:DeleteCIBucket` |
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 160)May include surrounding context.

md
| --- | --- | --- | --- | --- |
| 数据万象绑定 | `create-ci-bucket` | `PUT /`,CAM `ci:CreateCIBucket` | `delete-ci-bucket` | `PUT /?unbind`,CAM `ci:DeleteCIBucket` |
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 160)May include surrounding context.

md
| --- | --- | --- | --- | --- |
| 数据万象绑定 | `create-ci-bucket` | `PUT /`,CAM `ci:CreateCIBucket` | `delete-ci-bucket` | `PUT /?unbind`,CAM `ci:DeleteCIBucket` |
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 161)May include surrounding context.

md
| 数据万象绑定 | `create-ci-bucket` | `PUT /`,CAM `ci:CreateCIBucket` | `delete-ci-bucket` | `PUT /?unbind`,CAM `ci:DeleteCIBucket` |
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

请求域名均为 `https://<bucket>.ci.<region>.myqcloud.com`。所有 `delete-*` action 在严格模式下隐藏并拒绝执行;其中 `delete-ci-bucket` 虽使用 `PUT`,仍按解绑删除语义保护。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 161)May include surrounding context.

md
| 数据万象绑定 | `create-ci-bucket` | `PUT /`,CAM `ci:CreateCIBucket` | `delete-ci-bucket` | `PUT /?unbind`,CAM `ci:DeleteCIBucket` |
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

请求域名均为 `https://<bucket>.ci.<region>.myqcloud.com`。所有 `delete-*` action 在严格模式下隐藏并拒绝执行;其中 `delete-ci-bucket` 虽使用 `PUT`,仍按解绑删除语义保护。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 162)May include surrounding context.

md
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

请求域名均为 `https://<bucket>.ci.<region>.myqcloud.com`。所有 `delete-*` action 在严格模式下隐藏并拒绝执行;其中 `delete-ci-bucket` 虽使用 `PUT`,仍按解绑删除语义保护。

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/api_reference.md (reported line 162)May include surrounding context.

md
| 文档处理 | `create-doc-process-bucket` | `POST /docbucket`,CAM `ci:CreateDocProcessBucket` | `delete-doc-process-bucket` | `DELETE /docbucket`,CAM `ci:DeleteDocProcessBucket` |
| 媒体处理 | `create-media-bucket` | `POST /mediabucket`,CAM `ci:CreateMediaBucket` | `delete-media-bucket` | `DELETE /mediabucket`,CAM `ci:DeleteMediaBucket` |
| 智能语音 | `create-asr-bucket` | `POST /asrbucket`,CAM `ci:CreateAsrBucket` | `delete-asr-bucket` | `DELETE /asrbucket`,CAM `ci:DeleteAsrBucket` |
| 文件处理 | `create-file-process-bucket` | `POST /file_bucket`,CAM `ci:CreateFileProcessBucket` | `delete-file-process-bucket` | `DELETE /file_bucket`,CAM `ci:DeleteFileProcessBucket` |

请求域名均为 `https://<bucket>.ci.<region>.myqcloud.com`。所有 `delete-*` action 在严格模式下隐藏并拒绝执行;其中 `delete-ci-bucket` 虽使用 `PUT`,仍按解绑删除语义保护。

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/lib/ci_client.mjs:42