Back to skill

Security audit

C.R.A.B Deploy Agent

Security checks for vulnerabilities and agentic risk

Overview

This skill is a deployment helper, but its approval and deployment claims do not match the included script and its local state handling can affect files outside its intended state folder.

Review this skill carefully before installing. Do not rely on it for real approval-gated deployment control, and do not treat its reported GitHub or Cloudflare deployment status as authoritative. Use only simple deployment names, avoid storing broad Cloudflare tokens as shown, and prefer pinned dependencies and lockfile-based builds.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/deploy-agent.sh:27
Finding

Path Traversal Enables Unauthorized State File Access and Deletion

Content
View full analysis
"$file" log "State saved for: $name" } ``` The same unsafe path is used when initializing and cancelling deployments: ```bash local state_file=$(get_state_file "$name") if [ -f "$state_file" ]; then error "Deployment '$name' already exists. Use 'deploy-agent status $name' or 'deploy-agent cancel $name'" exit 1 fi cat > "$state_file" <
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/deploy-agent.sh:379
Finding

Dynamic jq Program Construction Allows State Corruption and Injection

Content
View full analysis
"$(get_state_file "$name")" ``` ```bash info "Would run: wrangler pages deploy --project-name=$name" info "Would run: wrangler pages domain $domain_name --project=$name" # Update state echo "$state" | jq ".step = 4 | .status = 'deployed' | .domain = \"$domain_name\"" > "$(get_state_file "$name")" ``` Initial state is also created using unescaped input: ```bash cat > "$state_file" <
Remediation
View remediation
"$tmp"; then chmod 600 "$tmp" mv -f "$tmp" "$state_file" else rm -f "$tmp" error "Failed to update deployment state" exit 1 fi ``` 4. Validate repository names and domains according to their respective GitHub and DNS naming rules. 5. Validate generated state with `jq -e` before replacing any existing file. 6. Add tests for quotes, backslashes, newlines, Unicode control characters, and jq metacharacters. ]]>

T08 · Insecure Dependencies

Warning
Location
SKILL.md:171
Finding

Unpinned npm Installation and npx Execution Create Supply-Chain Risk

Content
View full analysis
Remediation
View remediation

other

Warning
Location
scripts/deploy-agent.sh:189
Finding

Approval and Deployment Success States Are Recorded Without Enforcement or Execution

Content
View full analysis
"$state_file" < "$(get_state_file "$name")" ``` The GitHub operation is not executed, but the state is marked as ready: ```bash # Create repo (would use gh CLI here) # gh repo create "$repo_name" --public --description "Deployed with C.R.A.B Deploy Agent" # For now, just show what would happen info "Would run: gh repo create $repo_name --public" info "Then: git remote add origin https://github.com/user/$repo_name" info "Then: git add -A && git commit && git push" # Update state echo "$state" | jq ".step = 3 | .status = 'github_ready' | .repo_url = \"https://github.com/user/$repo_name\"" > "$(get_state_file "$name")" ``` The Cloudflare operation is also not executed, but the state is marked as deployed: ```bash # This is what wrangler would do: # wrangler pages deploy --project-name="$name" --branch=main # For custom domain: # wrangler pages domain "$domain_name" --project="$name" info "Would run: wrangler pages deploy --project-name=$name" info "Would run: wrangler pages domain $domain_name --project=$name" # Update state echo "$state" | jq ".step = 4 | .status = 'deployed' | .domain = \"$domain_name\"" > "$(get_state_file "$name")" ``` ### Tec ...[truncated 1920 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill description promises human approval at each stage, but the documented behavior indicates approvals are not actually enforced and deployment actions may be simulated or differ from what users expect. In a deployment skill that touches GitHub, Cloudflare, and local state, this mismatch is security-relevant because operators may rely on controls that do not exist and may misunderstand what data is read or written.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The cancel command is presented as aborting and cleaning up the deployment, but the documentation does not specify what local files, remote repositories, deployments, or state artifacts are removed. Ambiguous destructive behavior can lead to unintended data loss or deletion of resources the user did not realize would be affected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation instructs users to place a Cloudflare API token in a home-directory config file without any warning about credential sensitivity, least privilege, or storage hygiene. This increases the chance of unsafe token handling, overprivileged credentials, and accidental disclosure through shell history, screenshots, backups, or shared environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documentation tells users to execute npx @cloudflare/next-on-pages without pinning an exact version. That can pull a newer package at execution time, creating a supply-chain risk and making builds non-reproducible if a compromised or breaking release is published.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill metadata and user-facing text promise human approval at each deployment step, but the implementation transitions workflow state automatically and records progress without any approval capture or verification. In an agentic deployment context, this can mislead operators into believing guardrails exist when they do not, increasing the chance of unauthorized or premature repository and deployment actions once the placeholder commands are implemented.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script reports GitHub and Cloudflare stages as ready or complete even though it only prints 'Would run' messages and never performs or validates those actions. This creates a dangerous integrity gap: downstream users or automation may trust the recorded state and act on nonexistent repositories or deployments, potentially causing release confusion, missed security checks, or unsafe follow-on operations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The cancel path deletes deployment state immediately without any confirmation or safety checks. In a deployment workflow tool, accidental or scripted invocation can erase progress, approvals, and audit context, making recovery or review harder even if the impact is limited to local state.

Content

No source excerpt is available for this finding.

Ssd 3

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

Showing a plaintext API token assignment in a config example can normalize storing sensitive credentials directly in files and can lead users to paste real secrets into insecure locations. While the example uses a placeholder, the pattern still encourages a practice that increases accidental secret exposure risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.