T09 · Insecure Skill Coding Practices
- Location
references/cli-commands.md:13- Finding
Credentials Passed Directly Through Command-Line Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is an IBM ACE reference skill with no executable payload, but its admin, deployment, credential, and diagnostic guidance is under-scoped for production use.
Install only if you want ACE-specific development and administration help, and treat its operational examples as templates requiring review. Before using generated commands, confirm the target node/server/environment, avoid inline real passwords, do not expose the ACE admin API outside trusted management networks, use TLS/authentication where applicable, and handle trace or support bundles as sensitive data.
references/cli-commands.md:13Credentials Passed Directly Through Command-Line Arguments
references/deployment.md:126Administrative REST API Published Without Demonstrated TLS or Access Controls
The instruction 'When in doubt, trigger this skill' creates an overly permissive activation rule that can cause the ACE skill to be invoked outside its intended scope. Over-broad invocation increases the chance the agent will apply domain-specific guidance, workflows, or operational suggestions in unrelated contexts, which can lead to unsafe actions, incorrect automation, or leakage of irrelevant privileged context.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# Deploy
curl -X POST http://localhost:7600/apiv2/deploy \
-H 'Content-Type: application/octet-stream' \
--data-binary @MyApp.bar
The trigger scope includes generic development actions such as reading JIRA tickets, implementing changes, committing changes, or opening PRs, which are not inherently ACE-specific. This broadens skill activation into common engineering workflows and may let the skill inappropriately steer unrelated repository work, increasing the risk of unintended code changes or misuse of operational instructions.
The delete integration node command is inherently destructive and may remove an entire integration node configuration, yet the documentation presents it without caution. In a copilot skill, this can lead to accidental execution by users who treat the reference as safe operational guidance.
The documented undeploy command deletes all deployed flows from a server, but the reference gives no warning about its destructive effect. In an agent skill context, terse command references can be copied directly into production workflows, increasing the chance of accidental service disruption or total application removal.
The REST deployment example uses plain HTTP for an administrative deployment endpoint and provides no warning about transport security or access control. If reused beyond localhost or in misconfigured environments, BAR contents and deployment actions could be intercepted or modified, leading to unauthorized code deployment.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST http://localhost:7600/apiv2/deploy \
-H 'Content-Type: application/octet-stream' \
--data-binary @MyApplication.bar
The examples place secrets directly on the command line, exposing passwords through shell history, process listings, logs, and copied documentation. In an agent-assisted environment, users may paste real credentials into these patterns, causing credential leakage and unauthorized access to MQ or databases.
Line L012 states that BAR files are the only way to deploy flows to a running integration server. However, later content documents deployment to a stand-alone integration server via REST API and via mounting BARs into a filesystem/container, which directly contradicts the absolute claim in the earlier documentation.
The documentation includes a destructive delete-and-redeploy procedure without an explicit warning that mqsideploy ... -d removes existing deployments. In an agent skill context, this could be copied into automation or suggested to users, causing accidental service outage or loss of deployed applications in the target integration server.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Deploy
curl -X POST http://localhost:7600/apiv2/deploy \
-H 'Content-Type: application/octet-stream' \
--data-binary @MyApp.bar
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
The user trace section explicitly says trace captures message content and path at each node, but it omits a warning that traces may record sensitive payloads, PII, credentials, tokens, or business data. Because the skill provides step-by-step commands to enable debug tracing, it materially increases the chance that sensitive message data will be collected and retained in trace output files.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Check if HTTP listener is active
netstat -an | grep 7800 # default HTTP port
# Test with curl
curl -v http://localhost:7800/flowpath -d '{"test":"data"}' \
-H 'Content-Type: application/json'
The diagnostic capture guidance tells users to create a comprehensive support bundle containing configuration, logs, flow definitions, and system information, but it does not warn that these artifacts may include secrets, credentials, message payloads, hostnames, or other sensitive operational data. In a troubleshooting skill, users are especially likely to share the resulting archive externally with IBM Support or teammates, increasing the risk of unintended data disclosure.
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
mqsilist
# Check if work directory has correct permissions
ls -la /home/aceuser/ace-server/
# Restart container
docker restart ace-container
The manifest frames this skill around IBM ACE development and administration tasks, which strongly justifies ACE-specific commands. However, this file also documents raw HTTP deployment using curl against the admin REST API, introducing a general network invocation capability rather than sticking to ACE-native tooling. While related to ACE, exposing generic curl-based remote operations is somewhat broader than the stated CLI-oriented purpose.
This markdown reference includes INSERT and UPDATE examples that perform persistent database modifications, but the surrounding text does not warn that these operations change stored data. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or system integrity.
No suspicious patterns detected.