Back to skill

Security audit

ACE Copilot

Security checks for vulnerabilities and agentic risk

Overview

This skill is an IBM ACE reference skill with no executable payload, but its admin, deployment, credential, and diagnostic guidance is under-scoped for production use.

Install only if you want ACE-specific development and administration help, and treat its operational examples as templates requiring review. Before using generated commands, confirm the target node/server/environment, avoid inline real passwords, do not expose the ACE admin API outside trusted management networks, use TLS/authentication where applicable, and handle trace or support bundles as sensitive data.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/cli-commands.md:13
Finding

Credentials Passed Directly Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/deployment.md:126
Finding

Administrative REST API Published Without Demonstrated TLS or Access Controls

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (18)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction 'When in doubt, trigger this skill' creates an overly permissive activation rule that can cause the ACE skill to be invoked outside its intended scope. Over-broad invocation increases the chance the agent will apply domain-specific guidance, workflows, or operational suggestions in unrelated contexts, which can lead to unsafe actions, incorrect automation, or leakage of irrelevant privileged context.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
60% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/deployment.md (reported line 129)May include surrounding context.

Via REST API

bash
# Deploy
curl -X POST http://localhost:7600/apiv2/deploy \
  -H 'Content-Type: application/octet-stream' \
  --data-binary @MyApp.bar

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The trigger scope includes generic development actions such as reading JIRA tickets, implementing changes, committing changes, or opening PRs, which are not inherently ACE-specific. This broadens skill activation into common engineering workflows and may let the skill inappropriately steer unrelated repository work, increasing the risk of unintended code changes or misuse of operational instructions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The delete integration node command is inherently destructive and may remove an entire integration node configuration, yet the documentation presents it without caution. In a copilot skill, this can lead to accidental execution by users who treat the reference as safe operational guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented undeploy command deletes all deployed flows from a server, but the reference gives no warning about its destructive effect. In an agent skill context, terse command references can be copied directly into production workflows, increasing the chance of accidental service disruption or total application removal.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The REST deployment example uses plain HTTP for an administrative deployment endpoint and provides no warning about transport security or access control. If reused beyond localhost or in misconfigured environments, BAR contents and deployment actions could be intercepted or modified, leading to unauthorized code deployment.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cli-commands.md (reported line 149)May include surrounding context.

Deploy to Stand-Alone Server (REST API)

bash
curl -X POST http://localhost:7600/apiv2/deploy \
  -H 'Content-Type: application/octet-stream' \
  --data-binary @MyApplication.bar

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples place secrets directly on the command line, exposing passwords through shell history, process listings, logs, and copied documentation. In an agent-assisted environment, users may paste real credentials into these patterns, causing credential leakage and unauthorized access to MQ or databases.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Line L012 states that BAR files are the only way to deploy flows to a running integration server. However, later content documents deployment to a stand-alone integration server via REST API and via mounting BARs into a filesystem/container, which directly contradicts the absolute claim in the earlier documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation includes a destructive delete-and-redeploy procedure without an explicit warning that mqsideploy ... -d removes existing deployments. In an agent skill context, this could be copied into automation or suggested to users, causing accidental service outage or loss of deployed applications in the target integration server.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deployment.md (reported line 129)May include surrounding context.

Via REST API

bash
# Deploy
curl -X POST http://localhost:7600/apiv2/deploy \
  -H 'Content-Type: application/octet-stream' \
  --data-binary @MyApp.bar

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The user trace section explicitly says trace captures message content and path at each node, but it omits a warning that traces may record sensitive payloads, PII, credentials, tokens, or business data. Because the skill provides step-by-step commands to enable debug tracing, it materially increases the chance that sensitive message data will be collected and retained in trace output files.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 181)May include surrounding context.

md
# Check if HTTP listener is active
netstat -an | grep 7800    # default HTTP port

# Test with curl
curl -v http://localhost:7800/flowpath -d '{"test":"data"}' \
  -H 'Content-Type: application/json'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The diagnostic capture guidance tells users to create a comprehensive support bundle containing configuration, logs, flow definitions, and system information, but it does not warn that these artifacts may include secrets, credentials, message payloads, hostnames, or other sensitive operational data. In a troubleshooting skill, users are especially likely to share the resulting archive externally with IBM Support or teammates, increasing the risk of unintended data disclosure.

Content

No source excerpt is available for this finding.

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · references/troubleshooting.md (reported line 296)May include surrounding context.

md
mqsilist

# Check if work directory has correct permissions
ls -la /home/aceuser/ace-server/

# Restart container
docker restart ace-container

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest frames this skill around IBM ACE development and administration tasks, which strongly justifies ACE-specific commands. However, this file also documents raw HTTP deployment using curl against the admin REST API, introducing a general network invocation capability rather than sticking to ACE-native tooling. While related to ACE, exposing generic curl-based remote operations is somewhat broader than the stated CLI-oriented purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown reference includes INSERT and UPDATE examples that perform persistent database modifications, but the surrounding text does not warn that these operations change stored data. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.