Back to skill

Security audit

Tabussen

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Swedish public-transit planning skill that uses bundled shell scripts and the documented ResRobot API, with no evidence of hidden persistence, destructive behavior, or unrelated data access.

Install only if you are comfortable sending trip-planning queries to ResRobot/Trafiklab. Use a dedicated low-privilege ResRobot API key, avoid running with shell tracing or process logging, and rotate the key if you suspect local command-line exposure.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
journey.sh:104
Finding

ResRobot API Key Exposed Through the curl Process Command Line in Journey Search

Content
View full analysis
/cmdline` or process-monitoring utilities. Access depends on the host's user isolation, `/proc` configuration, and tracing restrictions, but a sufficiently privileged local process may capture the credential. Query-string credentials may also be exposed if command execution, process telemetry, or diagnostic data is recorded by surrounding automation. ### Attack Path 1. A victim configures a valid `RESROBOT_API_KEY`. 2. The victim invokes `journey.sh`. 3. The shell expands `${PARAMS}`, including `accessId=${API_KEY}`, into the URL passed to `curl`. 4. While `curl` is active, a local attacker or monitoring process with sufficient process-inspection privileges reads the command line. 5. The attacker extracts the API key from the `accessId` query parameter. 6. The attacker reuses the credential to make unauthorized ResRobot API requests. ### Impact Assessment The issue does not directly grant shell execution or elevated operating-system privileges. It can disclose the victim's Trafiklab/ResRobot API credential to a local actor capable of inspecting the process. ...[truncated 314 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
search-location.sh:44
Finding

ResRobot API Key Exposed Through the curl Process Command Line in Location Search

Content
View full analysis
` in clear text. HTTPS protects the request during network transmission but does not conceal command-line arguments from authorized local process inspection. Depending on the operating system's process-isolation settings, a local user, privileged service, endpoint-monitoring agent, or other process with sufficient access may observe the complete curl command through process listings or `/proc//cmdline`. The URL may additionally be retained by command auditing, process telemetry, or diagnostic tooling configured to capture process arguments. ### Attack Path 1. A victim exports a valid `RESROBOT_API_KEY`. 2. The victim runs `search-location.sh`. 3. The shell expands `${API_KEY}` into the URL passed to `curl`. 4. A concurrent local attacker or monitoring process with sufficient privileges captures curl's process arguments. 5. The attacker parses the key from the `accessId` query parameter. 6. The captured key is reused for unauthorized API calls or quota consumption. ### Impact Assessment Successful exploitation exposes the user's Trafiklab/ResRobot API credential. It does not inherently provide local code execution, persistence, or privilege escalation. The attacker can exercise the permissions available to the stolen key, including making API requests attributed to the victim and consuming associated request quotas. Abuse could lead to rate limiting or quo ...[truncated 80 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill instructs the agent to run shell commands like ./search-location.sh and ./journey.sh but does not declare any explicit tool scope such as allowed-tools or permissions. That creates an authorization gap where an agent or host may permit broader shell access than intended, increasing the blast radius if the skill or surrounding inputs are abused.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 514)May include surrounding context.

md
# Configuration
API_KEY="${RESROBOT_API_KEY:-YOUR_API_KEY_HERE}"
BASE_URL="https://api.resrobot.se/v2.1/location.name"

# Arguments
QUERY="$1"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · journey.sh (reported line 9)May include surrounding context.

sh
# Configuration
API_KEY="${RESROBOT_API_KEY:-YOUR_API_KEY_HERE}"
BASE_URL="https://api.resrobot.se/v2.1/location.name"

# Arguments
QUERY="$1"

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · search-location.sh (reported line 9)May include surrounding context.

sh
# Configuration
API_KEY="${RESROBOT_API_KEY:-YOUR_API_KEY_HERE}"
BASE_URL="https://api.resrobot.se/v2.1/location.name"

# Arguments
QUERY="$1"

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The document states that all times are Swedish local time, which imposes a locale-specific interpretation on time handling. While the skill is region-specific, the file does not explicitly tell the agent to confirm or disclose this locale assumption to users who may be outside Sweden or using another locale.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell script sends the user-provided location query to the ResRobot API and includes the access token in the request, which is a network operation covered by the missing-warning rule for code files. While the script's purpose implies location lookup, there is no explicit disclosure in output or comments warning that the query is transmitted to a third-party service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The natural-language guidance explicitly centers Swedish characters and Swedish place-name examples, which can amount to a locale-specific policy constraint when no opt-in or justification is provided. There is no accompanying explanation that the skill is intentionally Sweden-specific or that users may supply other locales where supported.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.