Back to skill

Security audit

Appian Deploy

Security checks for vulnerabilities and agentic risk

Overview

The skill performs its stated Appian deployment task, but it has under-disclosed credential/configuration handling and can send API keys and deployment files to an unvalidated endpoint.

Review before installing or running. Use only trusted workspaces, set APPIAN_BASE_URL and APPIAN_API_KEY explicitly, avoid relying on appian.json fallback, verify the endpoint is the intended HTTPS Appian environment, and rotate the API key if this was run with an untrusted or plaintext endpoint.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/index.js:45
Finding

Unvalidated Deployment Endpoint Can Expose API Credentials and Package Data

Content
View full analysis
''); throw new Error(`Deploy trigger failed [${res.status}]: ${text}`); } const data = await res.json(); if (!data.uuid) throw new Error(`No uuid in response: ${JSON.stringify(data)}`); return data; } ``` ```js async function pollStatus(credentials, deploymentUuid) { const pollUrl = `${credentials.baseUrl}/deployments/${deploymentUuid}`; const TERMINAL = new Set([ 'COMPLETED', 'COM ...[truncated 2754 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/index.js:19
Finding

Ancestor-Directory Configuration Discovery Enables Configuration Planting

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill declares network and environment-variable capabilities but does not explicitly scope or constrain them with a permissions or allowed-tools policy. That creates an avoidable trust gap: a caller reviewing only the manifest cannot easily tell what external access is intended, increasing the chance of over-broad execution or misuse if the implementation changes or is replaced.

Content

No source excerpt is available for this finding.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The code reads appian.json from the current or ancestor directories before deployment, but this read is not declared in the manifest, which states file operations are limited to the user-supplied package ZIP. Undeclared filesystem access weakens trust boundaries and enables configuration injection from repository content or surrounding directories, especially in automated agent or CI environments.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill searches parent directories for a local appian.json file and loads APPIAN_BASE_URL and APPIAN_API_KEY from it, even though the manifest says file operations are limited to reading the user-supplied package ZIP. This creates undeclared secret ingestion from the local filesystem and can cause the skill to use unintended credentials or attacker-planted configuration when run in a shared or untrusted workspace.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

Falling back to a local appian.json file expands the credential trust boundary beyond the injected runtime secrets the skill claims to use. This can cause accidental use of stale, developer-local, or attacker-planted credentials from the working directory, which is especially risky in shared repos, CI workspaces, or untrusted directories.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/index.js:32