Back to skill

Security audit

Appian Listpkg

Security checks for vulnerabilities and agentic risk

Overview

This skill appears intended to list Appian packages, but its credential and configuration handling is broader and less accurately disclosed than users should accept without review.

Review before installing. Use only with trusted APPIAN_BASE_URL values, prefer injected environment secrets, avoid relying on appian.json fallback files, and do not run it from directories where an untrusted parent appian.json could be discovered.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/index.js:43
Finding

API Key May Be Transmitted over Unencrypted HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/index.js:17
Finding

Fallback Credential Loader Searches Undocumented Parent Directories

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill uses sensitive environment variables and makes outbound network requests, but it does not declare an explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability because the runtime capabilities required by the skill are broader than what is formally documented or enforced, increasing the chance of unintended credential exposure or unauthorized external access if the skill is modified or reused.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The security manifest declares file operations as 'none', but the implementation reads appian.json from the current or parent directories and imports those values into process.env. A false security manifest can mislead reviewers, policy engines, or sandbox decisions, causing the skill to be treated as less sensitive than it is while it actually accesses local files and potentially secrets.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The code comments claim there is no file I/O, but credential validation walks parent directories and reads a local appian.json file if present. This mismatch is security-relevant because operators and downstream tooling may trust the documentation and grant the skill access or approvals under false assumptions, while the actual behavior expands the attack surface to local configuration discovery and secret ingestion.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/index.js:32