Back to skill

Security audit

Soc Deploy Thehive

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent TheHive/Cortex deployment skill, but it uses insecure defaults and exposes high-value admin credentials and services in ways users should review before installing.

Install only if you are prepared to review and harden the deployment first. Use a strong explicit password, run setup only on an isolated or firewalled host, bind ports to localhost during bootstrap, protect or remove the plaintext credentials file, avoid logging the output, rotate generated keys after setup, and fix the unsafe shell/JSON interpolation before accepting untrusted input.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (7)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:58
Finding

Remote Command Injection Through Unescaped Deployment Parameters

Content
View full analysis
:~/ scp references/docker-compose.yml :~/thehive-cortex/docker-compose.yml ssh "bash ~/setup.sh '' ''" ``` ### Technical Analysis The documented SSH invocation embeds the password and organization name directly in a remote shell command. Wrapping a value in single quotes is not safe if the value itself can contain a single quote. Because the SSH command is interpreted by a shell on the target host, a crafted parameter can close the quoted argument and append arbitrary shell commands. No validation or shell-safe escaping is applied before constructing the command. ### Attack Path 1. An attacker supplies a crafted organization name or password, such as: ```text SOC'; attacker-command; # ``` 2. The agent substitutes that value into the documented SSH command. 3. The resulting remote command is equivalent to: ```bash bash ~/setup.sh '' 'SOC'; attacker-command; #' ``` 4. The remote shell runs `attacker-command` with the privileges of the SSH account. ### Impact Assessment Successful exploitation provides arbitrary command execution on the deployment target as the SSH user. If the SSH user can run Docker, the attacker may be able to mount the host filesystem or start privileged containers, potentially escalating the compromise to the entire host. ]]>
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup.sh:8
Finding

Predictable Default Administrator Password

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/setup.sh:153
Finding

Administrator Passwords and API Keys Exposed in Logs and Plaintext Files

Content
View full analysis
"$DEPLOY_DIR/api-keys.txt" << EOF === TheHive + Cortex Credentials === Generated: $(date) TheHive: URL: http://${HOST_IP}:9000 User: admin@thehive.local Password: $PASSWORD API Key: $THEHIVE_KEY Cortex: URL: http://${HOST_IP}:9001 Superadmin: admin / $PASSWORD Superadmin API Key: $CORTEX_SUPER_KEY Org Admin: $ORG_ADMIN (API key only) Org Admin API Key: $CORTEX_ORG_KEY MCP Connection: THEHIVE_URL=http://${HOST_IP}:9000 THEHIVE_API_KEY=$THEHIVE_KEY CORTEX_URL=http://${HOST_IP}:9001 CORTEX_API_KEY=$CORTEX_SUPER_KEY EOF ``` The credentials are then printed in full: ```bash echo "TheHive Admin: admin@thehive.local / $PASSWORD" echo "TheHive Key: $THEHIVE_KEY" echo "Cortex Super: admin / $PASSWORD" echo "Cortex Super Key: $CORTEX_SUPER_KEY" echo "Cortex Org: $ORG_ADMIN" echo "Cortex Org Key: $CORTEX_ORG_KEY" ``` The skill also passes the password as a command-line argument at `SKILL.md:60`: ```bash ssh "bash ~/setup.sh '' ''" ``` ### Technical Analysis The deployment exposes high-value secrets through several channels: - Terminal output and captured automation logs - Shell and SSH command arguments - Process listings while the script is running - A persistent plaintext credential file - The modified Compose configuration, which receives the Cortex organization API key The file creation relies on the caller's current umask. With a common umask of `022`, the resulting credential file may be readable by other local users. The ...[truncated 939 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/docker-compose.yml:30
Finding

Externally Reachable Unauthenticated Cortex Bootstrap Window Over Cleartext HTTP

Content
View full analysis
/dev/null ``` The API reference explicitly confirms the endpoint's unauthenticated behavior: ```bash # Create superadmin (NO AUTH, only works when zero users) printf '{"login":"admin","name":"Admin","password":"pass","roles":["superadmin"]}' | \ curl -s -X POST http://:9001/api/user \ -H 'Content-Type: application/json' -d @- ``` ### Technical Analysis A Compose mapping such as `9001:9001` normally binds to `0.0.0.0`, making Cortex reachable through every host network interface unless an external firewall blocks it. The service is published before the script invokes the first-user endpoint. Cortex allows an unauthenticated request to create the first superadministrator when no users exist. This crea ...[truncated 1271 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/setup.sh:75
Finding

Unescaped User Inputs Permit JSON Payload Manipulation

Content
View full analysis
/dev/null ``` The same pattern is used for Cortex: ```bash printf '{"login":"admin","name":"Admin","password":"%s","roles":["superadmin"]}' "$PASSWORD" | \ curl -sf -X POST http://localhost:9001/api/user \ -H 'Content-Type: application/json' -d @- > /dev/null ``` The organization name is inserted into a double-quoted JSON string without JSON escaping: ```bash curl -sf -X POST http://localhost:9001/api/organization \ -H "Cookie: CORTEX_SESSION=$CX_SESSION; CORTEX-XSRF-TOKEN=$CSRF" \ -H "X-CORTEX-XSRF-TOKEN: $CSRF" \ -H 'Content-Type: application/json' \ -d "{\"name\":\"$ORG_NAME\",\"description\":\"$ORG_NAME organization\",\"status\":\"Active\"}" > /dev/null ORG_ADMIN="$(echo "$ORG_NAME" | tr '[:upper:]' '[:lower:]')-admin" printf '{"name":"%s Admin","roles":["read","analyze","orgadmin"],"organization":"%s","login":"%s"}' \ "$ORG_NAME" "$ORG_NAME" "$ORG_ADMIN" | \ curl -sf -X POST http://localhost:9001/api/user \ -H "Cookie: CORTEX_SESSION=$CX_SESSION; CORTEX-XSRF-TOKEN=$CSRF" \ -H "X-CORTEX-XSRF-TOKEN: $CSRF" \ -H 'Content-Type: application/json' -d @- > /dev/null ``` ### Technical Analysis `printf` and shell interpolation do not JSON-escape quotation marks, backslashes, newlines, or control characters. An input containing JSON syntax can terminate the intended string and add or alter object members. Inputs containing ordinary special characte ...[truncated 1160 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/docker-compose.yml:4
Finding

Container Images Are Not Pinned to Immutable Digests

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
references/docker-compose.yml:16
Finding

Elasticsearch Authentication Is Explicitly Disabled

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (24)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
See `references/gotchas.md` for full details:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The documentation explicitly shows unauthenticated creation of a Cortex superadmin and notes that it works when zero users exist, but it does not emphasize the takeover risk during initial exposure. In the context of a deployment skill, this is dangerous because operators may expose port 9001 before bootstrap completes, allowing anyone with network access to race the initialization and seize superadmin control.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill clearly performs shell-based actions over SSH/SCP and orchestrates deployment on a remote host, but it does not declare any tool scope such as permissions or allowed-tools. That omission weakens least-privilege controls and can allow broader-than-expected execution by an agent runtime, especially for a skill that handles credentials and writes files remotely.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrase "incident response platform" is broad enough that an agent may invoke this deployment skill in contexts where the user intended discussion, evaluation, or use of an existing platform rather than installation. In this case, mistaken invocation is more dangerous than usual because the skill performs remote deployment and account/API-key provisioning on a live host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill creates administrator credentials and API keys, then stores them in a plaintext file on the remote host, but the description does not clearly warn users about this persistence. That can lead to accidental exposure through shell history, backups, other local users, or later compromise of the target system.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 8)May include surrounding context.

Authentication

bash
# Login (returns THEHIVE-SESSION cookie)
curl -s -D - -X POST http://<host>:9000/api/v1/login \
  -H 'Content-Type: application/json' \
  -d '{"user":"admin@thehive.local","password":"secret"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This markdown file documents password changes and API key renewal, including that the key is returned in plain text, but it does not warn readers to protect secrets, avoid shell history leakage, or handle returned credentials securely. Under the markdown-file criteria, behaviors affecting account security and privacy should include explicit warnings.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 21)May include surrounding context.

bash
# Change password (CORRECT endpoint)
printf '{"currentPassword":"old","password":"new"}' | \
curl -s -X POST "http://<host>:9000/api/v1/user/<login>/password/change" \
  -H "Cookie: THEHIVE-SESSION=<session>" \
  -H 'Content-Type: application/json' -d @-

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

This example performs unauthenticated superadmin creation over HTTP during first-time setup. In deployment context, that combination is dangerous because it advertises a security-critical bootstrap path that can be intercepted on the network or abused by any reachable party before initialization is locked down.

Content

Scanner excerpt · references/api-reference.md (reported line 49)May include surrounding context.

Create superadmin (NO AUTH, only works when zero users)

printf '{"login":"admin","name":"Admin","password":"pass","roles":["superadmin"]}' |
curl -s -X POST http://:9001/api/user
-H 'Content-Type: application/json' -d @-

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 57)May include surrounding context.

bash
# Login (returns CORTEX_SESSION cookie)
printf '{"user":"admin","password":"pass"}' | \
curl -s -D - -X POST http://<host>:9001/api/login \
  -H 'Content-Type: application/json' -d @-

# Get CSRF token (make GET with session, capture CORTEX-XSRF-TOKEN cookie)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 76)May include surrounding context.

md
# Create org admin
printf '{"name":"Admin","roles":["read","analyze","orgadmin"],"organization":"SOC","login":"soc-admin"}' | \
curl -s -X POST http://<host>:9001/api/user \
  -H "Cookie: CORTEX_SESSION=<s>; CORTEX-XSRF-TOKEN=<csrf>" \
  -H "X-CORTEX-XSRF-TOKEN: <csrf>" \
  -H 'Content-Type: application/json' -d @-

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/gotchas.md (reported line 32)May include surrounding context.

md
## Bash Exclamation Marks

- Passwords with `!` break curl JSON due to bash history expansion
- `-d '{"password":"Foo!"}'` causes parse errors
- **Fix:** Always use `printf '...' | curl -d @-`

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 124)May include surrounding context.

md
- Passwords with `!` break curl JSON due to bash history expansion
- `-d '{"password":"Foo!"}'` causes parse errors
- **Fix:** Always use `printf '...' | curl -d @-`

## Cortex First-User Endpoint

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/gotchas.md (reported line 34)May include surrounding context.

md
- Passwords with `!` break curl JSON due to bash history expansion
- `-d '{"password":"Foo!"}'` causes parse errors
- **Fix:** Always use `printf '...' | curl -d @-`

## Cortex First-User Endpoint

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.sh (reported line 39)May include surrounding context.

sh
# Wait for Elasticsearch
echo "[2/11] Waiting for Elasticsearch..."
for i in $(seq 1 30); do
  if curl -sf http://localhost:9200/_cluster/health > /dev/null 2>&1; then
    echo "  Elasticsearch is up!"
    break
  fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The password-change request sends a new administrator password over plain HTTP, even though it targets localhost. While local loopback reduces network exposure, plaintext transport can still be captured by local malware, debugging proxies, container networking misconfigurations, or if the endpoint is later rebound off-host; in a security-platform deployment, handling admin credentials insecurely is especially risky.

Content

Scanner excerpt · scripts/setup.sh (reported line 79)May include surrounding context.

sh
# TheHive: Change password
echo "[6/11] TheHive: Changing admin password..."
printf '{"currentPassword":"secret","password":"%s"}' "$PASSWORD" | \
curl -sf -X POST "http://localhost:9000/api/v1/user/admin@thehive.local/password/change" \
  -H "Cookie: THEHIVE-SESSION=$TH_SESSION" \
  -H 'Content-Type: application/json' -d @- > /dev/null

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This request submits the Cortex superadmin password in plaintext over HTTP to create a highly privileged account. Because the created account governs the incident-response platform, compromise of this request can lead to full administrative control over investigations, analyzers, and integrations.

Content

Scanner excerpt · scripts/setup.sh (reported line 96)May include surrounding context.

sh
# Cortex: Create superadmin
echo "[8/11] Cortex: Creating superadmin..."
printf '{"login":"admin","name":"Admin","password":"%s","roles":["superadmin"]}' "$PASSWORD" | \
curl -sf -X POST http://localhost:9001/api/user \
  -H 'Content-Type: application/json' -d @- > /dev/null

# Cortex: Login + get CSRF

External Transmission

Medium
Category
Data Exfiltration
Confidence
85% confidence
Finding

The login call transmits the Cortex admin password over plain HTTP and obtains an authenticated session cookie from response headers. Even on localhost, this creates an opportunity for credential or session theft in hostile local environments, and the session grants privileged access needed for further provisioning.

Content

Scanner excerpt · scripts/setup.sh (reported line 101)May include surrounding context.

sh
# Cortex: Login + get CSRF
CX_SESSION=$(printf '{"user":"admin","password":"%s"}' "$PASSWORD" | \
curl -s -D - -X POST http://localhost:9001/api/login \
  -H 'Content-Type: application/json' -d @- 2>&1 | \
  grep -i 'CORTEX_SESSION' | head -1 | sed 's/.*CORTEX_SESSION=//;s/;.*//' | tr -d '\r')

External Transmission

Medium
Category
Data Exfiltration
Confidence
77% confidence
Finding

This request retrieves a CSRF/XSRF token over plain HTTP while authenticated with an active session cookie. Although the token itself is not a password, exposure of the session cookie and anti-CSRF token together can enable unauthorized authenticated actions against Cortex.

Content

Scanner excerpt · scripts/setup.sh (reported line 105)May include surrounding context.

sh
-H 'Content-Type: application/json' -d @- 2>&1 | \
  grep -i 'CORTEX_SESSION' | head -1 | sed 's/.*CORTEX_SESSION=//;s/;.*//' | tr -d '\r')

CSRF=$(curl -s -D - http://localhost:9001/api/user/admin \
  -H "Cookie: CORTEX_SESSION=$CX_SESSION" 2>&1 | \
  grep 'CORTEX-XSRF-TOKEN' | head -1 | sed 's/.*CORTEX-XSRF-TOKEN=//;s/;.*//' | tr -d '\r')

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.sh (reported line 111)May include surrounding context.

sh
# Cortex: Create org
echo "[9/11] Cortex: Creating org '$ORG_NAME'..."
curl -sf -X POST http://localhost:9001/api/organization \
  -H "Cookie: CORTEX_SESSION=$CX_SESSION; CORTEX-XSRF-TOKEN=$CSRF" \
  -H "X-CORTEX-XSRF-TOKEN: $CSRF" \
  -H 'Content-Type: application/json' \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/setup.sh (reported line 121)May include surrounding context.

sh
ORG_ADMIN="$(echo "$ORG_NAME" | tr '[:upper:]' '[:lower:]')-admin"
printf '{"name":"%s Admin","roles":["read","analyze","orgadmin"],"organization":"%s","login":"%s"}' \
  "$ORG_NAME" "$ORG_NAME" "$ORG_ADMIN" | \
curl -sf -X POST http://localhost:9001/api/user \
  -H "Cookie: CORTEX_SESSION=$CX_SESSION; CORTEX-XSRF-TOKEN=$CSRF" \
  -H "X-CORTEX-XSRF-TOKEN: $CSRF" \
  -H 'Content-Type: application/json' -d @- > /dev/null

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script injects a live Cortex API key directly into docker-compose.yml, causing a secret to be embedded in a configuration file that is likely to be reused, copied, committed, or viewed by others. This expands the exposure surface of a privileged credential beyond runtime memory into long-lived infrastructure artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script writes administrator passwords and multiple live API keys to a plaintext file on disk, creating a durable secret store with no permission hardening or operator warning. On multi-user systems, in backups, or if the home directory is later exposed, these credentials can be reused to fully administer TheHive and Cortex.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script prints administrative passwords and API keys to stdout, which can leak into terminal scrollback, shell session recordings, CI/CD logs, remote management consoles, or support transcripts. Because these are fully privileged credentials, any observer of the output can immediately take over the deployed incident-response platform.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.