Back to skill

Security audit

Bitwarden Vault CLI

Security checks for vulnerabilities and agentic risk

Overview

This Bitwarden CLI skill is mostly coherent, but it should be reviewed because it keeps vault session tokens in persistent shell sessions and includes under-disclosed examples that can modify vault items.

Install only if you are comfortable letting an agent operate Bitwarden CLI commands. Treat BW_SESSION, BW_CLIENTSECRET, and any exported application secrets as live credentials, lock or logout immediately after use, avoid leaving tmux sessions open, and require explicit confirmation before any create or edit command changes vault contents.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The examples encourage exporting secrets into environment variables and command lines without warning that such values may persist in the shell environment, be inherited by child processes, appear in crash dumps, or be exposed through process inspection in some setups. In a secret-management skill, normalizing this pattern increases the chance of accidental credential disclosure during routine use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The attachment example writes potentially sensitive material such as certificates directly to disk without warning about file-permission, residual-data, and unintended-sharing risks. On multi-user systems or developer machines with backups, sync tools, or loose default permissions, this can leave secrets exposed beyond the intended session.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest description limits scope to setting up Bitwarden CLI, authenticating, and reading secrets from the vault. This file additionally documents creating and editing items via bw create item and bw edit item, which are write operations against vault contents rather than setup/auth/read behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The create and edit examples perform state-changing vault operations, including overwriting passwords, without warnings about accidental modification, loss of previous values, or impact on shared/organizational items. In a credential-management context, demonstrating mutation without safeguards can lead users or agents to make unintended, hard-to-reverse changes to sensitive records.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/get-started.md (reported line 37)May include surrounding context.

Snap (Linux)

bash
sudo snap install bw

Native Executables

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/get-started.md (reported line 47)May include surrounding context.

Snap (Linux)

bash
sudo snap install bw

Native Executables

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation tells users to place Bitwarden API credentials in shell environment variables and proceed with login, but it omits any warning about exposure risks. Environment variables can be inherited by child processes, captured in CI logs or shell startup files, and remain visible to other local tooling or users depending on the platform and execution context; in a secret-management skill, that omission materially increases credential-handling risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The tmux guidance recommends exporting BW_SESSION and keeping it alive in a persistent multiplexer session without warning that the unlocked vault token remains usable for the lifetime of that shell/session. Anyone who can attach to the tmux session, read the shell environment, or access session state on the host may be able to reuse the token to access vault contents.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

The manifest emphasizes installing the CLI, authenticating, and reading secrets. The examples also include account/session management actions like bw lock and bw logout, plus server reconfiguration with bw config server, which are adjacent administrative capabilities not clearly stated in the description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.