Back to skill

Security audit

Bitwarden CLI

Security checks for vulnerabilities and agentic risk

Overview

This Bitwarden CLI skill is purpose-aligned but needs review because its examples can expose real vault secrets and keep an unlocked vault session active in a persistent shell.

Review before installing. Use this only in trusted sessions, avoid asking an agent to print secrets, prefer narrowly scoped secret passing, unset BW_SESSION and other secret variables promptly, run bw lock when done, and be cautious with any examples that create/edit vault records or write attachments to disk.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:59
Finding

Decrypted Bitwarden Secrets Exposed Through Standard Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:59-74; references/cli-examples.md:13-59; references/cli-examples.md:115-127
Vulnerability Type: Decrypted secret disclosure through agent-visible command output
Risk Level: High

Vulnerable Code

SKILL.md:59-74

bash
# Get password by item name
bw get password "GitHub"

# Get username
bw get username "GitHub"

# Get TOTP code
bw get totp "GitHub"

# Get full item as JSON
bw get item "GitHub"

# Get specific field
bw get item "GitHub" | jq -r '.fields[] | select(.name=="api_key") | .value'

# List all items
bw list items

references/cli-examples.md:13-59

bash
# Simple lookup (requires unique name)
bw get password "GitHub"

# If multiple items match, use item ID
bw get password 12345678-1234-1234-1234-123456789012

# Get username
bw get username "GitHub"

# Returns current 6-digit code
bw get totp "GitHub"

# Get full item (JSON)
bw get item "GitHub"

# Pretty print
bw get item "GitHub" | jq .

# Extract specific login fields
bw get item "GitHub" | jq -r '.login.username'
bw get item "GitHub" | jq -r '.login.password'
bw get item "GitHub" | jq -r '.login.totp'

# List all custom fields
bw get item "AWS Credentials" | jq '.fields'

# Get specific custom field by name
bw get item "AWS Credentials" | jq -r '.fields[] | select(.name=="access_key") | .value'

# Get hidden field
bw get item "AWS Credentials" | jq -r '.fields[] | select(.name=="secret_key") | .value'

# Get note content
bw get notes "My Secure Note"

# Full item with metadata
bw get item "My Secure Note" | jq -r '.notes'

references/cli-examples.md:115-127

bash
# Single credential
export GITHUB_TOKEN=$(bw get password "GitHub Token")

# Multiple credentials
export AWS_ACCESS_KEY_ID=$(bw get item "AWS" | jq -r '.fields[] | select(.name=="access_key") | .value')
export AWS_SECRET_ACCESS_KEY=$(bw get ite
...[truncated 3002 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove examples that directly print passwords, TOTP values, secure notes, hidden fields, or complete vault items to stdout.
  2. Explicitly prohibit agents from returning retrieved secret values in tool output, chat responses, logs, or diagnostic messages.
  3. Provide a hardened wrapper that retrieves only the required field and passes it directly to a narrowly scoped child process without returning secret-bearing stdout.
  4. Disable shell tracing with set +x before any secret operation and ensure command runners do not echo expanded commands or environment values.
  5. Avoid complete-item retrieval when only one field is needed. Apply least-data-access principles to every vault operation.
  6. Require explicit user confirmation before accessing sensitive vault fields, especially passwords, TOTP material, secure notes, and administrative credentials.
  7. Configure execution frameworks to redact known secret-bearing outputs and prevent tool results from being persisted in telemetry or conversation history.
  8. Unset temporary secret variables immediately after use, restrict child-process inheritance, and run bw lock as soon as the operation is complete.
  9. Document residual risks of environment-variable injection, including exposure through process inspection, crash reports, debugging tools, and inherited environments.
  10. Add automated documentation checks that reject examples containing direct secret-output patterns such as bw get password, bw get totp, unfiltered bw get item, and jq -r extraction of secret fields unless output is safely contained.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Showing export BW_SESSION=$(bw unlock --raw) without any handling guidance normalizes storing a sensitive session token in a shell environment, where it may be inherited by subprocesses, exposed to logs, or recovered from shell/session artifacts. Because BW_SESSION grants vault access for the unlocked session, leakage can directly enable unauthorized secret access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

These examples print passwords, usernames, TOTP codes, notes, and item JSON directly to the terminal, but do not warn that terminal output may be captured by scrollback, logging, recordings, shared sessions, or agent transcripts. In this skill context, the content is specifically about retrieving real vault secrets, so omission of output-safety guidance materially increases leakage risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

These examples encourage exporting secrets into environment variables and command lines without warning about exposure through shell history, process inspection, logs, child processes, or accidental debugging output. In an agent or automation context, that increases the chance that high-value credentials are propagated beyond the intended boundary and leaked.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest says this skill is for installing the Bitwarden CLI, authenticating, or reading secrets from the vault. This file documents write-capable operations such as bw create item and bw edit item, which modify vault contents rather than merely setting up, authenticating, or reading.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/get-started.md (reported line 37)May include surrounding context.

Snap (Linux)

bash
sudo snap install bw

Native Executables

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/get-started.md (reported line 47)May include surrounding context.

Snap (Linux)

bash
sudo snap install bw

Native Executables

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The guide tells users to place Bitwarden API credentials and the unlocked vault session token into environment variables without warning that these values are highly sensitive. Environment variables can be exposed through shell history, process inspection, logging, inherited subprocesses, CI job output, or persistent shell/tmux sessions, which could allow an attacker to authenticate to Bitwarden or access an already-unlocked vault.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The tmux guidance encourages preserving an authenticated Bitwarden CLI session across time without explaining the risk of leaving an unlocked vault token active in a persistent terminal session. If the tmux session is left attached, accessible to another local user, captured in backups, or resumed later on a shared or compromised host, the active BW_SESSION could be reused to read vault contents without re-entering the master password.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The manifest emphasizes CLI setup, authentication, and reading secrets from the vault. The documented bw get attachment ... --output ./cert.pem operation exports vault content onto the local filesystem, which is a broader behavior than simply reading a secret value from the CLI output.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.