Back to skill

Security audit

qshare

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent file-sharing purpose, but its implementation can expose more local files than the user selected and ships a hardcoded remote upload credential.

Review carefully before installing. The advertised workflow is understandable, but this version should not be used for sensitive directories because sharing one file may expose neighboring files through the public URL. Avoid the CNB option unless the hardcoded credential has been removed and uploads use clear user-owned credentials or a scoped authorization flow.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
src/qshare/cli.py:225
Finding

TryCloudflare Tunnel Exposes Unintended Sibling Files and Directory Listings

Content
View full analysis

Vulnerability Details

File Location: src/qshare/cli.py:225, 379-410
Vulnerability Type: Improper restriction of files served through a public tunnel
Risk Level: High

Vulnerable code:

python
server = ShareHTTPServer(
    ("127.0.0.1", port),
    partial(ShareHandler, directory=str(file_path.parent)),
)
python
local_url = f"http://127.0.0.1:{resolved_port}/{source.name}"

tunnel_process, tunnel_url = launch_trycloudflare_tunnel(
    local_url,
    timeout_seconds=min(ttl_seconds, 30),
)
public_file_url = build_download_url(tunnel_url, source.name)

Technical Analysis

The local HTTP server uses Python's SimpleHTTPRequestHandler with the selected file's parent directory as its document root. Although the printed URL points to the selected filename, the handler does not enforce a single-file allowlist.

The TryCloudflare tunnel forwards requests to the local HTTP server. Consequently, the remote request path is attacker-controlled, and an unauthenticated visitor can request other filenames or directories beneath the selected file's parent directory. Requests for directories can also invoke the handler's standard directory-listing behavior.

This crosses the intended authorization boundary from sharing one explicitly selected file to exposing additional local content. It also contradicts SKILL.md, which directs the agent not to expose arbitrary local paths, directory listings, or additional files.

Attack Path

  1. The user asks the Skill to share one local file through the default TryCloudflare workflow.
  2. start_local_http_server() configures the selected file's entire parent directory as the HTTP document root.
  3. The tunnel makes that local HTTP service reachable from the Internet.
  4. An unauthenticated visitor obtains the tunnel hostname from the shared URL.
  5. The visitor changes the URL path to /, another known or guessed filename, or a child-directory p ...[truncated 652 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the generic SimpleHTTPRequestHandler behavior with a dedicated handler that serves exactly one canonical URL path.
  • Return 404 Not Found for /, sibling filenames, child directories, URL-encoded path variations, and every path other than the authorized file.
  • Disable directory listing explicitly.
  • Avoid using the selected file's parent directory as a general-purpose document root.
  • Resolve and compare canonical paths before opening a file, ensuring the requested resource exactly equals the user-selected file.
  • Add tests confirming that the selected URL succeeds while /, sibling-file paths, nested paths, traversal forms, and encoded path variants are rejected.

T09 · Insecure Skill Coding Practices

Error
Location
src/qshare/cnb.py:12
Finding

Hardcoded CNB Bearer Token Grants Package Recipients Repository API Authority

Content
View full analysis

Vulnerability Details

File Location: src/qshare/cnb.py:12, 18-20, 33-50
Vulnerability Type: Hardcoded authentication credential
Risk Level: High

Vulnerable code:

python
TOKEN = "67emzlY14b8RDEHMJmuevI6GuON"
REPO = "steinveni/qshare"
API = "https://api.cnb.cool/{}".format(REPO)
python
def request_json(url, method="GET", payload=None):
    headers = {"Accept": ACCEPT, "Authorization": "Bearer " + TOKEN}
    data = None
    if payload is not None:
        headers["Content-Type"] = "application/json"
        data = json.dumps(payload).encode("utf-8")
    request = Request(url, data=data, headers=headers, method=method)
python
release = request_json(
    API + "/-/releases",
    method="POST",
    payload={
        "tag_name": tag,
        "name": tag,
        "body": "Release " + tag,
        "target_commitish": "main",
    },
)

Technical Analysis

A bearer token is embedded directly in distributed application source. Anyone with access to the repository, source archive, wheel contents, or installed Python files can extract and reuse it independently of the application.

The token is sent as the CNB API Authorization credential and is used by code that performs mutating operations, including creating releases and obtaining asset-upload URLs. Therefore, it is an operational credential rather than inert example data.

The CLI's interactive confirmation protects only the normal qshare --cnb execution path. It does not protect the token once disclosed because an attacker can send independent API requests without invoking the CLI or its confirmation function.

Attack Path

  1. An attacker downloads or otherwise reads the publicly distributed project source or installed package.
  2. The attacker extracts the plaintext bearer token from src/qshare/cnb.py.
  3. The attacker constructs direct requests to the configured CNB API and supplies the t ...[truncated 832 chars]
Remediation
View remediation

Remediation Suggestions

  • Revoke the exposed bearer token immediately and issue a replacement only if this workflow still requires one.
  • Remove the credential from the current source and published package artifacts.
  • Review repository history and previously released distributions because deleting the current constant does not remove earlier disclosures.
  • Require users to supply their own CNB credential through a protected environment variable, operating-system credential store, or narrowly permissioned configuration mechanism.
  • Validate that the credential is present only when the CNB upload feature is explicitly invoked.
  • Grant the replacement credential only the minimum repository and release permissions required.
  • Prefer short-lived or delegated upload credentials where supported.
  • Add secret-scanning checks to the development and release process to prevent future credentials from being committed or packaged.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying implementation contains a hardcoded CNB API bearer token, performs undisclosed remote release management, and lacks the described TryCloudflare flow or confirmation logic, this is a critical secret-management and unauthorized-upload issue. Hardcoded credentials combined with misleading documentation strongly suggest covert exfiltration or unauthorized use of third-party resources, especially dangerous in a skill explicitly designed to publish local files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying implementation contains a hardcoded CNB API bearer token, performs undisclosed remote release management, and lacks the described TryCloudflare flow or confirmation logic, this is a critical secret-management and unauthorized-upload issue. Hardcoded credentials combined with misleading documentation strongly suggest covert exfiltration or unauthorized use of third-party resources, especially dangerous in a skill explicitly designed to publish local files.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

If the underlying implementation contains a hardcoded CNB API bearer token, performs undisclosed remote release management, and lacks the described TryCloudflare flow or confirmation logic, this is a critical secret-management and unauthorized-upload issue. Hardcoded credentials combined with misleading documentation strongly suggest covert exfiltration or unauthorized use of third-party resources, especially dangerous in a skill explicitly designed to publish local files.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · src/qshare/cli.py (reported line 539)May include surrounding context.

python
def start_background_process(argv: List[str]) -> int:
    cmd = [sys.executable, "-m", "qshare"] + argv
    env = os.environ.copy()
    env["QSHARE_BACKGROUND_CHILD"] = "1"
    kwargs = {
        "stdin": subprocess.DEVNULL,

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The module is explicitly built to upload arbitrary local files to a fixed third-party CNB release repository using authenticated API calls, and nothing in this file enforces or verifies the promised 'explicit confirmation' before transmission. In a file-sharing skill, silent or programmatic exfiltration to a hard-coded external service is highly dangerous because it can publish sensitive local files outside the user's environment without meaningful user awareness or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
100% confidence
Finding

A hard-coded bearer token embedded in the source grants authenticated access to publish assets to the configured repository. Shipping live credentials inside a file-sharing skill is dangerous because anyone with code access can reuse the token, and the skill can perform privileged remote actions that exceed normal local file-sharing expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The code uses a hard-coded API token on every authenticated request without any user-facing disclosure that local files are being uploaded under a preconfigured account. This creates both a secret-exposure issue and a covert data-transfer issue, since users may believe they are only using a local sharing tool while the skill performs remote authenticated publishing.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: py (CVE-2022-42969 (ReDoS))

High
Category
Supply Chain
Confidence
70% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: pytest==6.2.5 — 2 advisory(ies): CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: pytest==7.4.4 — 2 advisory(ies): CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: pytest==8.3.5 — 2 advisory(ies): CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: pytest==8.4.2 — 2 advisory(ies): CVE-2025-71176 (pytest has vulnerable tmpdir handling); CVE-2025-71176 (pytest has vulnerable tmpdir handling)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: zipp==3.6.0 — 2 advisory(ies): CVE-2024-5569 (zipp Denial of Service vulnerability); CVE-2024-5569 (zipp Denial of Service vulnerability)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: zipp==3.15.0 — 2 advisory(ies): CVE-2024-5569 (zipp Denial of Service vulnerability); CVE-2024-5569 (zipp Denial of Service vulnerability)

High
Category
Supply Chain
Confidence
80% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill declares no explicit tool scope or permission boundaries despite directing actions that involve shell execution, local file access, environment exposure risk, and network publication. In a file-sharing skill, missing scope declarations are dangerous because the skill’s purpose inherently handles sensitive local files and external network exposure, increasing the chance of unintended or overbroad access.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

text

Before starting, explain that this is an upload to CNB and obtain an explicit
yes/no confirmation. Never bypass qshare's confirmation prompt or silently
switch a normal share to CNB. Treat sensitive files as requiring encryption
before upload. Return the `PUBLIC FILE URL` printed after a successful upload;
the CNB release is not automatically deleted by qshare.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 61)May include surrounding context.

md
yes/no confirmation. Never bypass qshare's confirmation prompt or silently
switch a normal share to CNB. Treat sensitive files as requiring encryption
before upload. Return the `PUBLIC FILE URL` printed after a successful upload;
the CNB release is not automatically deleted by qshare.

## Operational notes

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
72% confidence
Finding

The description hard-codes public sharing of local files without opt-in language, which normalizes a risky behavior in a package whose core purpose is data exposure. In this skill context, public file sharing is the primary capability, so missing explicit consent language increases the chance users invoke it without understanding that a local file will be exposed via a public URL.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_platform_wheels.py (reported line 49)May include surrounding context.

python
def make_wheel(base_wheel, binary, filename, tag, dist_dir):
    unpack_dir = Path(tempfile.mkdtemp(prefix="qshare-wheel-"))
    try:
        subprocess.run(["uvx", "--from", "wheel", "wheel", "unpack", str(base_wheel), "--dest", str(unpack_dir)], check=True)
        package_dir = next(unpack_dir.iterdir())
        wheel_metadata = next(package_dir.glob("*.dist-info/WHEEL"))
        lines = [

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/build_platform_wheels.py (reported line 62)May include surrounding context.

python
binary_target = package_dir / "qshare" / "_binaries" / filename
        binary_target.parent.mkdir(parents=True, exist_ok=True)
        shutil.copyfile(str(binary), str(binary_target))
        subprocess.run(["uvx", "--from", "wheel", "wheel", "pack", str(package_dir), "--dest-dir", str(dist_dir)], check=True)
        expected = dist_dir / (base_wheel.stem.replace("py3-none-any", "py3-none-{}".format(tag)) + ".whl")
        if not expected.is_file():
            raise RuntimeError("wheel pack did not create {}".format(expected))

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/qshare/cli.py (reported line 304)May include surrounding context.

python
| getattr(subprocess, "CREATE_NEW_PROCESS_GROUP", 0)
                | getattr(subprocess, "DETACHED_PROCESS", 0)
            )
        process = subprocess.Popen(
            [cloudflared_path, "tunnel", "--url", local_url, "--no-autoupdate", "--logfile", str(logfile)],
            **kwargs,
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · src/qshare/cli.py (reported line 555)May include surrounding context.

python
kwargs["creationflags"] = creationflags
    else:
        kwargs["start_new_session"] = True
    subprocess.Popen(cmd, **kwargs)
    print("qshare started in background.")
    return 0

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This line defines a hard-coded external API endpoint used for file upload operations. External transmission is expected for a sharing feature, but in this skill context it is more dangerous because the destination is fixed, authenticated, and tied to code-embedded credentials rather than transparent user choice.

Content

Scanner excerpt · src/qshare/cnb.py (reported line 14)May include surrounding context.

python
TOKEN = "67emzlY14b8RDEHMJmuevI6GuON"
REPO = "steinveni/qshare"
API = "https://api.cnb.cool/{}".format(REPO)
ACCEPT = "application/vnd.cnb.api+json"
CHUNK_SIZE = 1024 * 1024

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · src/qshare/cnb.py (reported line 100)May include surrounding context.

python
verify_url = info["verify_url"]
    if verify_url.startswith("/"):
        verify_url = urljoin("https://api.cnb.cool", verify_url)
    if not verify_url.startswith("https://api.cnb.cool/"):
        raise RuntimeError("unexpected CNB confirmation URL")
    request_json(verify_url, method="POST")

Internal Network Request

Medium
Category
Server-Side Request Forgery
Confidence
70% confidence
Finding

Code issues a request to a loopback, link-local, or private-range host. This can reach internal services not meant to be exposed and is a common SSRF pivot.

Content

Scanner excerpt · tests/test_qshare.py (reported line 70)May include surrounding context.

python
client.close()
        time.sleep(0.1)

        with urllib.request.urlopen("http://127.0.0.1:{}/large-file.bin".format(port)) as response:
            assert response.read() == file_path.read_bytes()
        assert thread.is_alive()
    finally:

Static analysis

No suspicious patterns detected.