Back to skill

Security audit

API自动生成工具

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a magic-api development helper, but it asks for broad file and command authority without enough scoping or user-control guidance.

Review before installing. Use this only in a constrained project workspace, approve any file changes or command execution explicitly, do not provide broad credentials, and replace any MD5 password guidance with a modern password-hashing approach such as Argon2id, scrypt, or bcrypt with appropriate parameters.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:21
Finding

Excessive and Unrestricted Agent Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 21-24
Vulnerability Type: Excessive read, write, and command-execution permissions
Risk Level: Medium

Vulnerable Code

yaml
tools:
- read
- exec
- write

The declared capabilities are also described at SKILL.md, lines 261-264, as supporting file reading and writing, external API integration, and system-command execution.

Technical Analysis

The Skill requests general-purpose read, write, and exec tools without specifying restrictions on accessible paths, permitted commands, command arguments, network destinations, or destructive actions. The documented purpose is primarily to provide configuration and development guidance for the magic-api framework, so unrestricted command execution and filesystem modification exceed the minimum permissions clearly required by the stated task.

Declaring a tool does not independently prove malicious execution. However, making unrestricted privileged tools available creates an exploitable least-privilege failure: ambiguous input, unsafe generated instructions, or malicious content processed by the Skill could cause the Agent to access unrelated files or execute commands outside the intended project scope.

Attack Path

  1. A user activates the Skill for API generation or configuration.
  2. The Agent grants the Skill access to the declared read, write, and exec tools.
  3. Attacker-controlled or ambiguous input causes generated instructions to reference an arbitrary path or shell command.
  4. The Agent reads sensitive local files, modifies files outside the project, or executes an unintended command.
  5. If outbound API access is also available, information obtained through file access or command output could be sent to an unspecified external service.

Impact Assessment

Successful exploitation could provide access to any files and commands permitted by the host Agent's execution cont ...[truncated 434 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove exec and write if the Skill only needs to provide documentation or generated text.
  2. Replace unrestricted access with narrowly scoped tools that operate only within the current project directory.
  3. Allowlist necessary commands, executable paths, arguments, file extensions, and network destinations.
  4. Reject absolute paths, parent-directory traversal, shell metacharacters, and untrusted command interpolation.
  5. Require explicit user confirmation before overwriting files, deleting data, executing commands, or sending data to external services.
  6. Run permitted commands in an isolated sandbox with minimal filesystem access, no inherited secrets, restricted networking, and resource limits.
  7. Document the exact operations for which each privileged tool is required.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:198
Finding

Insecure MD5 Password-Hashing Recommendation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 198
Vulnerability Type: Insecure password-storage guidance
Risk Level: Medium

Vulnerable Code

English rendering of the complete source line:

markdown
3. **Password encryption** - Use MD5/BCrypt; do not store plaintext.

Technical Analysis

The Skill presents MD5 as an acceptable alternative to BCrypt for password storage. MD5 is a fast, general-purpose hash function and is not suitable for passwords. Its speed permits attackers to test large password dictionaries efficiently using commodity GPUs or specialized cracking hardware. A plain MD5 digest also lacks the adaptive work factor required to increase cracking cost as hardware improves.

Although MD5 has known collision weaknesses, the principal password-storage risk is its extremely low computational cost and the likelihood of implementations omitting unique salts. Including MD5 in generated security guidance can lead developers or Agents to create applications with readily crackable password databases.

Attack Path

  1. A developer or Agent follows the Skill's password-storage recommendation.
  2. The application stores user passwords as MD5 hashes, potentially without unique cryptographic salts.
  3. An attacker obtains the password table through a database disclosure, backup leak, SQL injection, or unrelated infrastructure compromise.
  4. The attacker performs offline dictionary, brute-force, and precomputed-hash attacks against the MD5 values.
  5. Recovered passwords are used to access the affected application or other services where users reused their credentials.

Impact Assessment

Exploitation requires access to stored password hashes, but once hashes are obtained, MD5 substantially reduces the cost of recovering weak and moderately strong passwords. Impact can include user-account takeover, administrative compromise where privileged credentials are recovered, credential-stuffi ...[truncated 329 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove MD5 from all password-storage recommendations.
  2. Prefer Argon2id with parameters selected for the deployment's memory and latency budget.
  3. Where Argon2id is unavailable, use scrypt or BCrypt with a suitable adaptive cost factor.
  4. Generate a unique cryptographically secure salt for every password and rely on the selected password-hashing format to store algorithm parameters and salts.
  5. Consider a server-side pepper stored separately in a secrets manager or hardware-backed key store.
  6. Implement transparent rehashing after successful login when stored hashes use obsolete algorithms or outdated cost parameters.
  7. Never log plaintext passwords, derived hashes, salts paired with plaintext, or authentication secrets.
  8. Add tests or static checks that reject MD5, SHA-1, and unsalted general-purpose hashes in authentication code.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The activation description is overly broad, including generic productivity and workflow-improvement language rather than a tightly scoped trigger for magic-api tasks. Overbroad routing criteria can cause the skill to activate in unrelated contexts, exposing powerful tools like read/write/exec when the user did not intend to use this skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill describes file handling, API integration, and command execution capabilities but does not provide prominent user-facing warnings about data exposure, system modification, credential handling, or execution risk. In context, this is especially dangerous because the manifest includes read, write, and exec tools, so unsafe use could affect local files, secrets, or the host system.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The invocation steps tell the agent to call the skill with necessary parameters but do not define clear trigger boundaries, preconditions, or limits on when the skill should be used. In a skill with powerful tools, ambiguous invocation guidance increases the chance of unnecessary or unsafe activation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is presented as a magic-api generation tool, but it also claims broad file handling, external API integration, command execution, and information retrieval capabilities without showing clear scope boundaries or necessity. This kind of capability expansion increases attack surface and can mislead an agent into using powerful actions outside the user’s intended task, especially when exec and file access are available.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The documentation claims commands run in a 'safe sandbox', but the manifest only exposes a generic exec capability and provides no technical restrictions, policy, or enforcement details. This can create false trust and lead operators or agents to execute system commands under unsafe assumptions, potentially enabling arbitrary command execution on the host environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.