Back to skill

Security audit

工具编排器

Security checks for vulnerabilities and agentic risk

Overview

This encrypted memory skill is mostly disclosed, but it automatically stores conversation facts externally and changes runtime/plugin state with too little user control.

Review this carefully before installing. Confirm you are comfortable with automatic extraction of facts from future conversations into external encrypted storage, require an explicit way to pause/delete/export memory, use a pinned and verified plugin version, avoid the wildcard rm -rf reinstall command, and approve any gateway reload or restart yourself.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

other

Error
Location
SKILL.md:35
Finding

Automatic External Capture of Conversation Data Without Granular Consent

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:54
Finding

Unauthorized Gateway Configuration and Autonomous Runtime Reload

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:49
Finding

Execution of an Unpinned Third-Party Plugin Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:60
Finding

Broad Recursive Deletion During Reinstallation

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:77
Finding

Detached Pairing Process Without Lifecycle Supervision

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 44)May include surrounding context.

md
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。

**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。

## 安装

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。

**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。

## 安装

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 160)May include surrounding context.

md
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。

**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。

## 安装

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
12词恢复短语**绝不能**进入聊天或代理的LLM上下文。配对流程通过浏览器处理短语生成与导入。绝不要回显它,绝不要要求用户粘贴它,绝不要将其传递给任何工具。如用户无论如何粘贴了一个,告知其已泄露并重新配对以获得新钱包。

**硬性约束 — 安装/重装/升级流程:** 在安装、重装、升级或任何验证步骤期间,代理**绝不能**读取、列出、cat、显示或检查 `credentials.json`、`~/.tool-orchestrator/credentials.json`、`~/.tool-orchestrator*/credentials.json` 或任何凭据/短语/密钥/机密文件 — 无论出于任何原因,包括"验证安装"。这些文件包含加密密钥材料和智能账户地址,**绝不能**进入LLM上下文。绝不要运行 `ls`、`find`、`cat`、`show` 或类似命令针对插件目录来"检查文件"。

## 安装

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The specific wildcarded path rm -rf ~/.platform/npm/projects/*tool-orchestrator* is a true destructive-operation risk. Wildcards combined with recursive deletion can match more than intended, and in an automated agent workflow this can lead to accidental removal of unrelated project data or make recovery difficult.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

text
plugins uninstall tool-orchestrator
rm -rf ~/.platform/npm/projects/*tool-orchestrator*
plugins install @tool-orchestrator/tool-orchestrator
plugins enable tool-orchestrator

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

The specific wildcarded path rm -rf ~/.platform/npm/projects/*tool-orchestrator* is a true destructive-operation risk. Wildcards combined with recursive deletion can match more than intended, and in an automated agent workflow this can lead to accidental removal of unrelated project data or make recovery difficult.

Content

Scanner excerpt · SKILL.md (reported line 60)May include surrounding context.

text
plugins uninstall tool-orchestrator
rm -rf ~/.platform/npm/projects/*tool-orchestrator*
plugins install @tool-orchestrator/tool-orchestrator
plugins enable tool-orchestrator

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill's display name, summary, description, and all operational instructions are written exclusively in Chinese, with no indication that users may choose another language. This creates a locale/language constraint in the skill's natural-language interface without documented opt-in or region-specific justification.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

  1. 通过插件的进程内HTTP路由创建配对会话:

    bash
    curl -s http://localhost:18789/plugin/tool-orchestrator/pair/init
    

    → 返回 {"url":"https://…/pair/p/<id>#pk=…","pin":"123456","expires_at_ms":…}

Session Persistence

Medium
Category
Rogue Agent
Confidence
78% confidence
Finding

The fallback instruction uses setsid -f to detach a long-lived background process from the agent session. In an exec-capable agent environment, detached processes reduce auditability and can persist beyond the user's intent, potentially leaving unmanaged network-connected tooling running.

Content

Scanner excerpt · SKILL.md (reported line 77)May include surrounding context.

md
→ 返回 `{"url":"https://…/pair/p/<id>#pk=…","pin":"123456","expires_at_ms":…}`

   **不要使用 `tr pair --json`。** CLI在子进程中持有配对WebSocket,会被约30秒shell工具超时杀死,WS随后断开,用户提交短语时中继返回502。上述进程内路由完全避免此问题。仅在路由不可达时回退到CLI,且必须分离运行使WS存活: `setsid -f node "$TR_CLI" pair --json < /dev/null`。

2. 原样向用户展示 **url** 和 **pin**(从JSON读取,绝不编造值):"在浏览器中打开 `<url>`,输入PIN `<pin>`,生成或粘贴你的12词恢复短语。完成后回复done。" URL作为纯文本单独一行输出,`#pk=` 片段在反引号/markdown中会损坏。

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The reinstall instructions include a recursive deletion command against a wildcarded package path without strong safety guardrails. In an agent context with exec enabled, destructive shell snippets can cause unintended data loss or be misapplied if path expansion behaves unexpectedly or the environment differs from assumptions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.