Back to skill

Security audit

Minimax Usage

Security checks for vulnerabilities and agentic risk

Overview

This usage-checking skill has a coherent purpose, but its bundled script unsafely executes a parent-directory .env file instead of the documented local one.

Review before installing. The skill does not show evidence of intentional theft or persistence, but you should not run the bundled script unless the .env path is fixed and credentials are loaded as data rather than executed as shell code.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
minimax-usage.sh:6
Finding

Arbitrary Shell Code Execution Through Unsafe Parent-Directory Environment File Loading

Content
View full analysis

Vulnerability Details

File Location: minimax-usage.sh, line 6
Vulnerability Type: Unsafe execution of configuration data
Risk Level: High

Vulnerable Code

bash
source "$(dirname "$0")/../../.env"

Technical Analysis

The Bash source command interprets the specified file as shell code in the current process. Consequently, the referenced .env file is not limited to passive KEY=VALUE configuration entries: it may contain arbitrary commands, command substitutions, redirections, function definitions, or additional script imports.

The path also resolves two directories above the script directory. This conflicts with the setup instructions in SKILL.md, which tell users to create .env in the same directory as the script. The implementation therefore crosses the Skill package boundary and may load an unrelated or less-protected parent configuration file.

An attacker who can create or modify the resolved parent .env can execute arbitrary commands when a user invokes the Skill. Loading the file occurs before API credential validation, so malicious commands execute regardless of whether the required MiniMax variables are present.

Attack Path

  1. An attacker obtains write access to the .env file located two directories above minimax-usage.sh, or causes a crafted project hierarchy to be used.

  2. The attacker inserts shell commands into that file, for example:

    bash
    MINIMAX_CODING_API_KEY=dummy
    MINIMAX_GROUP_ID=dummy
    attacker_command
    
  3. A user runs ./minimax-usage.sh.

  4. Line 6 evaluates the entire .env file through source.

  5. attacker_command executes with the same identity, environment, filesystem access, and network permissions as the user running the Skill.

Impact Assessment

Successful exploitation provides arbitrary shell command execution with the invoking user's privileges. The attacker could read or modify files accessible to that ...[truncated 398 chars]

Remediation
View remediation

Remediation Suggestions

  1. Resolve configuration relative to the actual script directory and use the location documented in SKILL.md:

    bash
    SCRIPT_DIR="$(cd -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd)"
    ENV_FILE="${SCRIPT_DIR}/.env"
    
  2. Do not use source for an environment file that may be writable by another party. Parse only the two required keys as data, reject malformed lines, and never evaluate command substitutions or shell expressions.

  3. Prefer receiving MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID from an already configured process environment. If file-based configuration is required, use a parser that treats values as literal text.

  4. Verify that the configuration is a regular file, is not a symbolic link, and is owned by the expected user. Reject files writable by group or other users.

  5. Restrict the file permissions because it contains an API credential:

    bash
    chmod 600 .env
    
  6. Update SKILL.md and the implementation so they specify the same configuration location and security requirements.

Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · minimax-usage.sh (reported line 4)May include surrounding context.

sh
#!/bin/bash
# Minimax Coding Plan Usage Check
# Usage: ./minimax-usage.sh
# Requires: MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID in .env

source "$(dirname "$0")/../../.env"

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The script executes source "$(dirname "$0")/../../.env", which causes the shell to run any code present in that file, not just read key-value pairs. If an attacker can modify the .env file or influence that path, they can achieve arbitrary code execution in the context of the user running the script and access the API key or other local data.

Content

Scanner excerpt · minimax-usage.sh (reported line 6)May include surrounding context.

sh
# Usage: ./minimax-usage.sh
# Requires: MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID in .env

source "$(dirname "$0")/../../.env"

API_KEY="${MINIMAX_CODING_API_KEY}"
GROUP_ID="${MINIMAX_GROUP_ID}"

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · minimax-usage.sh (reported line 12)May include surrounding context.

sh
GROUP_ID="${MINIMAX_GROUP_ID}"

if [ -z "$API_KEY" ] || [ -z "$GROUP_ID" ]; then
  echo "❌ Error: MINIMAX_CODING_API_KEY and MINIMAX_GROUP_ID required in .env"
  exit 1
fi

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill instructs users to run a shell script (./minimax-usage.sh) and handle API credentials, but it declares no explicit tool scope or permissions metadata. This creates an authorization gap where automation platforms or reviewers cannot clearly constrain or validate the shell capability the skill relies on, increasing the risk of unintended command execution or future drift into more dangerous behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The manifest describes a usage-monitoring skill that fetches current stats and reports alerts. While authenticating to the Minimax API is expected, directly sourcing a parent .env file adds local configuration-file access and environment loading behavior that is broader than the stated purpose and not mentioned in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.