Back to skill

Security audit

T.LY URL Shortener

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it claims: it helps create T.LY short links, but users should handle the API token and optional package install carefully.

Before installing, confirm you trust the T.LY service and the tly-url-shortener-api package. Prefer an isolated virtual environment, avoid pasting real API keys into command history, and use a safer request method than the shown curl fallback if command-line process arguments are logged or observable on your system.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:17
Finding

Unpinned Third-Party Package Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17-21
Vulnerability Type: Unpinned runtime dependency installation
Risk Level: Medium

Vulnerable Code Snippet:

markdown
4. In Python environments, prefer the official PyPI package [`tly-url-shortener-api`](https://pypi.org/project/tly-url-shortener-api/).
5. Install it if needed:

```bash
pip install tly-url-shortener-api

Technical Analysis

The installation command does not pin the dependency to a reviewed version and does not verify a package hash or signature. Consequently, each installation resolves the package version available from the configured Python package index at execution time.

The effective executable content can therefore change after the Skill has been audited. If the package publisher account, package index, or local package-index configuration is compromised, a malicious release could execute code during installation or when the imported client and CLI are used.

The package name is explicit and there is no evidence in the reviewed files that its current release is malicious. The weakness is the absence of reproducible and integrity-verified dependency resolution.

Attack Path

  1. An attacker compromises the package publisher account, package distribution channel, or configured Python package index.
  2. The attacker publishes or serves a modified release under the expected package name.
  3. An Agent follows the Skill and runs pip install tly-url-shortener-api.
  4. Because no version or hash is specified, pip installs the attacker-controlled release.
  5. Malicious code executes during package installation, import, or invocation of the tly CLI.
  6. The code operates with the privileges of the Agent process and may access environment variables, including TLY_API_TOKEN.

Impact Assessment

Successful exploitation could provide code execution with the privileges of the user or Agent running pip and the ...[truncated 315 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the dependency to a specifically reviewed version, such as tly-url-shortener-api==<reviewed-version>.
  • Require package hashes with pip install --require-hashes and a reviewed requirements or lock file.
  • Install the dependency in a dedicated virtual environment using an unprivileged account.
  • Configure pip to use a trusted package index and prevent unintended dependency sources or dependency-confusion paths.
  • Review the package and its transitive dependencies before updating the pinned version.
  • Require explicit user authorization before installing new executable dependencies.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:67
Finding

T.LY API Token Is Expanded into a Process Command-Line Argument

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 67-74
Vulnerability Type: Sensitive credential exposure through process arguments
Risk Level: Medium

Vulnerable Code Snippet:

markdown
```bash
curl -X POST "https://api.t.ly/api/v1/link/shorten" \
  -H "Content-Type: application/json" \
  -d '{
    "long_url": "https://example.com/article",
    "domain": "https://t.ly/",
    "api_token": "'"$TLY_API_TOKEN"'"
  }'

Technical Analysis

The shell expands $TLY_API_TOKEN while constructing the argument passed to curl -d. The resulting JSON request body, including the plaintext API token, can therefore be present in the curl process argument vector.

Depending on operating-system access controls and execution infrastructure, command arguments may be visible through process inspection interfaces, monitoring agents, debugging facilities, audit systems, or command-execution logs. This undermines the Skill's stated objective of preventing credentials from being exposed in commands or logs.

The literal token is not stored in the Skill and ordinary shell history would generally retain the variable reference rather than its expanded value. The exposure occurs at execution time after shell expansion.

Attack Path

  1. A user or Agent exports a valid token through TLY_API_TOKEN.
  2. The Agent executes the documented curl fallback.
  3. The shell expands the environment variable into the JSON supplied as a command-line argument.
  4. A local process observer, sufficiently privileged user, monitoring service, or command-capture system records the curl argument vector while the process is running.
  5. The observer extracts the plaintext API token from the JSON.
  6. The attacker reuses the token against the T.LY API until the credential is revoked or expires.

Impact Assessment

Exposure grants the attacker the API permissions associated with the compromised T.LY token. This may ...[truncated 241 chars]

Remediation
View remediation

Remediation Suggestions

  • Avoid placing request bodies containing secrets directly in command-line arguments.
  • Generate the JSON request in a file with owner-only permissions, pass it using curl --data-binary @file, and securely remove the file immediately afterward.
  • Alternatively, provide the request body through a protected standard-input mechanism that does not expose the expanded secret in the process argument vector.
  • Prefer an authorization header if the T.LY API supports one, while ensuring the header is also supplied through a mechanism that avoids process-argument exposure.
  • Disable shell tracing around credential-handling operations and configure execution systems to redact secrets from logs.
  • Run the request under a dedicated, least-privileged account and rotate the token immediately if exposure is suspected.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Use a direct API call when the SDK/CLI is unavailable or not appropriate.

bash
curl -X POST "https://api.t.ly/api/v1/link/shorten" \
  -H "Content-Type: application/json" \
  -d '{
    "long_url": "https://example.com/article",

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Use a direct API call when the SDK/CLI is unavailable or not appropriate.

bash
curl -X POST "https://api.t.ly/api/v1/link/shorten" \
  -H "Content-Type: application/json" \
  -d '{
    "long_url": "https://example.com/article",

Static analysis

No suspicious patterns detected.