Back to skill

Security audit

Insforge Cli

Security checks for vulnerabilities and agentic risk

Overview

The skill is genuinely for InsForge backend administration, but it combines broad infrastructure authority with mutable installs, credential handling, and automatic skill installation that users should review before trusting.

Install only if you intentionally use InsForge and are comfortable granting an agent authority over your backend. Prefer pinned CLI versions, confirm any additional skill installation separately, avoid --yes for destructive actions, use least-privilege or short-lived credentials, and do not place real secrets in command lines, transcripts, or database export files.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:18
Finding

Unpinned CLI and Agent Skill Installation Expands the Trusted Supply Chain

Content
View full analysis
Remediation
View remediation
``` 2. Enforce package integrity through a lockfile, verified package digest, signed provenance, or an organization-controlled registry mirror. 3. Prefer a project-local installation over a global installation where practical, reducing the affected scope: ```bash npm install --save-dev @insforge/cli@ ``` 4. Do not automatically install Agent Skills as a side effect of project creation. Make this a separate, opt-in operation requiring explicit user approval. 5. Pin the Agent Skill repository to an immutable release or commit and verify its contents before loading it. 6. Display the package version, source, permissions, and intended changes before installation. 7. In CI/CD, install with a restricted service account, a minimal environment, read-only credentials where possible, and disabled unnecessary lifecycle scripts. 8. Re-audit downloaded Agent Skills and dependency updates before accepting newer versions. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
references/deployments-deploy.md:46
Finding

Deployment Secrets May Be Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (16)

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill includes mechanisms for non-interactive authentication via access tokens, email, and password, and also documents commands that can retrieve decrypted secret values. In the context of an agent skill for backend administration, this materially increases credential exposure risk: an agent could consume, print, persist, or misuse sensitive credentials and then perform privileged actions across databases, storage, functions, and deployments.

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
| Variable | Description |
|----------|-------------|
| `INSFORGE_ACCESS_TOKEN` | Override stored access token |
| `INSFORGE_PROJECT_ID` | Override linked project ID |
| `INSFORGE_EMAIL` | Email for non-interactive login |
| `INSFORGE_PASSWORD` | Password for non-interactive login |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployments-deploy.md (reported line 73)May include surrounding context.

md
# - Next.js: NEXT_PUBLIC_INSFORGE_URL
# - CRA: REACT_APP_INSFORGE_URL
# - Astro: PUBLIC_INSFORGE_URL
cat > .env.production << 'EOF'
INSFORGE_URL=https://your-project.insforge.app
INSFORGE_ANON_KEY=your-anon-key
EOF

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/deployments-deploy.md (reported line 166)May include surrounding context.

md
| Mistake | Solution |
|---------|----------|
| Including node_modules in zip | Exclude it - will be installed during build |
| Including .env files | Pass via `envVars` parameter instead |
| Missing VITE_* env vars | Add all required build-time variables to `envVars` |
| Checking status too early | Wait 30sec-1min before checking status |
| Missing vercel.json for SPA | Add rewrites config for client-side routing |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/functions-deploy.md (reported line 56)May include surrounding context.

md
- Import `createClient` from `npm:@insforge/sdk`
- Export a default async function that receives a `Request` and returns a `Response`
- Use `Deno.env.get()` to access secrets and environment variables
- Always handle CORS preflight (`OPTIONS`) for browser-invoked functions

### Public Function (No Authentication Required)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/login.md (reported line 44)May include surrounding context.

md
## Credential Storage

Tokens are saved to `~/.insforge/credentials.json` with restricted file permissions (0600). Includes:
- `access_token` and `refresh_token`
- User info (id, name, email)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill’s trigger criteria are broad enough to activate on generic requests like 'create a users table' or 'deploy my app' even when the project may not use InsForge. In an agent setting, this can route users into infrastructure-modifying workflows prematurely, increasing the chance of unintended backend changes, misuse of privileged tooling, or confusing the system into operating on the wrong platform.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Documenting a global '--yes' flag that skips confirmations is risky in a skill specifically designed for infrastructure administration, because many listed operations are destructive or high-impact. In an agentic workflow, this lowers safeguards against accidental execution of deletes, deploys, imports, or configuration changes without explicit user approval.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
| Flag | Description |
|------|-------------|
| `--json` | Structured JSON output (for scripts and agents) |
| `-y, --yes` | Skip confirmation prompts |

## Exit Codes

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation states that the workflow fetches the project's API key and outputs project details including the appkey, but provides no warning about treating the credential as sensitive. In CLI, agent, and CI/CD contexts, printing secrets to stdout can leak them into terminal scrollback, logs, transcripts, screenshots, or automation artifacts, enabling unauthorized access to the newly created project.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The command npx skills add insforge/agent-skills executes a package/tool without any pinned version, integrity control, or trust boundary explanation. In an agent skill context, this is especially dangerous because project creation implicitly triggers code retrieval and execution, creating a supply-chain risk where a compromised upstream package or changed latest version could run attacker-controlled code on the user's machine or CI environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This documentation describes exporting database schema and row data, including full exports to files, but provides no warning that backups may contain sensitive or regulated data such as user records, credentials, tokens, or PII. In an infrastructure-management skill, omission of handling guidance can lead users to create plaintext exports, over-export production data, or store backups insecurely, increasing the chance of data disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This markdown file documents a command that executes raw SQL against the project database and includes examples for CREATE TABLE, ALTER TABLE, and CREATE POLICY operations. The description and examples do not warn users that such queries can modify or damage data/schema or should be used with caution.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file describes zipping a source directory, uploading it to a presigned URL, and starting a deployment with env vars and metadata, which can affect user data and privacy. While the document explains what happens, it does not include a clear cautionary warning that local project contents and supplied environment variables will be transmitted to remote infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file includes an authenticated function example that extracts a bearer token, retrieves the current user, and inserts data into a user-specific table. While the example labels the section as accessing user data, it does not provide an explicit user warning or caution about handling personal data, authorization scope, or the privacy implications of writing user records.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation recommends supplying a password via environment variables for non-interactive login but does not warn that environment variables can be exposed through shell history, process inspection, CI job logs, crash dumps, or inherited subprocess environments. In an infrastructure-management CLI, these credentials can grant broad access to databases, functions, secrets, and deployments, so normalizing this practice increases credential exposure risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The markdown introduces an option to access system tables such as pg_tables and information_schema, which can expose database metadata and broaden the scope of queries. There is no accompanying warning about the sensitivity of this access or guidance on when it should be used.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The comment says 'no authentication needed', but the code still initializes a client with an anonKey taken from environment variables. While this may be valid for public-data access, the wording contradicts the actual credentialed behavior shown and could mislead readers about the need for configured secrets.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.