Back to skill

Security audit

agentscope-config-validator

Security checks for vulnerabilities and agentic risk

Overview

This skill is a small local AgentScope project validator that reads expected project files and reports configuration findings without network access, persistence, or secret exfiltration behavior.

Install only if you are comfortable running a local validator over the project path you provide. It will read pyproject.toml, .env, and some Python files, so avoid pointing it at unrelated directories containing sensitive material.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/validate_project.py (reported line 38)May include surrounding context.

python
findings = []
    env = project_root / ".env"
    if not env.exists():
        findings.append("WARN: .env file is missing")
        return findings
    text = env.read_text(encoding="utf-8")
    if "OPENAI_API_KEY" not in text and "DASHSCOPE_API_KEY" not in text:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/validate_project.py (reported line 44)May include surrounding context.

python
findings = []
    env = project_root / ".env"
    if not env.exists():
        findings.append("WARN: .env file is missing")
        return findings
    text = env.read_text(encoding="utf-8")
    if "OPENAI_API_KEY" not in text and "DASHSCOPE_API_KEY" not in text:

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/validate_project.py (reported line 36)May include surrounding context.

python
root = tmp_path / "project"
    root.mkdir()
    (root / "pyproject.toml").write_text("dependencies = ['agentscope']\n", encoding="utf-8")
    (root / ".env").write_text("OPENAI_API_KEY=\n", encoding="utf-8")
    (root / "main.py").write_text("import agentscope\n", encoding="utf-8")
    assert validate(root) == 0

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/validate_project.py (reported line 42)May include surrounding context.

python
root = tmp_path / "project"
    root.mkdir()
    (root / "pyproject.toml").write_text("dependencies = ['agentscope']\n", encoding="utf-8")
    (root / ".env").write_text("OPENAI_API_KEY=\n", encoding="utf-8")
    (root / "main.py").write_text("import agentscope\n", encoding="utf-8")
    assert validate(root) == 0

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · tests/test_validate_project.py (reported line 24)May include surrounding context.

python
root = tmp_path / "project"
    root.mkdir()
    (root / "pyproject.toml").write_text("dependencies = ['agentscope']\n", encoding="utf-8")
    (root / ".env").write_text("OPENAI_API_KEY=\n", encoding="utf-8")
    (root / "main.py").write_text("import agentscope\n", encoding="utf-8")
    assert validate(root) == 0

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill describes running a Python validator against a user-supplied project path and explicitly states it reads project files and checks project contents, but it does not declare any tool scope such as permissions or allowed-tools. That mismatch creates an authorization/visibility gap: the platform and user are not clearly informed that the skill needs filesystem access, which can lead to unintended file reads or writes beyond what a reviewer expects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.