Back to skill

Security audit

QwenPaw Environment Inspector

Security checks for vulnerabilities and agentic risk

Overview

This diagnostic skill is mostly coherent, but it can print full local credential values and sensitive path metadata during routine checks.

Review before installing or running. Use it only in environments where diagnostic output can be kept private, and avoid running the raw environment-variable check unless it is changed to report only whether required variables are set. Treat any generated report as potentially containing secrets or private host metadata.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:60
Finding

Credential-bearing environment variables are exposed in diagnostic output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 60
Vulnerability Type: Plaintext exposure of environment secrets
Risk Level: Medium

Vulnerable snippet:

bash
env | grep -E "QWENPAW|DASHSCOPE|OPENAI|ANTHROPIC|GITHUB" || true

Technical Analysis

The environment-inspection workflow instructs the agent to enumerate the complete process environment and print every entry whose name or value matches the listed provider terms. Because env emits entries as NAME=value, API keys and tokens are printed in plaintext rather than merely reporting whether required variables are configured.

This behavior is broader than the Skill's diagnostic need. The report format only requires an availability result, while the command can expose credentials belonging to QwenPaw and unrelated services such as GitHub, OpenAI, Anthropic, and DashScope. It also conflicts with the stated scope that the Skill does not handle API keys.

The trust boundary is crossed when secrets available only to the local process are copied into command output visible to the agent. That output may subsequently be retained in tool transcripts, agent context, diagnostic reports, or associated logs. The project contains no evidence of deliberate exfiltration or malicious intent, so this is classified as a reachable coding flaw rather than credential theft.

Attack Path

  1. A user, shell profile, CI environment, or credential tool defines a matching variable containing an API key or access token.
  2. The user invokes the environment-inspector Skill for routine diagnostics.
  3. The prescribed check executes env and filters its plaintext output.
  4. The matching variable's complete NAME=value entry is emitted.
  5. The credential enters agent-visible command output and may be retained in transcripts, reports, or logs accessible beyond the process that originally held it.

Impact Assessment

Successful exposure reveals the full values o ...[truncated 515 chars]

Remediation
View remediation

Remediation Suggestions

Replace environment enumeration with an explicit allowlist of variables genuinely required by QwenPaw, and report only whether each variable is set. Never print secret values.

For example:

bash
for key in QWENPAW_REQUIRED_VAR; do
  if [ -n "$(printenv "$key")" ]; then
    printf '%s=set\n' "$key"
  else
    printf '%s=unset\n' "$key"
  fi
done

Additionally:

  • Remove unrelated provider variables from the diagnostic scope unless they are demonstrably required.
  • Ensure generated reports contain only boolean presence indicators or redacted values.
  • Document that raw environment-variable values must not be included in agent responses, transcripts, or logs.
  • If partial identification is necessary, use strict redaction that never reveals enough of a token to authenticate.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

Listing ~/.qwenpaw and related directories is a form of filesystem enumeration that can expose filenames, permissions, ownership, and operational metadata useful to an attacker or inappropriate for logs and screenshots. In an environment-inspection skill this is contextually relevant, but it should still be minimized and treated as sensitive output.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

bash
python3 -c "from qwenpaw.constant import DOCS_DIR; print(DOCS_DIR or 'None')"
ls -la ~/.qwenpaw
  • 預期:可讀取 docs 路徑、工作目錄存在

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs enumerating environment variables and sensitive directories, which can reveal API keys, usernames, filesystem layout, and secret-storage locations in output or logs. In a diagnostic skill this may be useful, but without an explicit warning, masking guidance, or scoped filtering, it creates an avoidable secret/privacy disclosure risk.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

The main description text is presented in Chinese and the rest of the document continues in that language, but there is no indication that the skill is region-specific or that users can opt into another language. This can violate language/locale policy when a skill implicitly forces one language for all users.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The connectivity check contacts an external domain, which discloses that the tool is being run from the user's host and may leak timing, IP, or network-policy information. This is low impact in context, but users should be informed that a remote service will be contacted during diagnostics.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.