Back to skill

Security audit

1Password Browser Login

Security checks for vulnerabilities and agentic risk

Overview

This skill is designed to use 1Password credentials to log into websites, but it handles credential records too broadly and lacks clear user confirmation and domain-scoping safeguards.

Install only if you are comfortable letting the agent access selected 1Password items and submit those credentials through browser automation. Use a narrowly scoped 1Password service account, avoid broad vault access, and require users to specify the exact item and destination before any credential retrieval or form submission.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:37
Finding

Full 1Password Credential Records May Be Exposed Through Captured Command Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 37
Vulnerability Type: Sensitive credential exposure through command output
Risk Level: High

Vulnerable Code Snippet:

bash
source ~/.zshrc 2>/dev/null && op item get "<ITEM_NAME>" --vault "<VAULT_NAME>" --format json 2>&1

Technical Analysis

The documented command retrieves the complete 1Password item as JSON. The returned object can contain username and password fields, URLs, and other sensitive item metadata. Because standard error is redirected to standard output with 2>&1, all command output is sent through the same output channel.

Although the subsequent instructions prohibit printing or logging the password, that policy does not prevent the command-execution framework, agent transcript, telemetry system, debugging layer, or tool-call history from capturing the raw JSON before it is parsed. The implementation therefore exposes substantially more sensitive information than is required for browser authentication.

Attack Path

  1. A user or attacker requests that the agent log in using a named 1Password item.
  2. The agent follows the Skill instructions and executes the vulnerable op item get command.
  3. The 1Password CLI emits the complete item record as JSON, including password-bearing fields.
  4. The execution environment captures standard output in the tool result, transcript, logs, or telemetry.
  5. An actor with access to those retained outputs can recover and reuse the exposed credentials outside the intended browser session.

Impact Assessment

Successful exploitation can disclose the username, password, login URL, and potentially other fields stored in the selected 1Password item. An exposed password may permit unauthorized access to the associated external account with all privileges granted to that account. If the credential is reused elsewhere, the compromise may extend to addition ...[truncated 256 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not request or return the complete item JSON when only specific fields are needed.
  • Retrieve only the minimum required fields through narrowly scoped 1Password CLI options or secret references.
  • Avoid merging standard error into standard output for commands that handle secrets.
  • Use a protected secret-delivery mechanism that passes credentials directly to the browser without placing them in the agent transcript or general command output.
  • Configure execution infrastructure to suppress secret-bearing output, redact known sensitive fields, and prevent such output from entering telemetry or persistent logs.
  • Keep credentials in memory only for the duration of the login operation and clear references immediately afterward.
  • Use a dedicated, least-privileged 1Password service account that can access only explicitly authorized login items.

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:27
Finding

Broad Enumeration of 1Password Items and Vaults Exposes Unrelated Account Metadata

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 27–33
Vulnerability Type: Excessive credential inventory access and metadata disclosure
Risk Level: Medium

Vulnerable Code Snippet:

bash
source ~/.zshrc 2>/dev/null && op item list --format json 2>&1
bash
source ~/.zshrc 2>/dev/null && op vault list --format json 2>&1

Technical Analysis

When the requested item name is unclear, the Skill instructs the agent to list every item available to the service account. It also requires enumeration of all accessible vaults before retrieving a selected item.

These operations violate least-privilege and data-minimization principles because a login to one service does not require disclosure of the complete accessible credential inventory. Item and vault listings can reveal organization names, account names, service usage, internal systems, and the structure of privileged credential storage. Redirecting standard error into standard output further increases the chance that metadata and diagnostic details will be retained in execution records.

Attack Path

  1. An attacker submits an intentionally ambiguous request to log in with an unspecified or unclear 1Password item.
  2. Following the documented error-resolution flow, the agent executes op item list --format json.
  3. The agent also executes op vault list --format json while attempting to identify the correct vault.
  4. Complete accessible item and vault metadata is returned to the agent execution environment.
  5. The inventory may be displayed to the requester or retained in transcripts, logs, or telemetry.
  6. The attacker uses the disclosed names and organizational information to identify valuable systems, privileged accounts, or targets for phishing and follow-on attacks.

Impact Assessment

This issue can disclose metadata for every item and vault accessible to the configured service accoun ...[truncated 486 chars]

Remediation
View remediation

Remediation Suggestions

  • Require the requester to provide an explicit item name and vault name before accessing 1Password.
  • Do not return or display complete item or vault inventories to resolve ambiguous requests.
  • If discovery is unavoidable, use server-side filters and return only narrowly matched, non-sensitive identifiers.
  • Require user confirmation before accessing a selected credential when multiple matches exist.
  • Provision a dedicated service account for this Skill and grant it access only to the specific vaults and items required for approved workflows.
  • Prevent inventory output from being stored in transcripts, telemetry, or persistent command logs.
  • Record auditable authorization decisions without recording credential inventory or secret values.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:17
Finding

Repeated Execution of the Interactive Shell Startup File Creates an Arbitrary Code Execution Boundary

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 17, 27, 33, and 37
Vulnerability Type: Unsafe shell initialization and execution of unrelated startup commands
Risk Level: Medium

Vulnerable Code Snippet:

bash
source ~/.zshrc 2>/dev/null && op whoami 2>&1

The same unsafe initialization pattern is repeated for item listing, vault listing, and item retrieval:

bash
source ~/.zshrc 2>/dev/null && op item list --format json 2>&1
source ~/.zshrc 2>/dev/null && op vault list --format json 2>&1
source ~/.zshrc 2>/dev/null && op item get "<ITEM_NAME>" --vault "<VAULT_NAME>" --format json 2>&1

Technical Analysis

The source ~/.zshrc operation executes the entire interactive shell startup file in the current shell context. A .zshrc file can contain arbitrary commands, aliases, functions, command substitutions, hooks, network operations, or environment modifications. The Skill only needs access to OP_SERVICE_ACCOUNT_TOKEN, but it executes every other instruction in the startup file as well.

Suppressing standard error with 2>/dev/null can also conceal failures or indicators of malicious startup behavior. Because the commands run under the same identity as the agent, any code in .zshrc receives the agent’s filesystem, process, network, and environment access.

Attack Path

  1. An attacker or previously compromised process gains write access to the account’s ~/.zshrc.
  2. The attacker adds a malicious shell command, function, alias, or hook to that file.
  3. A user invokes the 1Password browser-login Skill.
  4. The Skill sources .zshrc before each documented 1Password CLI operation.
  5. The injected code executes with the privileges of the agent process.
  6. The code can access the agent’s available files and environment, modify command behavior, or transmit accessible data over the netw ...[truncated 818 chars]
Remediation
View remediation

Remediation Suggestions

  • Do not source interactive shell startup files from automated Skill workflows.
  • Provide OP_SERVICE_ACCOUNT_TOKEN through a dedicated secret manager, protected process environment, or narrowly scoped runtime configuration.
  • Invoke the 1Password CLI using a clean, explicitly constructed environment.
  • Use an absolute, trusted path to the op executable and avoid shell aliases or functions that can replace expected command behavior.
  • Store service-account configuration separately from .zshrc, with restrictive filesystem permissions and no executable shell content.
  • Avoid suppressing diagnostic output indiscriminately; handle expected errors explicitly while ensuring that secrets are redacted.
  • Run the Skill in a sandbox with restricted filesystem and network access to limit the impact of compromised local configuration.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises very broad trigger phrases such as helping log into arbitrary sites and then perform follow-up actions, which can match many ordinary browsing requests. That increases the chance the agent invokes this credential-handling skill in situations where the user did not clearly intend to use stored secrets, causing unnecessary exposure of sensitive credentials to external sites through browser automation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill retrieves credentials from 1Password and automatically types them into a website, but it does not require a user-facing warning or confirmation that secrets will be transmitted to an external service. In this context, that omission is more dangerous because the skill is specifically designed to bridge a secret store and arbitrary websites, so users may not fully appreciate that invoking the skill causes credential use on potentially untrusted or mistaken domains.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.