Back to skill

Security audit

tensorpool

Security checks for vulnerabilities and agentic risk

Overview

The skill has a coherent TensorPool migration purpose, but it under-scopes sensitive credential transfer and autonomous code-changing behavior enough that users should review it before installing.

Before installing, confirm you want an agent to transfer project files to TensorPool and potentially edit/rerun your code. Do not upload .env files, API tokens, private keys, regulated data, or proprietary datasets unless you have explicitly approved a secure method. Use a pinned TensorPool CLI install where possible, review exact rsync excludes, and require confirmation before cluster creation, package installation, file transfer, code edits, and cluster destruction.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:55
Finding

Unpinned TensorPool Package Installation Creates Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 55 and 88
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

Vulnerable Code

bash
# 1. Check tp is installed
pip show tensorpool || pip install tensorpool

The same installation pattern appears again in the prerequisites:

bash
pip show tensorpool || pip install tensorpool

Technical Analysis

The Skill instructs the Agent to install the latest version of tensorpool resolved through the environment's configured Python package index. It does not pin a reviewed version, verify a package hash, use a dependency lockfile, or explicitly select a trusted package repository.

Python package installation can run package-controlled build and installation logic. Consequently, a compromised package release, compromised transitive dependency, dependency-resolution attack, or maliciously configured package index could result in arbitrary code execution under the account running the Agent.

The audit did not find evidence that the named tensorpool package is malicious. The vulnerability is the unsafe and non-reproducible installation practice.

Attack Path

  1. An attacker compromises a package release, a transitive dependency, or a configured package index.
  2. The target environment does not already contain the tensorpool package.
  3. The Agent follows the Skill and executes pip install tensorpool.
  4. pip resolves and downloads the attacker-controlled package or dependency.
  5. Malicious build or installation logic executes with the Agent process's local privileges.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the user running the Agent. This may permit access to local project files, environment variables, API credentials, SSH configuration, and any remote systems accessible by that user. It could also compromise subsequent TensorPool clus ...[truncated 15 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin tensorpool to a specifically reviewed version.
  • Use a lockfile or requirements file containing cryptographic hashes.
  • Install only from an explicitly approved package index.
  • Prefer a pre-provisioned or isolated virtual environment.
  • Display the resolved version and source before installation.
  • Require user confirmation before installing software that can execute package-controlled build logic.
  • Periodically review pinned versions and update them through a controlled dependency-review process.

Example hardened installation pattern:

bash
python -m pip install \
  --index-url https://pypi.org/simple \
  --require-hashes \
  -r requirements-tensorpool.lock

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:140
Finding

Plaintext Credentials Are Included in the Recommended Remote Transfer Scope

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 140-181
Vulnerability Type: Plaintext secret storage and remote credential transfer
Risk Level: High

Vulnerable Code

The Skill recommends creating a plaintext .env file containing service credentials:

bash
# Create .env file if needed
cat > .env << EOF
HUGGINGFACE_TOKEN=hf_your_token_here
WANDB_API_KEY=your_wandb_key_here
EOF

It then explicitly identifies the .env file as content to transfer:

text
**2.4 Identify files to transfer:**
- Scripts (`.py` files)
- Configuration files (`.yaml`, `.json`, `.toml`)
- Requirements (`requirements.txt`)
- Small data files (< 1GB)
- Environment variables (`.env`)

The recommended broad project synchronization does not exclude .env:

bash
rsync -avz \
  --exclude=".git" \
  --exclude="__pycache__" \
  --exclude="*.pyc" \
  --exclude="venv/" \
  --exclude="outputs/" \
  ./ ubuntu@<cluster-ip>:~/my-project/

Technical Analysis

The workflow stores long-lived Hugging Face and Weights & Biases credentials in a plaintext file and then uploads the entire project directory to a remote cluster. Because .env is not excluded—and is explicitly listed as transferable—the secrets may be copied to the remote project directory.

The Skill does not require restrictive file permissions, short-lived credentials, secret scoping, an approved secret manager, secure deletion, credential revocation, or confirmation that cluster storage and snapshots no longer retain the file after cluster destruction.

SSH encrypts credentials in transit, but it does not protect plaintext secrets at rest on either the local or remote filesystem.

Attack Path

  1. The user or Agent writes valid API credentials into .env.
  2. The Agent follows the broad rsync command and uploads the project, including .env, to the cluster.
  3. The plaintext file remains ...[truncated 860 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove .env from the list of files to transfer.
  • Add .env, .env.*, credential files, and private keys to the rsync exclusion list.
  • Use TensorPool's approved secret-management or runtime secret-injection mechanism.
  • Use short-lived, minimally scoped credentials created specifically for the workload.
  • Set restrictive permissions such as chmod 600 if a local secret file is unavoidable.
  • Never commit .env; include it in .gitignore.
  • Document secure deletion and token revocation after the workload completes.
  • Validate that cluster destruction also handles attached storage, backups, and snapshots.

A safer transfer command would include:

bash
rsync -avz \
  --exclude=".git" \
  --exclude=".env" \
  --exclude=".env.*" \
  --exclude="*.pem" \
  --exclude="id_*" \
  --exclude="__pycache__" \
  --exclude="*.pyc" \
  --exclude="venv/" \
  --exclude="outputs/" \
  ./ ubuntu@<cluster-ip>:~/my-project/

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:246
Finding

Unsafe Shell Expansion Is Used to Load Environment Variables

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 246
Vulnerability Type: Unsafe parsing of an environment configuration file
Risk Level: Medium

Vulnerable Code

bash
# Load from .env
export $(cat .env | xargs)

Technical Analysis

This construction does not parse .env according to a well-defined dotenv grammar. Instead, it reads the file, tokenizes its contents through xargs, performs command substitution, and passes the resulting words to the shell's export builtin.

Whitespace, quotes, comments, line breaks, glob characters, malformed assignments, and option-like values may be interpreted incorrectly. This can alter or truncate credentials, create unintended environment variables, and change the behavior of subsequent dependency installation or workload commands. Depending on shell behavior and the exact content, values may also be exposed through diagnostics or process inspection.

This is not equivalent to directly executing every line of .env, so arbitrary command execution from ordinary command-substitution syntax embedded in the file is not assumed. The confirmed issue is unsafe, ambiguous shell parsing of potentially sensitive or project-controlled configuration.

Attack Path

  1. A user, repository contributor, or compromised project supplies a crafted or malformed .env file.
  2. The Agent transfers the file and executes export $(cat .env | xargs).
  3. xargs changes quoting and token boundaries or introduces unexpected arguments.
  4. The resulting environment differs from the intended configuration.
  5. Subsequent package installation, authentication, dataset download, or training commands operate with attacker-influenced settings or disclose malformed secret values through errors.

Impact Assessment

Exploitation can affect the current cluster shell and all child processes launched from it. Potential consequences include credential disclosure, use of attacker-s ...[truncated 341 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not parse dotenv files with export $(cat .env | xargs).
  • Prefer an approved secret manager that injects an allowlisted set of variables directly into the workload.
  • If dotenv files must be supported, use a maintained dotenv parser rather than shell tokenization.
  • Explicitly allowlist expected variable names such as HUGGINGFACE_TOKEN and WANDB_API_KEY.
  • Reject duplicate keys, malformed entries, unexpected variable names, and values containing prohibited control characters.
  • Avoid placing secret values in command-line arguments.
  • Restrict file permissions and delete temporary secret material when the process terminates.

For Python workloads, load and validate expected keys within the application using a pinned and reviewed dotenv implementation, while obtaining production secrets from the platform's secret-management facility.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

  1. SSH key available (may be needed for rsync/scp to cluster):

    bash
    ls ~/.ssh/id_ed25519.pub || ssh-keygen -t ed25519
    
  2. User has a TensorPool account — sign up at tensorpool.dev

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The instruction to create a .env file with tokens directly encourages storing secrets in plaintext within the project workspace. In the surrounding workflow, that workspace is later prepared for transfer to a remote cluster, making exposure substantially more likely.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

2.2 Check for environment variables:

bash
# Create .env file if needed
cat > .env << EOF
HUGGINGFACE_TOKEN=hf_your_token_here
WANDB_API_KEY=your_wandb_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

This line includes concrete examples of high-value credentials such as HUGGINGFACE_TOKEN and WANDB_API_KEY in a file creation block. Providing copyable secret-handling patterns in plaintext increases the chance that users will store, sync, and expose real credentials through the rest of the workflow.

Content

Scanner excerpt · SKILL.md (reported line 140)May include surrounding context.

2.2 Check for environment variables:

bash
# Create .env file if needed
cat > .env << EOF
HUGGINGFACE_TOKEN=hf_your_token_here
WANDB_API_KEY=your_wandb_key_here
EOF

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill tells the agent to identify and transfer scripts, configs, requirements, small data files, and environment variables to a remote cluster without a clear privacy or security warning. This omission is dangerous because users may unknowingly send proprietary code, sensitive datasets, or secrets to third-party infrastructure under overly broad file-selection guidance.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

Loading all values from a .env file directly into the shell environment on the cluster can expose secrets to process inspection, debugging output, shell history patterns, and accidental inheritance by child processes. In combination with earlier advice to create and transfer the .env file, this forms an insecure end-to-end credential handling pattern.

Content

Scanner excerpt · SKILL.md (reported line 245)May include surrounding context.

7.4 Set environment variables (if needed):

bash
# Load from .env
export $(cat .env | xargs)

# Or set manually

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The manual export example reinforces direct handling of a live API token in shell commands, which users may paste into shared terminals, logs, screenshots, or session recordings. Given the remote-cluster context, mishandled tokens can grant access to external services and may be difficult to detect or revoke promptly.

Content

Scanner excerpt · SKILL.md (reported line 246)May include surrounding context.

7.4 Set environment variables (if needed):

bash
# Load from .env
export $(cat .env | xargs)

# Or set manually
export HUGGINGFACE_TOKEN=hf_your_token_here

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases are broad and common enough that the skill could activate on routine performance or GPU-related requests, even when the user did not intend cloud migration or remote code transfer. Unintended invocation matters here because the skill can lead to credential handling, file transfer, infrastructure creation, and autonomous code changes.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
95% confidence
Finding

The phrase 'without asking for permission' explicitly endorses autonomous decision-making over user code execution and modification. In this skill, that autonomy is more dangerous because it combines remote execution, dependency installation, reruns, and potential changes to code and environment across multiple iterations.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
## Error Handling & Iterative Fixing

When running the user's script on TensorPool and it throws errors, **Claude should proactively diagnose and fix the code** without asking for permission, as long as the fix is in service of the script's original training/inference objective.

**Guiding principles:**
- **Fix it, don't just report it.** If a script fails with a traceable error (import errors, CUDA issues, shape mismatches, OOM, path errors, dependency issues), read the traceback, identify the root cause, apply the fix, and re-run.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly authorizes autonomous diagnosis, code edits, and reruns on the user's script without prior approval. That expands the skill from migration assistance into unsupervised modification of user code and configuration, creating risk of unintended logic changes, destructive edits, or propagation of insecure fixes during iterative troubleshooting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill promotes proactive code modification and reruns without first warning the user that their files may be changed. In a development-assistance context, silent edits can introduce integrity issues, break reproducibility, or overwrite intentional local configurations while the user may assume the agent is only providing guidance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill instructs creation of a plaintext .env file containing API tokens and later implies that project files, including environment data, may be transferred to the remote cluster. This encourages insecure secret handling and increases the chance of credential exposure through shell history, file sync, logs, misconfigured permissions, or compromise of the remote environment.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill normalizes moving a .env file with secrets onto the cluster and loading it into the shell, using plain-language examples that are likely to be copied directly. This creates a concrete path for credential leakage through remote storage, process environments, shell expansion, accidental inclusion in archives, or broad rsync of the project directory.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 283)May include surrounding context.

Press Ctrl+A then D to detach

Reconnect later with: screen -r training

Option 3: Use nohup (runs in background)

nohup python train.py > training.log 2>&1 & tail -f training.log # Monitor progress

text

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

Press Ctrl+A then D to detach

Reconnect later with: screen -r training

Option 3: Use nohup (runs in background)

nohup python train.py > training.log 2>&1 & tail -f training.log # Monitor progress

text

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
75% confidence
Finding

The manifest describes helping users move local ML scripts onto TensorPool clusters. In contrast, the documented workflow includes downloading datasets from arbitrary URLs with wget, a general network retrieval capability not specifically scoped to TensorPool cluster setup or execution. This is a broader capability than the manifest suggests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.