Back to skill

Security audit

Cotrace

Security checks for vulnerabilities and agentic risk

Overview

This skill is for work-activity tracking, but it asks for broad collection, a global third-party CLI install, and an external bridge without enough privacy or trust guardrails.

Review this skill before installing. Only use it if you trust the Cotrace/Pieces setup, the ftc CLI publisher, and the configured bridge endpoint. Prefer a pinned or isolated CLI install, confirm what data Pieces/Cotrace collects, use narrow date ranges, avoid retrieving detailed records unless needed, and make sure you know how to revoke login access and remove the configured resource and alias.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Error
Location
references/install.md:29
Finding

Unpinned Global Installation of a Mutable Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: references/install.md, lines 29-34
Vulnerability Type: T08: Insecure Dependencies
Risk Level: High

Vulnerable Code

bash
npm install -g @autolabz/ftc-cli@latest

Verification:

bash
ftc -v

Technical Analysis

The installation workflow directs the Agent to install the mutable latest version of @autolabz/ftc-cli globally. The package is neither pinned to a previously audited version nor validated using an integrity digest or trusted provenance information.

Because the latest tag can be reassigned after this Skill has been reviewed, the code executed during a future installation may differ from the version originally expected. An attacker who compromises the package, its publisher account, or its distribution channel could publish a malicious release. Package installation may also invoke npm lifecycle scripts, allowing code to execute during installation before the subsequent version check occurs.

The global installation scope increases exposure because the resulting executable is placed in the user's global command environment and can subsequently be invoked outside this Skill.

Attack Path

  1. An attacker compromises the npm package, publisher credentials, or package distribution process.
  2. The attacker publishes a malicious version and assigns it to the latest tag.
  3. The Agent follows the installation instructions and executes npm install -g @autolabz/ftc-cli@latest.
  4. Malicious package code or lifecycle scripts execute with the privileges of the account running the Agent.
  5. The installed global ftc executable remains available for later calls and may intercept authentication information, alter requests, access user files, or execute additional commands.

Impact Assessment

Successful exploitation can provide arbitrary code execution with the operating-system privileges of the Agent user. The attacker may access ...[truncated 377 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace @latest with an exact, reviewed package version.
  2. Record and verify the package integrity digest and package provenance before installation.
  3. Prefer a project-local or isolated installation over a global installation.
  4. Inspect package contents and lifecycle scripts before approving upgrades.
  5. Consider installing with lifecycle scripts disabled during initial validation, then enable only scripts proven necessary.
  6. Require explicit user approval before installing or upgrading executable third-party packages.
  7. Maintain an allowlist of approved package names, versions, registries, and publisher identities.
  8. Run the CLI under a minimally privileged account or sandbox with restricted file and network access.

other

Warning
Location
references/install.md:41
Finding

External Bridge Receives Access to Sensitive Personal Work-Activity Data Without Documented Trust Validation

Content
View full analysis

Vulnerability Details

File Location: references/install.md, lines 41-45; authentication at lines 58-78; data verification at lines 103-107
Vulnerability Type: other: External service trust and privacy exposure
Risk Level: Medium

Vulnerable Code

External resource and alias registration:

bash
ftc resource add https://ftc-bridge.apiservice.autolab-server.site

ftc alias add cotrace https://ftc-bridge.apiservice.autolab-server.site/api/80noahia7rhpdoipbihqe

Authentication:

bash
ftc login &
FTC_PID=$!

Data retrieval:

bash
echo '{"tool":"get_workstream_summaries","args":{"created":{}}}' | ftc call cotrace

The primary workflow also permits retrieval of detailed records, including AI annotations:

bash
echo '{"tool":"get_workstream_summaries_details","args":{"identifiers":["<UUID_1>","<UUID_2>"]}}' | ftc call cotrace

Technical Analysis

The workflow configures a fixed external bridge, asks the user to complete browser-based authorization, and then uses that bridge to access personal work-activity records. These records may reveal applications used, projects, documents, organizational activity, and other sensitive personal or business context.

The audited documentation does not provide an endpoint ownership-validation procedure, an authorization-scope description, a data-retention policy, or a privacy disclosure explaining what information is processed by the CLI and bridge. It also does not require a separate informed-consent checkpoint before querying detailed activity records.

This is not evidence that the specified service is malicious. The risk arises from placing authentication and sensitive telemetry access behind an externally configured service without documenting the trust boundary or controls needed to validate it.

Attack Path

  1. The Agent installs and invokes the third-party ftc CLI.
  2. The Agent registers `ftc-br ...[truncated 1127 chars]
Remediation
View remediation

Remediation Suggestions

  1. Document the service owner, processing locations, retention period, subprocessors, and privacy policy.
  2. Validate the endpoint against an administrator-controlled allowlist before registration.
  3. Publish and verify expected TLS identities, deployment provenance, and endpoint fingerprints where operationally feasible.
  4. Explain the requested authorization scopes before login and request only the minimum scopes needed.
  5. Require explicit informed consent before retrieving work summaries or detailed AI annotations.
  6. Default to narrow time ranges rather than querying with an empty created object.
  7. Retrieve detailed records only when necessary and only for identifiers explicitly selected for the user's request.
  8. Redact credentials, confidential content, and unrelated personal information from Agent output and logs.
  9. Provide procedures for revoking authorization, deleting retained data, and removing the configured resource and alias.
  10. Execute the CLI in a restricted environment and prevent authentication output from being stored in persistent logs.
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is explicitly designed to collect and retrieve a user's daily work activity and detailed records, which are likely to contain sensitive personal and enterprise context. Because it lacks an explicit privacy warning, consent boundary, or data-minimization guidance, it can be invoked in ways that surprise users or expose more work-history data than they intended to share.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition '需要获取用户实际工作活动数据时' is overly broad, making activation criteria ambiguous and increasing the chance the skill is used without sufficiently specific user intent. In a privacy-sensitive skill, vague routing can cause unnecessary collection or disclosure of work-history data when a narrower or different capability should have been used.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide directs the user to install Pieces/Cotrace and grant system collection permissions, but it does not clearly warn that these permissions may capture broad work activity and personal context, nor does it instruct the user to verify exactly what data is being collected before proceeding. In a work-trajectory collection skill, this omission is security-relevant because users may unknowingly enable privacy-invasive telemetry and expose sensitive business or personal activity to the configured service.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Assuming Beijing time for Chinese users based solely on language is a locale inference that may misrepresent timestamps and produce inaccurate work-history reporting. While lower severity than direct data exposure, it can still lead to mistaken disclosures about when activities occurred and violates least-assumption handling of user context.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.