Back to skill

Security audit

TencentCloud COS Storage

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Tencent Cloud storage management skill, but it asks for very broad cloud access and includes unsafe credential and deletion guidance.

Install only if you are comfortable reviewing and narrowing the Tencent Cloud permissions first. Use a dedicated sub-user limited to specific buckets and prefixes, avoid printing `.env` files, run dependencies in a virtual environment, and treat delete or lifecycle-expiration operations as irreversible unless your COS account has separate recovery controls.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:147
Finding

Wildcard COS Policy Grants Excessive Cloud Privileges

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:147-149
Vulnerability Type: T05: Unauthorized Access and Privilege Escalation
Risk Level: High

Vulnerable Code:

json
"action": [
  "name/cos:*"
],
"resource": "*"

Technical Analysis

The documented access policy grants every Tencent Cloud COS action against every COS resource available to the configured sub-user. This violates least privilege and contradicts the document's recommendation to use minimal permissions.

The wildcard action can authorize security-sensitive and destructive operations beyond ordinary object upload and download, including bucket administration, ACL changes, lifecycle configuration, object deletion, and bucket deletion, subject to Tencent Cloud's policy evaluation rules. The wildcard resource scope applies those permissions across all matching COS resources in the account rather than limiting access to explicitly approved buckets or object prefixes.

Attack Path

  1. A user follows the Skill documentation and creates a sub-user policy containing name/cos:* over *.
  2. The resulting secret ID and secret key are configured for the Skill.
  3. An attacker obtains those credentials through host compromise, accidental .env exposure, malicious local code, or another credential leak.
  4. The attacker authenticates directly to Tencent Cloud COS using the exposed credentials.
  5. The attacker invokes COS operations against any resource covered by the wildcard policy, rather than being limited to the bucket and operations required by the intended workflow.
  6. Depending on account resources and Tencent Cloud policy evaluation, the attacker can read, overwrite, expose, reconfigure, or delete COS data.

Impact Assessment

Compromise of the configured credentials may provide account-wide COS access. Potential impact includes:

  • Confidentiality loss through unauthorized object listing and download.
  • Integrity loss ...[truncated 431 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace name/cos:* with an explicit list of operations required for each supported workflow.
  2. Scope resource to approved bucket and object resource identifiers instead of *.
  3. Publish separate policy templates for:
    • Read-only object access.
    • Upload and download access.
    • Lifecycle administration.
    • Bucket creation and deletion.
  4. Keep ACL modification, object deletion, lifecycle expiration, bucket clearing, and bucket deletion disabled unless explicitly required.
  5. Use object-prefix restrictions where workloads only need access to a particular namespace.
  6. Use separate short-lived credentials for administrative and routine object operations where supported.
  7. Add explicit policy review and credential-rotation guidance, and ensure the documented policy matches the claim of least privilege.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:178
Finding

Unpinned Packages Are Installed into the System Python Environment

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:178-180
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code:

bash
pip3 install --break-system-packages \
  cos-python-sdk-v5 \
  python-dotenv

Technical Analysis

The installation command does not pin dependency versions or verify package hashes. Consequently, installations performed at different times may retrieve dependency releases that were not included in this audit. If a package release or its distribution channel is compromised, installation can introduce attacker-controlled code.

The --break-system-packages option also bypasses protections for an externally managed Python environment. This allows pip to modify system-managed packages, potentially replacing versions used by other applications and creating dependency conflicts or unsafe global behavior.

No malicious dependency was identified in the audited files. The vulnerability is the unsafe and non-reproducible dependency installation process.

Attack Path

  1. An attacker compromises a listed package, one of its transitive dependencies, a package maintainer account, or the package delivery channel.
  2. A malicious or otherwise unsafe release becomes the version selected by pip because no version constraints or hashes are specified.
  3. A user follows the documented installation command.
  4. Pip downloads and installs the changed package into the system Python environment.
  5. Package installation hooks or subsequently imported package code executes with the privileges of the user running pip.
  6. Because system package protections were bypassed, the modified dependency may also affect unrelated applications that use the same Python environment.

Impact Assessment

Successful exploitation can result in arbitrary code execution with the privileges of the installing or executing user. Possible consequences include:

  • Theft of Tencent Cloud cr ...[truncated 455 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove --break-system-packages from the documented installation procedure.
  2. Create and activate an isolated virtual environment before installing dependencies:
    bash
    python3 -m venv .venv
    . .venv/bin/activate
    
  3. Pin direct and transitive dependencies to reviewed versions in a lock file.
  4. Record cryptographic hashes for every distribution and install with hash enforcement, such as:
    bash
    pip install --require-hashes -r requirements.lock
    
  5. Generate the lock file from a trusted index and review dependency changes before updating it.
  6. Use an explicitly configured HTTPS package index and avoid untrusted supplemental indexes.
  7. Add automated dependency vulnerability and provenance checks to the release process.
  8. Run the Skill as an unprivileged user and keep its environment separate from system and unrelated application environments.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 303)May include surrounding context.

md
- ✅ 使用子用户密钥,不用主账号
- ✅ 设置最小权限
- ✅ .env 文件妥善保管
- ✅ 定期轮换密钥 (90 天)
- ❌ 不要提交密钥到 Git

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · src/cos_manager.py (reported line 644)May include surrounding context.

python
- ✅ 使用子用户密钥,不用主账号
- ✅ 设置最小权限
- ✅ .env 文件妥善保管
- ✅ 定期轮换密钥 (90 天)
- ❌ 不要提交密钥到 Git

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The troubleshooting step instructs users to run 'cat config/.env', which can print sensitive Tencent Cloud credentials directly to the terminal, logs, shell history capture tools, or shared support transcripts. In a support or multi-user environment, this increases the chance of accidental credential exposure and subsequent cloud resource compromise.

Content

Scanner excerpt · SKILL.md (reported line 335)May include surrounding context.

问题 1: 凭证验证失败

bash
cat config/.env
python3 src/verify_config.py

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The delete_bucket method can irreversibly remove an entire bucket, and with force=True it first clears all objects without any confirmation, dry-run, or additional safeguard. In an agent or automation context, a mistaken parameter, prompt injection, or logic error could destroy large amounts of data immediately.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · src/cos_manager.py (reported line 590)May include surrounding context.

python
rules.append(rule_dict)
            
            return rules
        
        except CosServiceError as e:
            print(f"❌ 获取失败:{e}")

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 227)May include surrounding context.

上传文件

python
cos.upload_file(
    bucket="my-data-bucket",
    local_path="/tmp/data.parquet",
    key="data/2024/03/28/data.parquet"

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · src/cos_manager.py (reported line 350)May include surrounding context.

python
### 上传文件

```python
cos.upload_file(
    bucket="my-data-bucket",
    local_path="/tmp/data.parquet",
    key="data/2024/03/28/data.parquet"

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · src/cos_manager.py (reported line 439)May include surrounding context.

python
### 上传文件

```python
cos.upload_file(
    bucket="my-data-bucket",
    local_path="/tmp/data.parquet",
    key="data/2024/03/28/data.parquet"

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · src/cos_manager.py (reported line 730)May include surrounding context.

python
### 上传文件

```python
cos.upload_file(
    bucket="my-data-bucket",
    local_path="/tmp/data.parquet",
    key="data/2024/03/28/data.parquet"

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The surrounding comment and returned metadata imply the create_bucket method applies the requested storage_class to the bucket. However, when storage_class is not STANDARD, the code calls put_bucket_versioning(Status='Enabled'), which controls versioning rather than storage class. This is an active contradiction between documented intent and actual behavior.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The delete_object method performs permanent object deletion with no warning, confirmation, or safety controls. In agent-driven workflows, this increases the chance of accidental or induced destructive actions against user data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The lifecycle configuration API allows callers to create expiration rules that automatically delete objects in the future, yet there is no explicit warning, review step, or validation of destructive policy effects. This can silently create delayed data loss that may be overlooked until it is too late.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The file’s natural-language instructions, examples, and operational guidance are entirely in Chinese, starting from the title and continuing throughout the document. Under the stated policy, forcing a specific language without offering the user a language or locale choice can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.