Back to skill

Security audit

UNCLEMATTCONNECTTOGPTWEBLOGINOFFIREFORWEBGPTLOGINGTOYOURSHIT

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed Codex/ChatGPT login bridge, but its implementation gives prompt-controlled Codex runs broader local file and environment exposure than the user-facing warning clearly covers.

Install only if you are comfortable with this skill invoking your authenticated Codex/ChatGPT account and with prompts potentially causing readable workspace files or environment values to be processed by that provider. Use it from a clean, minimal working directory and sanitized shell environment; do not run ask on untrusted prompts or in projects containing secrets.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/gpt-web-login-bridge.js:86
Finding

Prompt-Controlled Codex Agent Can Read and Disclose Local Workspace Files

Content
View full analysis

Vulnerability Details

File Location: scripts/gpt-web-login-bridge.js, lines 86-103
Vulnerability Type: Excessive local file access during provider-backed prompt execution
Risk Level: High

Vulnerable Code

js
function codexAsk(prompt) {
  const result = runCodex([
    'exec',
    '--ignore-user-config',
    '--ignore-rules',
    '--skip-git-repo-check',
    '--ephemeral',
    '--json',
    '-C',
    bridgeCwd,
    '-s',
    'read-only',
    '-c',
    'approval_policy="never"',
    '-c',
    'model_reasoning_effort="low"',
    prompt,
  ]);

Technical Analysis

The bridge passes arbitrary caller-controlled prompt text to a Codex agent operating in bridgeCwd. The read-only sandbox prevents filesystem modification, but it does not prevent the agent from reading files available within its execution context.

The use of --ignore-rules also disables repository-level rules that might otherwise limit file inspection or regulate handling of sensitive project data. Meanwhile, approval_policy="never" means tool operations proceed without an interactive approval boundary where permitted by the sandbox.

Consequently, the effective provider data boundary is broader than the submitted prompt. Local source code, configuration files, credentials stored in readable project files, and other workspace content may enter the provider context through agent tool calls.

Attack Path

  1. A user, another skill, or an untrusted automation component invokes the bridge using the ask command.
  2. The supplied prompt instructs the Codex agent to inspect files, such as configuration files, deployment manifests, source files, or hidden files in the working directory.
  3. The bridge starts Codex in bridgeCwd with read-only filesystem access and repository rules disabled.
  4. Codex uses its available tools to read accessible local files.
  5. File contents are submitted to the authentica ...[truncated 681 chars]
Remediation
View remediation

Remediation Suggestions

  • Use a provider mode that does not expose filesystem or shell tools when the intended operation is only a text model request.
  • Run Codex from a newly created, empty, permission-restricted working directory rather than from the caller-selected project directory.
  • Do not use --ignore-rules unless repository rules have been independently validated and intentionally replaced with stricter bridge-specific controls.
  • Enforce an allowlist of readable files if local context is required, and copy only approved content into an isolated directory.
  • Separate plain prompt completion from agentic repository operations. Require an explicit, separately authorized command for any operation that grants local file access.
  • Clearly disclose that local file contents and tool results—not only the original prompt—may be sent to the authenticated provider.
  • Reject or require additional confirmation for prompts requesting file inspection, secret discovery, environment inspection, or recursive workspace analysis.

T09 · Insecure Skill Coding Practices

Error
Location
scripts/gpt-web-login-bridge.js:26
Finding

Codex Child Process Inherits the Entire Parent Environment

Content
View full analysis

Vulnerability Details

File Location: scripts/gpt-web-login-bridge.js, lines 26-35
Vulnerability Type: Excessive inheritance of potentially sensitive environment variables
Risk Level: High

Vulnerable Code

js
function runCodex(args) {
  return spawnSync(codexBin, args, {
    cwd: bridgeCwd,
    encoding: 'utf8',
    maxBuffer: 64 * 1024 * 1024,
    env: {
      ...process.env,
      GPT_WEB_LOGIN_BRIDGE_CHILD: '1',
    },
  });
}

Technical Analysis

The bridge copies every environment variable from its parent process into the Codex child process. Runtime environments commonly contain sensitive values such as cloud credentials, API keys, CI/CD tokens, database connection strings, proxy credentials, and internal service endpoints.

Passing the full environment violates least privilege because the child normally needs only a small subset of variables, such as executable lookup paths, basic runtime settings, and variables specifically required for Codex authentication.

Because the child executes prompt-controlled agent tasks, inherited variables may be accessible through shell or process-inspection tools available to that agent. The read-only filesystem setting does not protect environment variables, and disabling interactive approval does not create a secret-access boundary.

Attack Path

  1. The bridge is launched from a shell, CI runner, development environment, or agent host containing secrets in environment variables.
  2. A caller submits a crafted ask prompt requesting inspection of environment variables or execution of a command such as env or printenv.
  3. runCodex copies the complete parent environment into the Codex process.
  4. If the Codex tool sandbox permits process or shell inspection, the agent reads the inherited values.
  5. The values enter provider processing and may be reproduced in the bridge response.
  6. The attacker obtains credentials or sensiti ...[truncated 766 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace the spread of process.env with an explicit allowlist containing only variables required to launch and authenticate Codex.
  • Include basic variables such as PATH, HOME, locale settings, and platform-specific runtime variables only after confirming they are necessary.
  • Explicitly exclude common secret-bearing variables, including cloud credentials, CI tokens, database URLs, API keys, and proxy credentials.
  • Launch the child from a sanitized wrapper environment dedicated to the bridge.
  • Disable shell and process-inspection tools for ordinary ask requests.
  • Add automated tests that populate the parent environment with sentinel secrets and verify that the child cannot inspect or return them.
  • Document the remaining environment variables inherited by the provider process and their security purpose.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

External Model or Provider Selection

High
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill is explicitly designed to route prompts to an externally authenticated Codex/ChatGPT provider, and it even notes that ask and smoke send prompt text to that provider. In this context, the danger is not token theft but unintended data exfiltration: sensitive user or workspace content could be forwarded to a third-party service, and the use of --ignore-rules weakens local policy guardrails that might otherwise block unsafe forwarding.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

Default provider is Codex CLI. The script uses:

bash
codex exec --ignore-user-config --ignore-rules --skip-git-repo-check --ephemeral --json

This uses Codex auth while avoiding recursive user config, hooks, and persistent session files for the bridge call. It is the clean route: let Codex be logged in, let the bridge call Codex, keep the agent’s grubby little hands away from secrets.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 89)May include surrounding context.

md
- `SKILL.md`: this loud no-secrets bridge rulebook.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
- `SKILL.md`: this loud no-secrets bridge rulebook.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/gpt-web-login-bridge.js (reported line 24)May include surrounding context.

js
console.error('Missing prompt argument or stdin.');
    process.exit(2);
  }
  return prompt;
}

function runCodex(args) {

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes executable behavior that uses environment-controlled settings and invokes a local bridge/provider, but it does not declare any explicit tool scope or permissions boundary in the skill metadata. That omission can cause the host or downstream agents to run the skill with broader-than-expected capabilities, making environment-variable influence and command execution less auditable and easier to misuse.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/gpt-web-login-bridge.js:28