Back to skill

Security audit

Palo Alto Firewall Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent read-only Palo Alto firewall audit skill, but users should handle firewall API credentials and audit data carefully.

Install only if you intend to audit Palo Alto firewalls. Use a dedicated read-only API account, keep PAN_API_KEY out of shared logs and transcripts, avoid putting passwords or API keys in copied URLs or shell history, and review whether firewall logs, URL data, and WildFire/PAN-DB-related data handling fit your organization's privacy and compliance rules.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/cli-reference.md:181
Finding

API Credentials Exposed Through URL Query Parameters

Content
View full analysis
&password=` to generate a key, then pass `&key=` on subsequent requests. - REST API (PAN-OS 9.1+) provides a more modern interface at `/restapi/v10.x/` with JSON responses. Supports the same read-only operations. ``` ### Technical Analysis The documentation instructs operators to place an account password in an HTTP URL query string and to transmit the resulting API key through another query parameter. Although HTTPS protects these values while in transit, query strings are commonly retained outside the encrypted transport channel by: - Shell history and command history - HTTP client diagnostics and verbose output - Management-plane, reverse-proxy, and access logs - Monitoring, tracing, and observability systems - Browser history, copied URLs, and support bundles - Audit artifacts or terminal transcripts Anyone with access to such records may recover a reusable password or API key. The recommendation to use a dedicated read-only account limits potential modification privileges, but it does not eliminate unauthorized access to sensitive firewall information. ### Attack Path 1. An administrator follows the documented example and constructs a key-generation URL containing the username and password. 2. The request URL is retained in shell history, HTTP diagnostics, proxy logs, terminal recordings, or another operational record. 3. The generated API key is subsequently included in query strings and may be retained through the same mechanisms. 4. An attacker obtains access to one of these records through a compromised workstation, log platform, support archive, or overly broad log permissions. 5. The attacker extracts the password or API key. 6. The attacker authe ...[truncated 936 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/cli-reference.md (reported line 38)May include surrounding context.

md
|----------|-------------|
| Full running security policy | `show running security-policy` |
| Security policy (candidate config) | `show config merged running-config security` |
| Policy hit counts | `show rule-hit-count vsys vsys1 security rules all` |
| Test policy match | `test security-policy-match source <IP> destination <IP> protocol <num> application <app> destination-port <port> from <zone> to <zone>` |
| NAT policy | `show running nat-policy` |
| Policy-based forwarding | `show running pbf-policy` |

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/cli-reference.md (reported line 49)May include surrounding context.

md
|----------|-------------|
| Full running security policy | `show running security-policy` |
| Security policy (candidate config) | `show config merged running-config security` |
| Policy hit counts | `show rule-hit-count vsys vsys1 security rules all` |
| Test policy match | `test security-policy-match source <IP> destination <IP> protocol <num> application <app> destination-port <port> from <zone> to <zone>` |
| NAT policy | `show running nat-policy` |
| Policy-based forwarding | `show running pbf-policy` |

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The API key generation example shows user and password in the URL query string without any warning about the security implications. Even over HTTPS, query strings are commonly exposed in browser history, shell history, reverse proxies, monitoring tools, and server/access logs, which can leak administrator credentials during audit activity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This is a markdown file, so SQP-2 applies to omitted warnings in descriptive text. The file states that PAN-DB performs cloud lookups for unknown URLs and that unknown files may be submitted to WildFire sandbox analysis, but it does not warn that these behaviors can transmit URL or file-derived data off-device and may have privacy or compliance implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.