Back to skill

Security audit

Byted Vefaas Skills

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent veFaaS deployment guide, but it asks users and agents to install and use a powerful cloud CLI in ways that can expose credentials or change live cloud resources without enough safeguards.

Review this carefully before installing. Prefer SSO or protected CI secrets over pasting AK/SK or tokens into commands, avoid --yes for production unless the target app, region, gateway, and impact are confirmed, do not share debug logs until redacted, and pin or verify the CLI package before global installation.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:12
Finding

Mutable Remote CLI Package Is Installed and Executed Globally

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/authentication.md:17
Finding

Cloud Credentials and Tokens Are Passed Through Command-Line Arguments

Content
View full analysis
--secretKey ``` ### Technical Analysis The documented commands place access keys, secret access keys, STS session tokens, and OAuth tokens directly in command-line arguments. Real values substituted into these examples may be exposed through: - Shell history files. - Process listings and process-monitoring tools. - Terminal session recording. - CI job logs or command tracing. - Endpoint detection and audit telemetry. - Error reports that capture complete command lines. Environment variables are presented elsewhere as an alternative, but the unsafe argument-based method remains a prominently documented authentication workflow without a warning about its disclosure properties. ### Attack Path 1. A user replaces the placeholders with valid cloud credentials or a valid OAuth token. 2. The user executes the command in a normal shell or CI job. 3. The complete command is retained in shell history, process telemetry, command tracing, or CI logs. 4. A local user, log administrator, compromised monitoring agent, or unauthorized party with access to retained logs retrieves the credential. 5. The attacker authenticates to Volcengine using the exposed crede ...[truncated 700 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/troubleshooting.md:13
Finding

Environment Secrets and Full API Responses Can Be Written to Plaintext Logs

Content
View full analysis
2>&1 | tee debug.log ``` Environment-management documentation shows that sensitive values are printed directly: ```bash vefaas env list # Output: # > Environment Variables: # DATABASE_URL=postgres://user:pass@host:5432/db # API_KEY=your-api-key # NODE_ENV=production ``` ```bash vefaas env get DATABASE_URL # Output: postgres://user:pass@host:5432/db ``` ### Technical Analysis The CLI documentation states that debug logs include API request and response parameters and preserve full JSON response data. It also directs users to display those logs and duplicate debug output through `tee`. Separately, environment-variable commands return plaintext database URLs and API keys. The guidance does not require sensitive-field redaction, restrictive file permissions, retention controls, secure deletion, or inspection before logs are submitted for support. Conseque ...[truncated 1573 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
references/authentication.md:68
Finding

Documentation Recommends Blanket veFaaS Full-Access Permissions

Content
View full analysis
**Access Key Management** 3. Create new AK/SK pair 4. Ensure account has **veFaaSFullAccess** policy ``` ### Technical Analysis The documentation recommends assigning the broad `veFaaSFullAccess` policy without distinguishing between read-only inspection, deployment, environment-variable management, application creation, and function updates. This violates the principle of least privilege. Most workflows require only a subset of actions and should be constrained by account, resource, region, environment, or deployment stage. The use of newly created AK/SK credentials further increases risk if the keys are long-lived. The policy assignment is not itself an unauthorized privilege escalation because an authorized administrator must grant it. However, it unnecessarily increases the blast radius of credential disclosure, CLI compromise, or CI runner compromise. ### Attack Path 1. An administrator follows the documentation and grants `veFaaSFullAccess` to a user or automation identity. 2. Long-lived AK/SK credentials are generated for that identity. 3. The credentials are exposed through command-line arguments, logs, a compromised workstation, or a malicious dependency. 4. The attacker authenticates as the overprivileged identity. 5. The attacker performs veFaaS operations beyond those required for the original deployment task. 6. Multiple applications or functions accessible under the broad policy may be modified or disrupted. ### Impact Assessment A compromised identity with full veFaaS access may be able to perform broad application and function management actions allowed by that managed policy, potentially in ...[truncated 415 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (20)

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
| Option | Description |
|--------|-------------|
| `-d, --debug` | Enable debug mode for troubleshooting |
| `--yes` | Non-interactive mode (required for CI/AI coding) |
| `--region` | Region override (e.g., cn-beijing) |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · cookbooks/deploy-existing-code.md (reported line 71)May include surrounding context.

vefaas env set DATABASE_URL "postgres://user:pass@host:5432/db" vefaas env set API_KEY "your-api-key"

Or import from .env file

vefaas env import ./.env.prod

text

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

The instruction to import from a .env file encourages use of a file format that commonly stores credentials, tokens, and connection strings, without any warning about securing the file, excluding it from version control, or validating where those values will be transmitted. In a deployment-management context, this can lead to credential exposure through repository commits, local compromise, or accidental propagation of sensitive secrets to remote environments.

Content

Scanner excerpt · cookbooks/manage-functions.md (reported line 90)May include surrounding context.

Import from File

bash
vefaas env import .env

Scenario D: View and Update Configuration

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/configuration.md (reported line 98)May include surrounding context.

text
# Local config
*.local
.env.local

# Dependencies
node_modules/

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · cookbooks/manage-functions.md (reported line 133)May include surrounding context.

md
# Troubleshooting Reference

## Enable Debug Mode

When encountering issues, first enable debug mode with `--debug` or `-d`:

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 3)May include surrounding context.

md
# Troubleshooting Reference

## Enable Debug Mode

When encountering issues, first enable debug mode with `--debug` or `-d`:

Instruction Override

High
Category
Prompt Injection
Confidence
70% confidence
Finding

This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.

Content

Scanner excerpt · references/troubleshooting.md (reported line 5)May include surrounding context.

Enable Debug Mode

When encountering issues, first enable debug mode with --debug or -d:

bash
vefaas --debug deploy

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill promotes non-interactive deployment commands such as vefaas deploy ... --yes and later documents state-changing configuration commands, but it does not clearly warn that these actions create or modify remote cloud resources. In an AI-agent context, this increases the chance of unintended deployment, configuration drift, cost incurrence, or production impact because the commands are presented as routine workflow steps.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill includes credential-bearing login (--accessKey, --secretKey) and environment-variable management commands without guidance on secret hygiene, masking, or avoiding shell history/log exposure. In a tool-using agent setting, this can lead to accidental disclosure of cloud credentials or sensitive application secrets through command history, transcripts, debug logs, or persisted config files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The cookbook repeatedly uses --yes on deploy commands, which suppresses confirmation for an operation that creates or updates remote applications immediately. In a deployment skill, this increases the chance of accidental production changes or unintended resource creation, especially if a user copies commands verbatim without realizing they are non-interactive and immediately effective.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The example vefaas env import ./.env.prod encourages bulk uploading environment variables but does not warn that secrets in the file will be transmitted to and stored on the remote platform. In this skill context, users are likely to paste real production .env files, so omission of a warning can lead to unintentional disclosure or mishandling of sensitive credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The cookbook demonstrates listing, getting, setting, and importing environment variables including examples like DATABASE_URL and API_KEY, but provides no warning that these values may be secrets and may be exposed in terminals, shell history, screenshots, logs, or shared sessions. In an operational deployment skill, normalizing direct secret inspection and modification without safeguards increases the chance of credential leakage or accidental disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation shows passing raw access keys and secret keys directly on the command line and exporting them in shell environment variables without any security warning. Command-line secrets can leak through shell history, process inspection, logs, screenshots, or shared terminals, making credential compromise more likely in real-world use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The example uses vefaas deploy --yes together with automatic gateway selection, which can immediately create and deploy cloud resources without an explicit confirmation step or warning about side effects. In deployment tooling, this increases the chance of unintended resource creation, cost exposure, and accidental publication of an application, especially when users copy-paste commands from documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation instructs users to pass long-lived secrets directly on the command line and notes that credentials are stored locally, but it does not warn that command-line arguments may be exposed via shell history, process listings, CI logs, or auditing tools. In a deployment skill for serverless infrastructure, these credentials can grant broad account access, so insecure handling materially increases the risk of credential theft and subsequent compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly demonstrates commands that print all environment variables and individual secret values directly to terminal output, including examples such as DATABASE_URL and API_KEY. In a deployment/operations skill, this is dangerous because terminals, shell history, CI logs, screen sharing, and support transcripts can expose credentials and enable unauthorized access to databases or external services.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The documentation recommends npx vitepress build without pinning a version, which can cause execution of whatever package version npm resolves at runtime. If a malicious or compromised upstream package version is published, users following this guidance could execute unreviewed code during build, making this a real supply-chain risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The troubleshooting guide explicitly states that debug output includes HTTP requests/responses and that log files contain full JSON response data, but it does not warn that these artifacts may contain credentials, tokens, environment variables, internal identifiers, or other sensitive operational data. Users may copy, inspect, or share these logs during support workflows, creating a realistic risk of secret disclosure and unintended data exposure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The feedback section instructs users to capture --debug output, latest log files, and environment details for submission without any privacy or sensitivity warning. Because earlier sections indicate logs contain full JSON response data, this encourages users to share potentially sensitive information such as access metadata, service configuration, machine details, or secrets embedded in responses and environment context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation explicitly states that cloud-linked configuration is stored locally in .vefaas/config.json, and the example structure includes function IDs, application IDs, region, and public endpoint URLs. While not credentials, these identifiers and URLs are deployment metadata that can aid reconnaissance or accidental disclosure if users commit or share the file without realizing its sensitivity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.