T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:12- Finding
Mutable Remote CLI Package Is Installed and Executed Globally
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent veFaaS deployment guide, but it asks users and agents to install and use a powerful cloud CLI in ways that can expose credentials or change live cloud resources without enough safeguards.
Review this carefully before installing. Prefer SSO or protected CI secrets over pasting AK/SK or tokens into commands, avoid --yes for production unless the target app, region, gateway, and impact are confirmed, do not share debug logs until redacted, and pin or verify the CLI package before global installation.
SKILL.md:12Mutable Remote CLI Package Is Installed and Executed Globally
references/authentication.md:17Cloud Credentials and Tokens Are Passed Through Command-Line Arguments
references/troubleshooting.md:13Environment Secrets and Full API Responses Can Be Written to Plaintext Logs
references/authentication.md:68Documentation Recommends Blanket veFaaS Full-Access Permissions
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
| Option | Description |
|--------|-------------|
| `-d, --debug` | Enable debug mode for troubleshooting |
| `--yes` | Non-interactive mode (required for CI/AI coding) |
| `--region` | Region override (e.g., cn-beijing) |
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
vefaas env set DATABASE_URL "postgres://user:pass@host:5432/db" vefaas env set API_KEY "your-api-key"
vefaas env import ./.env.prod
The instruction to import from a .env file encourages use of a file format that commonly stores credentials, tokens, and connection strings, without any warning about securing the file, excluding it from version control, or validating where those values will be transmitted. In a deployment-management context, this can lead to credential exposure through repository commits, local compromise, or accidental propagation of sensitive secrets to remote environments.
vefaas env import .env
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# Local config
*.local
.env.local
# Dependencies
node_modules/
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
# Troubleshooting Reference
## Enable Debug Mode
When encountering issues, first enable debug mode with `--debug` or `-d`:
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
# Troubleshooting Reference
## Enable Debug Mode
When encountering issues, first enable debug mode with `--debug` or `-d`:
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
When encountering issues, first enable debug mode with --debug or -d:
vefaas --debug deploy
The skill promotes non-interactive deployment commands such as vefaas deploy ... --yes and later documents state-changing configuration commands, but it does not clearly warn that these actions create or modify remote cloud resources. In an AI-agent context, this increases the chance of unintended deployment, configuration drift, cost incurrence, or production impact because the commands are presented as routine workflow steps.
The skill includes credential-bearing login (--accessKey, --secretKey) and environment-variable management commands without guidance on secret hygiene, masking, or avoiding shell history/log exposure. In a tool-using agent setting, this can lead to accidental disclosure of cloud credentials or sensitive application secrets through command history, transcripts, debug logs, or persisted config files.
The cookbook repeatedly uses --yes on deploy commands, which suppresses confirmation for an operation that creates or updates remote applications immediately. In a deployment skill, this increases the chance of accidental production changes or unintended resource creation, especially if a user copies commands verbatim without realizing they are non-interactive and immediately effective.
The example vefaas env import ./.env.prod encourages bulk uploading environment variables but does not warn that secrets in the file will be transmitted to and stored on the remote platform. In this skill context, users are likely to paste real production .env files, so omission of a warning can lead to unintentional disclosure or mishandling of sensitive credentials.
The cookbook demonstrates listing, getting, setting, and importing environment variables including examples like DATABASE_URL and API_KEY, but provides no warning that these values may be secrets and may be exposed in terminals, shell history, screenshots, logs, or shared sessions. In an operational deployment skill, normalizing direct secret inspection and modification without safeguards increases the chance of credential leakage or accidental disclosure.
The documentation shows passing raw access keys and secret keys directly on the command line and exporting them in shell environment variables without any security warning. Command-line secrets can leak through shell history, process inspection, logs, screenshots, or shared terminals, making credential compromise more likely in real-world use.
The example uses vefaas deploy --yes together with automatic gateway selection, which can immediately create and deploy cloud resources without an explicit confirmation step or warning about side effects. In deployment tooling, this increases the chance of unintended resource creation, cost exposure, and accidental publication of an application, especially when users copy-paste commands from documentation.
The documentation instructs users to pass long-lived secrets directly on the command line and notes that credentials are stored locally, but it does not warn that command-line arguments may be exposed via shell history, process listings, CI logs, or auditing tools. In a deployment skill for serverless infrastructure, these credentials can grant broad account access, so insecure handling materially increases the risk of credential theft and subsequent compromise.
The documentation explicitly demonstrates commands that print all environment variables and individual secret values directly to terminal output, including examples such as DATABASE_URL and API_KEY. In a deployment/operations skill, this is dangerous because terminals, shell history, CI logs, screen sharing, and support transcripts can expose credentials and enable unauthorized access to databases or external services.
The documentation recommends npx vitepress build without pinning a version, which can cause execution of whatever package version npm resolves at runtime. If a malicious or compromised upstream package version is published, users following this guidance could execute unreviewed code during build, making this a real supply-chain risk.
The troubleshooting guide explicitly states that debug output includes HTTP requests/responses and that log files contain full JSON response data, but it does not warn that these artifacts may contain credentials, tokens, environment variables, internal identifiers, or other sensitive operational data. Users may copy, inspect, or share these logs during support workflows, creating a realistic risk of secret disclosure and unintended data exposure.
The feedback section instructs users to capture --debug output, latest log files, and environment details for submission without any privacy or sensitivity warning. Because earlier sections indicate logs contain full JSON response data, this encourages users to share potentially sensitive information such as access metadata, service configuration, machine details, or secrets embedded in responses and environment context.
The documentation explicitly states that cloud-linked configuration is stored locally in .vefaas/config.json, and the example structure includes function IDs, application IDs, region, and public endpoint URLs. While not credentials, these identifiers and URLs are deployment metadata that can aid reconnaissance or accidental disclosure if users commit or share the file without realizing its sensitivity.
No suspicious patterns detected.