Back to skill

Security audit

Byted Volc Cdn Manage

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its CDN-management purpose, but it needs review because it can make live cloud CDN changes and has unsafe CLI and credential-handling patterns.

Install only after reviewing the scripts and using least-privilege Volcengine credentials limited to the required CDN actions. Verify the Volcengine CLI source and checksum yourself, avoid putting AK/SK values in shell history or chat, prefer the interactive scripts with confirmation, and carefully review every domain, origin, refresh URL, and preload URL before running commands against production.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (4)

T08 · Insecure Dependencies

Warning
Location
references/install-guide.md:31
Finding

Volcengine CLI Is Downloaded and Installed Without Integrity Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/install-guide.md:66
Finding

Secret Keys Are Passed Through Command-Line Arguments

Content
View full analysis
\ --secret-key \ --region cn-guangzhou \ --profile default ``` The FAQ repeats the same pattern: ```bash # references/faq.md:22-25 ve configure set --access-key --secret-key --region cn-guangzhou --profile default ``` The interactive script also instructs users to run it: ```bash # scripts/add-cdn-domain.sh:120 echo " ve configure set --access-key --secret-key --region cn-guangzhou --profile default" ``` ### Technical Analysis When users replace the placeholders with real values, the SecretKey becomes part of the shell command line. Depending on the operating system and shell configuration, it may be retained in shell history and may be visible to local process-monitoring tools while the command executes. This is not a hardcoded credential in the repository. The vulnerability is the recommended method of supplying a sensitive credential. ### Attack Path 1. A user copies the documented command and substitutes a real SecretKey. 2. The shell records the full command in its history file, or exposes it through process metadata during execution. 3. Another process or user with sufficient local access reads the command history or process arguments. 4. The attacker retrieves the AK/SK pair. 5. The attacker authenticates to Volcengine and invokes APIs allowed by the associated identity. ### Impact Assessment The attacker obtains the permissions assigned to the exposed cloud identity. In the context of this Skill, those permissions may include creating CDN domains, reading CDN configuration, and submittin ...[truncated 310 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/add-cdn-domain.sh:18
Finding

Project-Local Executable Is Preferred Without Provenance Verification

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/submit-preload.sh:24
Finding

User-Controlled Values Are Concatenated Into JSON Without Escaping

Content
View full analysis
Remediation
View remediation
&2; exit 1 ;; esac body=$(printf '%s\n' "${urls[@]}" | jq -R . | jq -s --arg type "$refresh_type" '{Type: $type, UrlList: .}') ``` 3. Validate URLs with an appropriate parser and restrict schemes to those accepted by the API. 4. Validate enumerated fields such as service region and service type against explicit allowlists. 5. Validate weights as integers in the documented range. 6. Use `jq --arg` for domain, project, origin, and other scalar values. 7. Validate the final payload with `jq -e` before invoking the CLI. 8. Add an explicit confirmation step to non-interactive scripts before state-changing cloud operations, or provide a clearly named `--yes` option for automation. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (23)

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

代码的主要行为是新增 CDN 域名,这与声明的一部分一致。但声明还包含两个重要能力:1)支持刷新/预热;2)必要时检查并安装 CLI。该代码片段中只看到对本地 ve 可执行文件存在性的检查,缺失安装逻辑;同时也没有任何刷新或预热相关 API 调用(如 URL/目录刷新或预热)。因此描述覆盖的能力范围明显大于实际代码行为,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

代码的核心行为是:检查 ve CLI 是否可执行、让用户选择预热或刷新、收集 URL、构造请求体并调用 ve cdn SubmitPreloadTask 或 ve cdn SubmitRefreshTask。这与声明中的“刷新预热”部分一致,但与“管理 CDN 域名、支持新增域名”不符,因为代码没有创建/添加域名相关调用。此外,声明说会在需要时检查并安装 CLI,而代码仅在 CLI 缺失时提示参考安装文档并退出,并不实际安装。因此描述未准确代表代码实际行为,属于明显不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

代码片段只是定义了两个函数:一个输出不同业务类型的推荐 CDN 配置 JSON,另一个输出这些配置的说明文字。它没有调用火山引擎 CLI,也没有执行任何域名管理操作,没有新增域名、缓存刷新、预热、CLI 检查或安装等行为。该代码的实际用途更像是“生成 CDN 推荐配置模板”,与声明的“通过 CLI 管理 CDN 域名并支持刷新预热”存在明显主功能不匹配。

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

声明描述的是一个较完整的 CDN 域名管理能力集合,包括新增域名、刷新预热,以及必要时检查安装 CLI。实际提供的代码片段只是一个“提交刷新任务”的脚本:它构造 UrlList 和 Type 参数后调用 ve cdn SubmitRefreshTask。代码中没有新增域名相关调用,没有预热任务相关调用,也没有任何检查/安装 CLI 的逻辑,只有本地或系统 ve 可执行文件的选择。因此该代码片段的实际行为明显比声明更窄,且缺少声明中的关键能力,属于描述与行为不一致。

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill clearly instructs users to run shell commands such as bash scripts/... and ve ..., but the manifest does not declare any tool scope or allowed tools. This creates an execution-scope ambiguity where an agent may invoke shell capabilities without explicit least-privilege boundaries, increasing the risk of unintended command execution or overly broad runtime permissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill instructs users to perform CDN refresh and preload operations without clearly warning that these actions immediately affect live traffic, cache state, origin load, and user-visible content delivery. In an agent-assisted context, omission of impact warnings can lead to accidental production disruption, excessive cache invalidation, or unintended high-load events against origin infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The prerequisites tell users to configure AK/SK credentials but provide no guidance on secure handling, storage, redaction, or least-privilege use. In an agent setting, this omission increases the risk that users paste secrets into chat, store them insecurely in shell history or scripts, or use overprivileged credentials for state-changing CDN operations.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

L004 将文档范围描述为“CDN 域名创建”的常见场景,但后续示例不仅创建域名,还包含私有对象存储源站鉴权配置,直接在请求体中设置 AccessKeyId 和 AccessKeySecret。相较于“创建域名”的表述,这属于额外的敏感能力展示,超出了仅创建域名这一自然语义范围。

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The example shows AccessKeyId and AccessKeySecret embedded directly in a CLI payload for private object storage origin authentication, without any warning about secret handling. Users may copy this pattern into shell history, repos, logs, tickets, or shared terminals, causing credential leakage and unauthorized access to the backing storage or CDN-integrated resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This is a markdown file, so SQP-2 applies to user-facing documentation. The section shows ve cdn DeleteCdnDomain --Domain "www.example.com" as a direct deletion command, but does not warn that it removes an existing CDN domain configuration or advise the user to verify the target before running it.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/install-guide.md (reported line 46)May include surrounding context.

bash
unzip -q ve.zip
mkdir -p ~/.local/bin
mv ve ~/.local/bin/

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/install-guide.md (reported line 46)May include surrounding context.

bash
unzip -q ve.zip
mkdir -p ~/.local/bin
mv ve ~/.local/bin/

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The guide tells users to pass the AccessKey and SecretKey directly as command-line arguments to ve configure set. Secrets supplied on the command line can be exposed via shell history, terminal logging, process listings, or audit tooling, which creates a realistic credential leakage risk for cloud accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

这是一个 markdown 文件,适用 SQP-2。L067-L068 明确要求填写 AccessKeyId 和 AccessKeySecret,但文档没有提醒用户这些字段属于敏感凭证、应避免泄露、记录或提交到不安全位置;该行为涉及隐私和系统完整性,应有基本警示。

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/add-cdn-domain.sh (reported line 112)May include surrounding context.

sh
echo ""
        echo "3. 解压并安装:"
        echo "   unzip -q ve.zip"
        echo "   mkdir -p ~/.local/bin"
        echo "   mv ve ~/.local/bin/"
        echo ""
        echo "4. 配置环境变量(如果还没有配置):"

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/add-cdn-domain.sh (reported line 112)May include surrounding context.

sh
echo ""
        echo "3. 解压并安装:"
        echo "   unzip -q ve.zip"
        echo "   mkdir -p ~/.local/bin"
        echo "   mv ve ~/.local/bin/"
        echo ""
        echo "4. 配置环境变量(如果还没有配置):"

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The natural-language/config value sets "ServiceRegion": "chinese_mainland" unconditionally. This enforces a specific locale/region behavior with no visible user choice, which matches the policy category for language/locale-style regional constraints lacking opt-in or justification in the file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest description says the skill supports both adding CDN domains and performing refresh/preload operations. In this script, the only user-selectable actions are '提交预热任务' and '提交刷新任务', which call SubmitPreloadTask and SubmitRefreshTask respectively; there is no code path for creating or adding domains.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The comment and all user-facing usage/help output are written in Chinese, which imposes a specific language on users without any opt-in or explanation. This matches the policy category for language/locale violations because the script does not offer an alternative language or justify that it is intended only for a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The comments and echoed user-facing strings are entirely in Chinese, including usage guidance and operational warnings. Under the policy, forcing a specific language without user opt-in is a natural-language locale violation unless the locale restriction is clearly justified, which this script does not do.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

L004 明确说文档提供的是“CDN 域名创建”的常见场景,但后续多个场景包含缓存、压缩、页面优化、回源协议、回源 Host、Range、CacheKey、VideoDrag 以及私有桶鉴权等附加配置。这里并非单纯信息不全,而是文档对自身范围的表述与实际示例覆盖内容存在明显偏差。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

SQP-3 适用于所有文件类型。该文档全文以中文固定呈现,未说明这是面向特定中文区域用户的受限文档,也未提供语言选择或用户自选机制,可能构成语言/locale 策略上的强制单一语言。

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script's comments and usage/help text are written in Chinese, including the only user-facing guidance shown on incorrect invocation. This imposes a specific language on users without any opt-in or indication that the skill is intentionally limited to a Chinese-speaking or region-specific audience.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.