Back to skill

Security audit

Multisage

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent purpose, but its instructions create avoidable risks around secret handling, external AI forwarding, global package installation, and shell command construction.

Install only if you are comfortable sending prompts to Multisage and its downstream AI providers. Configure the API key through a trusted environment mechanism, do not let the agent search or print .env files, prefer a pinned local CLI install, and avoid passing untrusted user text through the shown Bash command templates without safe argument handling.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:44
Finding

Shell Command Injection Through User-Controlled Query Interpolation

Content
View full analysis
/tmp/multisage-output.txt 2>&1 cat /tmp/multisage-output.txt # Wrong — tee can cause issues in non-TTY contexts multisage -q "your question" | tee output.txt # DON'T DO THIS ``` Equivalent unsafe interpolation patterns also appear at `SKILL.md:58-61` and `SKILL.md:108-124`. ### Technical Analysis The Skill instructs the Agent to place a user-provided question directly inside a double-quoted shell command. Shell double quotes do not prevent command substitution through constructs such as `$(command)` or backticks. If the Agent textually replaces `"your question"` with untrusted content, the shell evaluates command substitutions before invoking `multisage`. Embedded quotes or other shell syntax can also terminate or alter the intended argument. The documentation supplies no argument-array invocation, strict escaping procedure, or other mechanism that reliably separates user data from shell syntax. For example, a question containing `$(id)` could cause `id` to execute locally while its output is inserted into the argument sent to `multisage`. ### Attack Path 1. An attacker asks the Agent to consult Multisage about a question containing shell command-substitution syntax. 2. The Agent follows the Skill and inserts the question into the documented Bash command. 3. Bash parses the resulting command and evaluates the attacker-controlled substitution. 4. The injected command executes with the operating-system permissions of the Agent process. 5. The attacker may use the execution primitive to read accessible files, modify workspace data, invoke network tools, or launch additional payloads. ### Impact Assessment Successful exploitation provides arbitrary command execution with the privileges of the user running the Agent. The affecte ...[truncated 207 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:26
Finding

Overbroad Credential Discovery Exposes API Keys

Content
View full analysis
/dev/null || grep MULTISAGE_API_KEY ~/.env 2>/dev/null # 3. Export it (replace with actual key found above) export MULTISAGE_API_KEY="msk_..." ``` ### Technical Analysis The Skill tells the Agent to search both the project `.env` file and the user's home-level `~/.env` file. Accessing the home-level file crosses the project boundary and may expose credentials unrelated to the current task. Moreover, `grep` prints the complete matching line. If that line contains an assignment such as `MULTISAGE_API_KEY=msk_...`, the full secret is emitted into tool output. It may consequently be retained in Agent context, execution logs, terminal history, or audit records. Even the initial partial-key output unnecessarily discloses part of the credential. This violates least-privilege and secret-handling principles because the Skill only needs confirmation that an explicitly configured credential exists; it does not need to discover or display credentials from arbitrary environment files. ### Attack Path 1. The Skill is invoked while `MULTISAGE_API_KEY` is not inherited by the shell. 2. The Agent follows the documented troubleshooting instructions. 3. The Agent reads `.env` or `~/.env` with `grep`. 4. The command prints the complete API-key assignment into tool output. 5. The secret becomes available to any party or subsystem with access to the conversation, terminal output, or associated logs. 6. A party obtaining the key can submit queries to the service and consume the victim's credits until the key is revoked or its service-side limits are reached. ### Impact Assessment The direct impact is disclosure of the Multisage API k ...[truncated 330 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Global Installation of a Third-Party npm Package

Content
View full analysis
Remediation
View remediation
``` - Prefer a project-local, isolated installation over a global installation. - Commit and enforce a lockfile containing npm integrity metadata. - Verify package provenance, publisher identity, release signatures, and integrity before installation. - Use a trusted registry and prevent unreviewed registry overrides. - Disable lifecycle scripts where compatible with the package: ```bash npm install --ignore-scripts --save-exact multisage@ ``` - Re-review and test each dependency update before changing the pinned version. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Credential Access

High
Category
Privilege Escalation
Confidence
99% confidence
Finding

The skill explicitly instructs searching .env and ~/.env for MULTISAGE_API_KEY, which is credential discovery behavior. Reading secret-bearing files is dangerous because those files often contain unrelated API keys and tokens, and even partial echoing or handling of those values can leak credentials beyond the skill's intended purpose.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
echo "${MULTISAGE_API_KEY:0:8}"

# 2. If empty, look for it in common locations
grep MULTISAGE_API_KEY .env 2>/dev/null || grep MULTISAGE_API_KEY ~/.env 2>/dev/null

# 3. Export it (replace with actual key found above)
export MULTISAGE_API_KEY="msk_..."

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The invocation guidance is broad enough that the skill may trigger for generic requests like asking for expert opinions or deep research, even when the user did not intend to send data to an external multi-provider service. Overbroad triggering increases the chance of accidental data exfiltration, unnecessary charges, and use in contexts where external transmission is inappropriate.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill does not prominently warn that user prompts are transmitted to multiple third-party AI providers, despite the core function being multi-provider forwarding. Without clear disclosure, users may unknowingly send sensitive project, personal, or proprietary information to several external services at once, multiplying privacy and compliance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs the agent to inspect shell state and search local files such as .env and ~/.env for an API key. That exceeds the stated purpose of querying an external service and creates a credential-access path where the agent may read secrets from unrelated project or user files without explicit consent. In a fork/contextual agent setting, this is especially risky because local workspace data is commonly in scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The skill includes a cancel operation for in-progress deep research jobs, which is an account-affecting action outside the core read/query flow described by the skill. While not directly exposing secrets, it can modify remote account state or disrupt paid work if invoked unintentionally or on the wrong thread ID.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.