Back to skill

Security audit

Agent Cluster

Security checks for vulnerabilities and agentic risk

Overview

The skill bundles a much broader ERP/CMS/agent system than advertised and includes unsafe CMS execution paths that can make live changes or upload local files under weak controls.

Review before installing. Do not run this with real ERP, CMS, Amazon, or model API credentials until the scope is clarified and the preview, approval-timeout, upload-path, secret-export, and audit-logging issues are fixed. Use an isolated test environment and grant only narrowly scoped test credentials.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
cms_executor/engine/executor.py:220
Finding

Preview Mode Executes Live CMS Mutations While Claiming No Changes Are Made

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
cms_executor/agent_integration.py:278
Finding

Read-Only Roles Can Upload Arbitrary Local Files to a Remote CMS

Content
View full analysis
CMSResult: """Upload a media file.""" start = time.perf_counter() op = CMSOperation( operation_type=CMSOperationType.UPLOAD, resource_type=CMSResourceType.MEDIA, platform=self.platform, data={"file_path": file_path, "metadata": metadata or {}}, risk_level=RiskLevel.MEDIUM, ) ``` ```python # cms_executor/connectors/wordpress_connector.py:140-149 async def _do_upload_media( self, client: httpx.AsyncClient, file_path: str, metadata: dict ) -> dict: import mimetypes mime_type, _ = mimetypes.guess_type(file_path) with open(file_path, "rb") as f: file_content = f.read() files = { "file": ( file_path.split("/")[-1], file_content, mime_type or "application/octet-stream", ) } data_fields = {k: str(v) for k, v in metadata.items()} resp = await client.post( "/wp-json/wp/v2/media", files=files, data=data_fields ) ``` ```python # cms_executor/connectors/magento_connector.py:201-213 async def _do_upload_media( self, client: httpx.AsyncClient, file_pat ...[truncated 2515 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
cms_executor/engine/executor.py:352
Finding

Medium-Risk CMS Writes Are Automatically Approved After Human Approval Timeout

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
api_integration/api_config.py:166
Finding

ERP API Keys Are Exported to Plaintext YAML Files

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
cms_executor/engine/audit.py:334
Finding

Audit Log Flush Uses an Invalid File API and Silently Loses Durable Audit Records

Content
View full analysis
str: """Write an audit record in batches.""" self._pending.append(record.to_dict()) if self._enable_console: logger.info( f"[CMS_AUDIT] {record.event_type} | " f"{record.platform.value} | {record.agent_id} | " f"{record.resource_id[:20] if record.resource_id else ''}" ) if len(self._pending) >= self._flush_threshold: await self._flush() return record.record_id async def _flush(self) -> None: """Write pending records to disk.""" if not self._pending: return today = datetime.now(timezone.utc).strftime("%Y-%m-%d") log_file = self.log_dir / f"cms_audit_{today}.jsonl" lines = "\n".join( json.dumps(r, ensure_ascii=False) for r in self._pending ) log_file.write_text(lines + "\n", mode="a") self._pending.clear() ``` ```python # cms_executor/engine/executor.py:457-470 async def _emit_audit( self, plan: ExecutionPlan, ctx: ExecutionContext ) -> None: """Emit the audit log.""" try: await self.audit_logger.log_cms_write( operation=( plan.operations[0] if plan.operations else CMSOperation() ), result=ctx.results[0] if ctx.results else None, execution_context=ctx, trace_id=ctx.trace_id, ) except Exception as e: logger.warning(f"[executor] Audit log failed: {e}") ``` ### Technical Analysis `pathlib.Path.write_text()` does not accept a `mode` parameter. When the pending buffer reaches the flush threshold, `_flush()` raises `TypeError` instead of ...[truncated 1629 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (432)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The design materially exceeds the skill’s declared multi-CMS foreign-trade scope by adding GEO marketing, Amazon operations, customer service, memory, scheduling, and security infrastructure. This kind of scope expansion increases the attack surface and can cause the skill to access or act on data and systems users would not reasonably expect from the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Amazon-specific retail operations are presented as a first-class domain even though the skill metadata claims Shopify, WooCommerce, and Magento CMS orchestration. This mismatch can mislead operators about what data sources, APIs, and business actions the skill may touch, creating authorization and governance risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
93% confidence
Finding

The plan explicitly includes scraping support and anti-bot evasion measures such as multi-IP pools and request spacing, despite the skill being ներկայացted as a CMS coordination system. Evasion-oriented collection capabilities increase legal/compliance risk and create a pathway for unauthorized data harvesting, abuse of third-party services, and concealment of collection activity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The registry materially exceeds the skill’s declared purpose. Instead of a bounded Shopify/WooCommerce/Magento foreign-trade coordination skill, it defines a large GEO/Amazon operational cluster with broad orchestration, content, advertising, monitoring, memory, and reporting capabilities, creating capability drift and expanding what can be invoked far beyond user expectations. In an agent system, this increases attack surface, raises the chance of unauthorized task routing, and can enable misuse of unrelated business functions under an apparently narrower skill label.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The README describes an enterprise ERP-oriented multi-agent cluster, which materially conflicts with the manifest claiming an Amazon foreign-trade multi-CMS system for Shopify/WooCommerce/Magento. This kind of identity mismatch can mislead users about what the skill actually does, what systems it may connect to, and what data it may access, increasing the risk of unsafe installation or over-trust.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented integrations emphasize SAP, Yonyou, Kingdee, and REST ERP adapters rather than the declared CMS platforms. Users expecting storefront/CMS integrations could unknowingly enable access to back-office business systems, creating a serious transparency and trust problem around system boundaries and potential data exposure.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Listing only ERP integrations where the manifest promises Shopify/WooCommerce/Magento support is a substantive capability mismatch, not a minor docs inconsistency. In a security context, misleading integration claims can cause operators to grant credentials or approve deployment under false assumptions about reachable systems and operational impact.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
92% confidence
Finding

The body’s ERP MCP-service orientation contradicts the front matter’s foreign-trade multi-CMS framing. That is dangerous because users could unknowingly expose ERP-connected tooling when they believe they are enabling a commerce-platform skill with approvals and safeguards.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.insecure_tls_verification

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
cms-executor/README.md:163

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
memory/tests/test_immediate_skill_hook.py:62