Back to skill

Security audit

Jenkins Skills

Security checks for vulnerabilities and agentic risk

Overview

This Jenkins skill is generally coherent, but it can automatically use Jenkins credentials to trigger, disable, or enable CI jobs without an enforced confirmation step.

Install only if you are comfortable giving the agent access to Jenkins credentials. Use a least-privilege Jenkins token, prefer read-only credentials for routine inspection, avoid production jobs unless separately approved, and require explicit user confirmation before any build, enable, or disable action.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/jenkins_cli.py:174
Finding

State-Changing Jenkins Operations Do Not Enforce User Confirmation

Content
View full analysis

Vulnerability Details

File Location: scripts/jenkins_cli.py, lines 174–183, 204–214, and 228–249
Vulnerability Type: Missing authorization confirmation for state-changing operations
Risk Level: Medium

Vulnerable Code

python
def cmd_build(cfg, args):
    params = {}
    for kv in args.param or []:
        if "=" not in kv:
            die(f"--param expects KEY=VALUE, got: {kv}")
        k, v = kv.split("=", 1)
        params[k] = v
    if params:
        path = job_path(args.name) + "/buildWithParameters"
        resp = request(cfg, "POST", path, expect_json=False, params=params)
    else:
        path = job_path(args.name) + "/build"
        resp = request(cfg, "POST", path, expect_json=False)
    out({"job": args.name, "queued": True,
         "queue_url": resp.headers.get("Location")})
python
def cmd_enable(cfg, args):
    request(cfg, "POST", job_path(args.name) + "/enable", expect_json=False)
    out({"job": args.name, "enabled": True})


def cmd_disable(cfg, args):
    request(cfg, "POST", job_path(args.name) + "/disable", expect_json=False)
    out({"job": args.name, "disabled": True})
python
s = sub.add_parser("build", help="trigger a build")
s.add_argument("name")
s.add_argument("--param", action="append", help="KEY=VALUE (repeatable)")
s.set_defaults(func=cmd_build)

...

s = sub.add_parser("enable", help="enable a job")
s.add_argument("name")
s.set_defaults(func=cmd_enable)

s = sub.add_parser("disable", help="disable a job")
s.add_argument("name")
s.set_defaults(func=cmd_disable)

Technical Analysis

The build, enable, and disable commands issue authenticated Jenkins POST requests immediately after parsing their arguments. They do not require an explicit confirmation flag, an interactive confirmation prompt, a dry-run step, or an approval token bound to the selected job and parameters.

SKILL.md instructs ...[truncated 2262 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require an explicit confirmation control for every state-changing command, such as --confirm.
  2. Before confirmation, display the exact Jenkins URL, operation, normalized job name, and complete build parameter set.
  3. In interactive use, prompt for approval and default to rejection. Do not treat empty input as approval.
  4. For Agent or non-interactive execution, use a short-lived approval value bound to the exact operation, job, and parameters rather than a reusable global switch.
  5. Provide a --dry-run mode that reports the intended request without sending it.
  6. Consider an allowlist for approved jobs or environments, particularly where the configured account can access production pipelines.
  7. Use separate least-privilege Jenkins tokens for read-only inspection, build triggering, and job configuration so that routine status checks cannot exercise unnecessary mutation privileges.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes capabilities that rely on environment variables and outbound network access to a Jenkins server, yet it does not declare any tool scope or permission boundaries. In an agent setting, that omission can let the skill be invoked with broader-than-expected authority, increasing the chance of unauthorized job triggering, job disabling, or access to sensitive build logs and metadata.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The activation guidance is broad enough that a generic user request about builds, logs, or CI could automatically trigger this skill, even when the user did not clearly intend Jenkins operations. Because the skill can perform mutating actions against CI infrastructure, overbroad activation materially raises the risk of accidental or socially engineered execution.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The example triggers use casual phrases like running a deployment task or fetching failed logs without enough specificity, which may match ordinary conversational requests. In the context of a skill that can contact Jenkins and change job state, ambiguous triggers increase the likelihood of unintended activation and potentially disruptive CI actions.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation without any visible trigger constraints, exclusions, or confirmation requirements. Because this skill can inspect jobs, trigger builds, stream logs, and enable or disable Jenkins jobs, broad automatic invocation increases the chance of unintended CI actions or disclosure of sensitive build information from ambiguous user requests.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/USAGE.md (reported line 47)May include surrounding context.

}

text

> `chmod 600 ~/.devops-skills/jenkins.json`,切勿提交到仓库。

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The usage guide explicitly documents disabling and enabling Jenkins jobs, which are operationally destructive or availability-impacting actions, but it does not warn users about service disruption, approval requirements, or scope limits. In an agent skill context, exposing these actions as normal commands increases the chance that an LLM or user triggers them without understanding the production impact.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The natural-language activation examples are broad and map directly to sensitive Jenkins actions such as triggering builds and retrieving logs, without clear constraints on authorization, environment, or confirmation requirements. In an agent-driven workflow, vague triggers can cause unintended execution of impactful CI/CD operations from casual user phrasing.

Content

No source excerpt is available for this finding.

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The dependency is only range-pinned as requests>=2.25,<3, which means installation may resolve to multiple versions and the manifest does not guarantee exclusion of known vulnerable releases. In a Jenkins-management skill that likely makes authenticated HTTP requests to a CI server, a vulnerable requests version could expose credentials, weaken TLS/request handling, or otherwise increase risk when interacting with attacker-controlled URLs or redirects.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.