Back to skill

Security audit

BytePlusCDN

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real BytePlus CDN management tool, but it handles cloud credentials and production CDN/log-delivery changes in ways that need careful review before use.

Install only in a virtual environment, pin or review dependencies first, and use least-privilege BytePlus credentials. Avoid putting secrets directly in command lines or using the JSON helper without a protected output path. Review every domain, purge, preload, and log-delivery command before running it, especially any all-domain option or external log destination, and require HTTPS endpoints for log delivery.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
reference/requirements.txt:1
Finding

Unpinned Third-Party Dependencies Permit Unreviewed Package Versions

Content
View full analysis
=1.0.0 click>=8.0.0 ``` The Skill instructs users to install these dependencies directly: ```bash cd /path/to/byteplus-cdn pip3 install -r reference/requirements.txt ``` ### Technical Analysis Both dependencies use open-ended `>=` constraints. Consequently, installation does not reproduce a specific reviewed dependency set: any future version published under either package name can satisfy the requirements. There is no lock file, hash verification, or upper version bound in the audited project. Package installation can execute package build or installation logic with the privileges of the user running `pip3`. Although no malicious dependency is currently demonstrated by the project files, this configuration creates a supply-chain exposure to compromised future releases and unexpected compatibility or security regressions. ### Attack Path 1. An attacker compromises the package registry account or release process for an allowed dependency, or otherwise causes a malicious future version to be published under the legitimate package name. 2. The malicious version remains compatible with the open-ended `>=` constraint. 3. A user follows `SKILL.md` and runs `pip3 install -r reference/requirements.txt`. 4. `pip` downloads and installs the new, unreviewed release. 5. Malicious build, installation, import-time, or runtime code executes with the installing user's privileges. ### Impact Assessment Successful exploitation could execute arbitrary code with the privileges of the user installing or running the Skill. Depending on those privileges, the attacker could access local files, environment variables, BytePlus credentials, cloud-storage credentials, and network resources available to that user. The issue does no ...[truncated 135 chars]
Remediation
View remediation
click== ``` 2. Generate a lock file containing transitive dependencies. 3. Record and enforce package hashes with `pip --require-hashes`. 4. Install from an explicitly configured trusted package index. 5. Review and test dependency updates before changing the lock file. 6. Use a dedicated virtual environment and avoid installing the Skill as a privileged system user. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cli.py:105
Finding

Cloud Credentials and Tokens Can Be Supplied Through Process Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/json_for_log.py:19
Finding

Credential Conversion Utility Prints Secrets or Writes Them with Ambient File Permissions

Content
View full analysis
"{\"type\":\"...\"}" escaped_json = json.dumps(json.dumps(data)) # Remove the outer quotes escaped_json = escaped_json[1:-1] if output_file: with open(output_file, 'w', encoding='utf-8') as out_f: out_f.write(escaped_json) print(f"Successfully escaped JSON to '{output_file}'") else: # Print to stdout so it can be captured or copied print(escaped_json) ``` ### Technical Analysis The utility is expressly intended to process credential JSON such as a GCP service-account document. When no output file is given, it prints the complete escaped credential to stdout. Standard output may be captured by terminal logs, CI systems, agent transcripts, shell redirection, or monitoring tools. When an output file is provided, ordinary `open(..., 'w')` creation relies on the process umask rather than enforcing owner-only access. The code also does not prevent writing through an existing symbolic link or overwriting an existing file. Therefore, the generated plaintext credential may have permissions broader than intended or may be redirected to an unintended target under adversarial local filesystem conditions. Escaping the JSON does not encrypt or redact it; private keys and tokens remain recoverable. ### Attack Path #### Standard-output disclosure 1. A user runs the utility without `--output`. 2. The complete GCP credential is printed to stdout. 3. A terminal recorder, CI log, agent transcript, or other output-capture mechanism stores it. 4. A party with access to the captured output recovers the service-account private key. 5. The attacker authenticates as that service account. #### Output-file dis ...[truncated 985 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/cli.py:458
Finding

Log-Delivery Configuration Accepts Plaintext HTTP Destinations

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (16)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The skill is presented as a BytePlus CDN operations tool, yet it apparently also supports arbitrary local JSON transformation and credential-like file processing unrelated to core CDN tasks. That expands the effective trust boundary: users may supply sensitive local files believing the skill is limited to CDN administration, while hidden or undocumented file-processing behavior can expose or misuse credential material.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is presented as a BytePlus CDN operations tool, yet it apparently also supports arbitrary local JSON transformation and credential-like file processing unrelated to core CDN tasks. That expands the effective trust boundary: users may supply sensitive local files believing the skill is limited to CDN administration, while hidden or undocumented file-processing behavior can expose or misuse credential material.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cdn_client.py (reported line 5)May include surrounding context.

python
from byteplus_sdk.cdn.service import CDNService

def init_cdn_client():
    # 只从项目根目录加载 .env 文件(安全边界)
    # 项目根目录是 scripts 目录的父级
    scripts_dir = os.path.dirname(os.path.abspath(__file__))
    project_root = os.path.dirname(scripts_dir)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cdn_client.py (reported line 9)May include surrounding context.

python
# 项目根目录是 scripts 目录的父级
    scripts_dir = os.path.dirname(os.path.abspath(__file__))
    project_root = os.path.dirname(scripts_dir)
    env_path = os.path.join(project_root, '.env')
    
    if env_path and os.path.exists(env_path):
        with open(env_path, 'r', encoding='utf-8') as f:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill requests or implies access to environment variables, file operations, and networked API usage, but it does not declare any explicit tool scope such as allowed tools or permissions. That weakens containment and reviewability because an agent may use broader capabilities than a user would reasonably infer from the manifest, especially when handling API keys and local files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill documents destructive or high-impact operations such as cache purge, prefetch, domain changes, and log delivery to third-party endpoints without prominent warnings or confirmation guidance. In production CDN environments, these actions can immediately affect live traffic, content availability, cache behavior, and external transmission of potentially sensitive logs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explicitly states that authentication information is loaded from environment variables or a .env file and may be interactively requested, but it provides no warning that these values are highly sensitive secrets. In a skill intended for CDN administration, this omission increases the chance that users store, copy, or share credentials insecurely, which could enable unauthorized access to CDN configuration and data delivery controls.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The example shows plaintext secret assignment in a .env file without any caution about exposure, which normalizes insecure handling of access keys. In the context of a CDN management skill, leaked credentials could let an attacker alter domains, purge or preload content, change origin settings, or access log delivery configurations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

When private S3 storage is configured, this function includes AccessKeyID and AccessKeySecret in the request body sent through the CDN client. The code prompts for the secrets, but it does not display any warning or confirmation that these credentials will be transmitted to an external service as part of task creation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This handler sends user-supplied configuration and realtime log delivery settings to remote services, and the caller commands populate it with sensitive tokens, access keys, or authentication payloads for SLS, HTTP Server, Splunk, and BigQuery. Although prompts collect secrets securely in some cases, there is no confirmation prompt or explicit user-facing warning here that the command will forward logs and embedded credentials to third-party endpoints.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest describes a skill for BytePlus CDN domain, policy, purge/prefetch, and log delivery management. This script is a generic JSON-escaping helper explicitly framed around handling large JSON credentials such as GCP service accounts and BigQuery-oriented escaping, which is not justified by the stated CDN-management purpose.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The docstring says the script is useful for passing large JSON credentials like GCP service accounts as command-line arguments, which points to a different operational intent than the BytePlus CDN-focused manifest. This creates an intent-level divergence between the documented purpose of the code and the advertised purpose of the skill package.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script prints the fully escaped JSON content to stdout, which can expose secrets such as service account keys or other credentials in terminal history, CI logs, shell capture, or process-monitoring environments. In the context of a skill that already references credentials outside its stated purpose, this behavior is more dangerous because users may treat the tool as a convenience helper and inadvertently leak sensitive material.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency specification for byteplus-sdk uses a lower-bound-only constraint, which allows future unreviewed versions to be installed. This weakens build reproducibility and can unintentionally introduce breaking changes or vulnerable releases through normal dependency resolution or supply-chain compromise.

Content

Scanner excerpt · reference/requirements.txt (reported line 1)May include surrounding context.

text
byteplus-sdk>=1.0.0
click>=8.0.0

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
99% confidence
Finding

The click dependency is also unpinned, so installations may resolve to different versions over time, including versions with known security issues. Because this package has an identified advisory in some releases, leaving the version unconstrained increases the chance of pulling an affected or otherwise unvetted version.

Content

Scanner excerpt · reference/requirements.txt (reported line 2)May include surrounding context.

text
byteplus-sdk>=1.0.0
click>=8.0.0

Unverifiable Dependency: click has 1 known advisory(ies) (CVE-2026-7246 (Pallets Click, versions 8.3.2 and below, contain a command injection vulnerabili)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
93% confidence
Finding

The manifest references click without pinning a version, and there is a known advisory affecting Click 8.3.2 and below. Because the installed version is not fixed or constrained to a safe release, consumers of this skill could end up installing an affected version, which is especially relevant if any CLI inputs are later passed into shell execution paths.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.