Back to skill

Security audit

automate-it

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for managing Automate It content workflows, but it can send its API key to any configured API URL and has high-impact publishing/deletion capabilities.

Install only if you trust Automate It and need an agent to manage content workflows. Use the narrowest API key scopes possible, leave AUTOMATE_IT_API_URL unset unless you intentionally use a trusted HTTPS endpoint, and be especially careful with reviewer/admin keys, --no-review, publish, schedule, automation, file, folder, and delete commands.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
ait.mjs:247
Finding

Bearer API Key Disclosure Through an Unvalidated Configurable API Endpoint

Content
View full analysis

Vulnerability Details

File Location: ait.mjs:247-273
Vulnerability Type: Unvalidated credential destination and plaintext transport exposure
Risk Level: Medium

Vulnerable Code

js
function baseUrl(ctx) {
  return (ctx.env.AUTOMATE_IT_API_URL || DEFAULT_API_URL).replace(/\/+$/, "");
}

function apiKey(ctx) {
  const key = ctx.env.AUTOMATE_IT_API_KEY;
  if (!key) {
    throw new CliError(
      "AUTOMATE_IT_API_KEY is not set. Create an API key in Automate It (Profile → API keys) and export it."
    );
  }
  return key;
}

async function mcpRequest(ctx, method, params) {
  const url = `${baseUrl(ctx)}/mcp`;
  let res;
  try {
    res = await ctx.fetchFn(url, {
      method: "POST",
      headers: {
        Authorization: `Bearer ${apiKey(ctx)}`,
        "Content-Type": "application/json",
        Accept: "application/json, text/event-stream",
      },
      body: JSON.stringify({ jsonrpc: "2.0", id: 1, method, params }),
      signal: AbortSignal.timeout(REQUEST_TIMEOUT_MS),
    });

Technical Analysis

The CLI accepts AUTOMATE_IT_API_URL as an unrestricted API base URL. The value is only normalized by removing trailing slashes; its scheme, hostname, port, and trust relationship are not validated.

Every MCP request then attaches AUTOMATE_IT_API_KEY as a bearer credential in the Authorization header. As a result, any party capable of influencing the process environment can redirect authenticated requests to an attacker-controlled endpoint. The implementation also accepts an http:// URL, allowing the credential and request content to travel without transport encryption.

Sending workspace data to the Automate It API is necessary for the Skill's declared remote task-management and publishing functionality. However, sending the bearer credential to an arbitrary destination is not required for ordinary production use and exceeds a safe le ...[truncated 2013 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require encrypted transport

    • Parse the configured endpoint with the standard URL class.
    • Reject every scheme other than https:.
    • Permit plaintext HTTP only under a clearly named development-only option, and never send production credentials through that mode.
  2. Restrict credential destinations

    • Allowlist api.automate.it.com for normal production operation.
    • If private or self-hosted endpoints are required, use a separate explicit configuration containing an administrator-approved hostname allowlist.
    • Reject URLs containing embedded user information or unexpected ports.
  3. Require explicit trust for custom endpoints

    • Treat a non-default endpoint as a sensitive security decision rather than an ordinary environment override.
    • Require an explicit option such as AUTOMATE_IT_ALLOW_CUSTOM_API_HOST=true.
    • Display the normalized destination hostname before transmitting credentials, without printing the API key.
  4. Reduce credential impact

    • Continue recommending narrowly scoped API keys.
    • Use separate keys for read-only monitoring, content submission, publishing, and administrative operations.
    • Rotate and revoke any key suspected of having been sent to an untrusted endpoint.
  5. Add automated validation tests

    • Verify that http:// endpoints are rejected.
    • Verify that unapproved hostnames are rejected.
    • Verify that malformed URLs and credential-bearing URLs are rejected.
    • Verify that the bearer header is attached only after endpoint validation succeeds.

A hardened implementation should validate the endpoint before constructing any authenticated request, for example:

js
function baseUrl(ctx) {
  const configured = ctx.env.AUTOMATE_IT_API_URL || DEFAULT_API_URL;
  let url;

  try {
    url = new URL(configured);
  } catch {
    throw new CliError("AUTOMATE_IT_API_URL must b
...[truncated 543 chars]
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (52)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 56)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 68)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 81)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 97)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 105)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 115)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 117)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 121)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 159)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 202)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 219)May include surrounding context.

md
All commands use the bundled CLI: `./ait.mjs` (Node 18+ or Bun; also runs as `node ait.mjs …`). It speaks the same MCP server that human-driven clients (Claude

Static analysis

No suspicious patterns detected.