Back to skill

Security audit

Internal Admin Playwright

Security checks for vulnerabilities and agentic risk

Overview

This internal admin automation skill is coherent in purpose, but it ships sensitive credentials and can make broad admin, VPN, and moderation changes with weak safeguards.

Review before installing. Do not use the packaged credentials; rotate any real VPN or admin credentials that may have been exposed. Run only in a disposable or dedicated environment unless the VPN helper is rewritten to avoid global /etc changes, shell injection risk, default-route replacement, broad process termination, OTP logging, and unsanitized debug captures.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (8)

T09 · Insecure Skill Coding Practices

Error
Location
references/vpn_config.yaml:2
Finding

Plaintext VPN Credentials Committed to the Project

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
debug/login_test.py:10
Finding

Administrative Account Credentials Hard-Coded in Executable Scripts

Content
View full analysis
1 else "" BASE_URL = "https://staff.bluemv.net/d.php" USERNAME = "wulongcha" PASSWORD = "wulongcha" SKILL_ROOT = Path(__file__).parent.parent ``` The scripts subsequently submit the credentials: ```python page.locator('input[name="username"]').fill(USERNAME) page.locator('input[name="password"]').fill(PASSWORD) page.locator('input[name="card_num"]').fill(OTP) ``` ### Technical Analysis Two executable scripts contain the same administrative username and password. The password is identical to the username, which is also a weak credential choice. Both scripts submit these values directly to the administration endpoint. Although an OTP appears to be required, multi-factor authentication does not make publishing the static authentication factor safe. An attacker who obtains an OTP through phishing, logging, endpoint compromise, or another weakness would already possess the remaining credentials. ### Attack Path 1. An attacker obtains the project or packaged Skill. 2. The attacker extracts the administration URL, username, and password from either script. 3. The attacker reaches the administration login page, potentially after using the separately exposed VPN credentials. 4. The attacker obtains a valid OTP through a separate compromise or disclosure. 5. The attacker authenticates and performs actions permitted to the exposed account. ### Impact Assessment The exposed account is used by scripts capable of reaching administrative functions and performing moderation actions. If the account and OTP are valid, exploitatio ...[truncated 178 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/vpn_l2tp.py:61
Finding

Root-Level Shell Command Injection Through VPN Server Configuration

Content
View full analysis
subprocess.CompletedProcess: return subprocess.run(cmd, shell=True, text=True, capture_output=True, check=check) ``` ```python def write_configs(cfg: dict): server = cfg.get("server", "").strip() username = cfg.get("username", "").strip() password = cfg.get("password", "").strip() psk = cfg.get("psk", "").strip() ``` ```python if cfg.get("route_all_traffic", True): gw = sh("ip route | awk '/default via/ {print $3; exit}'", check=False).stdout.strip() if gw: sh(f"ip route replace {server} via {gw} dev eth0", check=False) sh("ip route replace default dev ppp0", check=False) ``` ### Technical Analysis The `server` value originates in editable YAML configuration and is interpolated into a command string passed to `subprocess.run(..., shell=True)`. No IP-address or hostname validation is performed, and shell metacharacters are not escaped. VPN setup writes to `/etc` and modifies system routes, so the script is expected to run with elevated privileges. Consequently, command injection through `server` can inherit those privileges. ### Attack Path 1. An attacker modifies `references/vpn_config.yaml` before an administrator invokes the Skill. 2. The attacker places shell metacharacters and an additional command in the `server` value. 3. A user invokes `scripts/vpn_l2tp.py up`, or runs the main program with `AUTO_VPN=1`. 4. The value reaches the formatted `ip route replace` command. 5. Because `shell=True` is used, the shell parses and executes the injected command. 6. If VPN setup is running as root, the injected command also runs as root. A safe validation test can use a benign marker-file command in a disposable environment to confirm ...[truncated 378 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/whitelist.py:15
Finding

Domain Whitelist Bypassed by All Non-Document Requests

Content
View full analysis
``` ### Technical Analysis The Skill claims that requests to non-whitelisted domains are blocked, but the implementation only validates requests whose Playwright resource type is `document`. Requests classified as scripts, stylesheets, images, fonts, media, XHR, fetch, or other non-document types are always allowed. This means untrusted JavaScript on an otherwise allowed page can communicate with arbitrary external domains. The committed HTML artifact demonstrates that the target page already references an external resource. ### Attack Path 1. An attacker compromises the allowed administration site or one of its permitted exter ...[truncated 795 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run.py:257
Finding

One-Time Password and Account Details Disclosed Through Debug Logging

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.py:290
Finding

Authenticated Page Content Persisted in Unprotected Debug Artifacts

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/vpn_l2tp.py:29
Finding

VPN Automation Destructively Reconfigures Host-Wide Networking

Content
View full analysis
/var/log/xl2tpd-manual.log 2>&1 &") ``` ```python if gw: sh(f"ip route replace {server} via {gw} dev eth0", check=False) sh("ip route replace default dev ppp0", check=False) ``` ```python def down(skill_root: Path): sh("poff -a", check=False) sh("pkill pppd", check=False) sh("pkill xl2tpd", check=False) sh("/usr/sbin/ipsec down l2tp-psk", check=False) sh("/usr/sbin/ipsec stop", check=False) ``` ### Technical Analysis The VPN helper overwrites global IPsec, xl2tpd, and PPP configuration files rather than creating an isolated connection profile. It restarts and stops IPsec globally, terminates every `pppd` and `xl2tpd` process, and replaces the system default route. The implementation does not back up the prior configuration, record which processes it created, or restore the original default route. The `down()` operation can disrupt VPN sessions unrelated to this Skill. ### Attack Path 1. A privileged user invokes the documented VPN command or enables `AUTO_VPN=1`. 2. The Skill replaces existing files under `/etc`. 3. It terminates host-wide PPP and xl2tpd processes and restarts IPsec. 4. It changes the ...[truncated 567 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run.py:226
Finding

TLS Certificate Validation Disabled for Administrative Authentication

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
Findings (48)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

Partial or absent whitelist enforcement is a serious issue when the skill explicitly claims to prohibit external access. In a tool designed for internal admin systems, incomplete filtering can permit unexpected outbound requests, data exposure to unapproved domains, or loading of external resources that undermine the claimed security boundary.

Content

No source excerpt is available for this finding.

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · debug/last_error.html (reported line 11)May include surrounding context.

html
<link href="/static/admin/css/animate.min.css" rel="stylesheet">
    <link href="/static/admin/css/style.min862f.css?v=4.1.0" rel="stylesheet">
    <!--[if lt IE 9]>
    <meta http-equiv="refresh" content="0;ie.html"/>
    <![endif]-->
    <script>if (window.top !== window.self) {

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The page loads a third-party Cloudflare Insights beacon from an external domain, which directly contradicts the skill's stated prohibition on external network access for internal-admin automation. In an internal admin context, this can leak metadata about access to an internal login page, create undeclared outbound connectivity, and weaken trust boundaries around a supposedly isolated workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The script hardcodes a live-looking internal admin username and password directly in source, which exposes privileged credentials to anyone who can read the repository, logs, backups, or copied files. In the context of an internal admin Playwright skill, this is especially dangerous because the credentials enable direct access to a backend system and exceed what a diagnostic script should embed.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This script does more than menu navigation: it makes autonomous moderation decisions and executes approve/reject actions against a live internal admin system. In the context of a skill described as controlled internal automation, hidden decision-making logic materially increases risk because it can alter production content state at scale without human review.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

Hardcoded admin credentials in source code are a direct secret exposure risk. Anyone with access to the skill files, logs, backups, or version history can recover them and gain unauthorized access to the internal staff system, especially dangerous here because the target is an internal administrative interface.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · scripts/review_comments.py (reported line 31)May include surrounding context.

python
data = json.loads(path.read_text(encoding="utf-8"))
            rules = [r for r in data["rules"] if r.get("enabled")]
            print(f"已加载规则文件: {path}")
            return rules
    return []

def check_content(text, rules):

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script performs state-changing approval/rejection actions automatically in a live moderation system without user confirmation, warning, or rollback safeguards. If the rules are wrong, tampered with, or overly broad, the automation can rapidly cause censorship errors, policy violations, or loss of legitimate user content at scale.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
83% confidence
Finding

The code explicitly accesses a repository-local .env file as a credential source, which is a form of credential collection/persistence inside the skill package. For an internal admin automation tool, embedding or auto-loading secrets from local files increases exposure risk and makes compromise of the skill directory materially more damaging.

Content

Scanner excerpt · scripts/run.py (reported line 20)May include surrounding context.

python
def _load_dotenv(skill_root: Path) -> None:
    env_file = skill_root / "references" / ".env"
    if not env_file.exists():
        return
    for line in env_file.read_text(encoding="utf-8").splitlines():

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The debug output prints the OTP, username, and target URL directly to stdout during login. In a controlled internal-admin automation skill, these values are highly sensitive and may be captured by terminal logs, CI runners, shell history wrappers, centralized logging, or other observers, enabling credential replay or account compromise.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

This specific debug statement emits the OTP in cleartext with no warning or masking. OTPs are short-lived but still security-sensitive, and disclosure during an active login window can enable immediate unauthorized access or aid monitoring of authentication workflows.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Writing full page HTML to disk on failure can capture login forms, prefilled usernames, hidden tokens, internal URLs, session identifiers, and other sensitive application state. In an internal admin context, debug artifacts stored locally in predictable paths materially increase the risk of credential leakage and unauthorized insight into internal systems.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
98% confidence
Finding

This is a true tool-parameter abuse issue because the generic shell wrapper accepts arbitrary command strings and is later fed interpolated data. In a skill explicitly designed for internal admin/VPN access and likely run with elevated privileges, command injection has amplified impact: arbitrary code execution, network rerouting, credential theft, and host compromise.

Content

Scanner excerpt · scripts/vpn_l2tp.py (reported line 11)May include surrounding context.

python
def sh(cmd: str, check: bool = True) -> subprocess.CompletedProcess:
    return subprocess.run(cmd, shell=True, text=True, capture_output=True, check=check)


def load_cfg(skill_root: Path) -> dict:

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script overwrites system VPN/IPsec/PPP configuration under /etc and controls daemons without any confirmation, backup, or rollback. In a privileged automation context this can disrupt existing host networking or security configuration and can lock out administrators if run on the wrong machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The up/down flows modify the default route and terminate networking processes like pppd and xl2tpd without confirmation or safety checks. On an internal-admin automation skill, this can sever host connectivity, redirect all traffic through the VPN, or disrupt other active tunnels and administrative sessions.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The route guard only enforces the hostname whitelist for document navigations and explicitly allows all non-document requests such as scripts, XHR/fetch, images, fonts, and iframes' subresources to any destination. In an internal-admin automation skill, this can allow a whitelisted internal page to trigger requests to attacker-controlled or external hosts, causing data exfiltration, request smuggling to unapproved endpoints, or bypass of the stated 'no external access' control.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README explicitly describes the skill as using Chinese command routing, and the command configuration example is presented only in Chinese. Because no user opt-in, alternative language support, or justification for a Chinese-only interface is documented, this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file shows users setting STAFF_USERNAME, STAFF_PASSWORD, GOOGLE_OTP, and a login URL to run the skill, which clearly involves sensitive authentication data. While the README later advises not to commit real credentials, it does not explicitly warn users in the run instructions about secret exposure risks in shell history, process listings, or local environment handling.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill metadata declares no explicit tool scope even though it describes capabilities involving environment variables, file access, networking, and shell execution. In an automation skill that can manipulate VPN state and access internal admin systems, missing scope declarations weakens containment and can allow broader-than-expected execution in a sensitive environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description and command examples state that routing is based on Chinese instructions and show only Chinese command forms, which indicates a language-specific constraint. Because no user choice, opt-in, or justification for enforcing Chinese is provided in the natural-language description, this is a locale/language policy concern.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Third-party telemetry on an internal administrative login page is unnecessary for the described automation purpose and introduces avoidable data exposure to an external service. Even if it only collects page-view or timing data, it still creates an external reporting channel from a sensitive internal workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script accesses and uses sensitive authentication data from hardcoded literals without any protection, warning, or justification, which increases the likelihood of accidental exposure and reuse. This is not merely a UX omission: the code itself stores plaintext admin credentials in a retrievable form, making compromise of the repository or workstation sufficient to obtain them.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.