Back to skill

Security audit

Casdoor-api-assistant

Security checks for vulnerabilities and agentic risk

Overview

This Casdoor API helper is mostly coherent, but it can guide users into generating sensitive OAuth secrets in URLs and lists high-impact admin endpoints without enough warnings.

Install only if you are comfortable reviewing generated Casdoor requests before use. Do not paste real client secrets, refresh tokens, passwords, or access tokens into generated URLs; prefer environment variables, secret stores, or request bodies where supported. Treat examples for delete, payment, token, session, impersonation, MFA, and user-management endpoints as privileged operations requiring explicit authorization and careful confirmation.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
references/endpoint-index.md:302
Finding

OAuth Client Secrets and Refresh Tokens May Be Placed in URL Query Strings

Content
View full analysis

Vulnerability Details

File Location: references/endpoint-index.md:302-303, used with the parameter-mapping instructions in references/example-patterns.md:11-15
Vulnerability Type: Sensitive information exposure through URL query parameters
Risk Level: Medium

Vulnerable Code Snippets

references/endpoint-index.md:302-303:

markdown
- `POST /api/login/oauth/access_token` — get OAuth access token (params: grant_type:query, client_id:query, client_secret:query, ...)
- `POST /api/login/oauth/refresh_token` — refresh OAuth access token (params: grant_type:query, refresh_token:query, scope:query, ...)

references/example-patterns.md:11-15:

markdown
- Path parameters stay in the URL path.
- Query parameters go in the query string and should only include values the user actually supplied.
- Body parameters should be serialized as JSON unless the Swagger operation states another content type.
- Header values such as bearer tokens should use placeholders like `<access-token>` when not provided.

Technical Analysis

The endpoint index classifies client_secret and refresh_token as query parameters. The example-generation rules then explicitly instruct the agent to place all parameters classified as query into the URL query string.

Consequently, generated OAuth requests may take forms equivalent to:

text
POST /api/login/oauth/access_token?...&client_secret=REAL_SECRET
POST /api/login/oauth/refresh_token?...&refresh_token=REAL_REFRESH_TOKEN

Although transmitting credentials to the intended Casdoor token endpoint is necessary for the declared functionality, placing them in a URL exceeds the minimum exposure required. OAuth credentials should normally be sent in the request body using application/x-www-form-urlencoded, or through another authentication mechanism explicitly supported by the deployment. HTTPS protects the request while in transit but does not prevent URL disclosure through:

  • Reverse-proxy, ingress, ...[truncated 2188 chars]
Remediation
View remediation

Remediation Suggestions

  1. Override the imported endpoint metadata for OAuth token operations so that client_secret and refresh_token are treated as form-body parameters rather than query parameters.
  2. Generate token requests using Content-Type: application/x-www-form-urlencoded, for example:
bash
curl -X POST 'https://&lt;casdoor-host&gt;/api/login/oauth/access_token' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/x-www-form-urlencoded' \
  --data-urlencode 'grant_type=&lt;grant-type&gt;' \
  --data-urlencode 'client_id=&lt;client-id&gt;' \
  --data-urlencode 'client_secret=&lt;client-secret&gt;'
  1. Add an explicit safety rule to references/example-patterns.md: passwords, client secrets, authorization codes, access tokens, and refresh tokens must not be placed in URL paths or query strings, even if generated Swagger metadata classifies them as query parameters.
  2. Use placeholders by default and avoid reproducing real credentials supplied in conversation. Instruct users to inject secrets through environment variables, protected secret stores, or interactive input.
  3. Redact sensitive values from displayed commands, debugging output, logs, and error reports.
  4. If a particular Casdoor version accepts credentials only in the query string, clearly warn the user about logging exposure, recommend upgrading or changing server configuration, and avoid presenting that mode as the default.
  5. Add regression tests or review checks ensuring generated URLs never contain parameter names such as client_secret, refresh_token, password, access_token, or authorization codes.
  6. Rotate any credential that has already appeared in a URL or associated operational logs, and purge or restrict access to affected logs where feasible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (6)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
1. Start with `references/endpoint-index.md`

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/auth-and-debugging.md (reported line 9)May include surrounding context.

md
1. Verify the endpoint path and HTTP method from `references/endpoint-index.md`.
2. Verify every required path, query, and body parameter.
3. Verify whether the request should include an access token, cookie, or no auth at all.
4. Compare the caller's request shape with the generated curl or code example.
5. Inspect the response code and map it to the most likely root cause.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · references/example-patterns.md (reported line 51)May include surrounding context.

)

text

## Output Rules

- Always explain which parameter values are placeholders.
- When a user asks for JS or Python examples, mirror the same endpoint and parameters as the curl example.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instruction to use this file whenever 'the user describes a business task but does not know which endpoint family fits it' is a broad natural-language trigger for a markdown skill reference. It does not define boundaries, examples of when not to use the file, or any narrower routing criteria, which could cause unintended invocation for many generic business-task queries.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The section is labeled Verification API, but its listed typical paths are /api/get-payment, /api/get-payments, and /api/get-user-payments, which are payment-related rather than verification-related. This is an active documentation contradiction that could misroute users or agents to the wrong endpoint family.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown file instructs users to use it first to choose endpoints, and it enumerates numerous destructive or security-sensitive actions such as delete, update, password, token, impersonation, payment, and webhook operations. There is no accompanying warning that these endpoints can modify data, affect authentication state, or trigger irreversible actions, which can mislead users into treating the index as purely informational and low-risk.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.