Back to skill

Security audit

mx-auto

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its local automation purpose, but it handles powerful tokens and can send them to configurable URLs without enough safety boundaries.

Review this skill before installing. It is intended for local Runtime automation and may run local triggers/scripts or read existing browser sandbox tab content. Only use it in an environment where Runtime base URLs and preferences are trusted, avoid storing cloud tokens with the preference helper, and rotate any Runtime or cloud token that may have been used with an untrusted configured URL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/run.sh:220
Finding

Runtime administrator token can be disclosed to an attacker-controlled endpoint

Content
View full analysis
/dev/null 2>&1; then printf '%s\n' "$candidate" return 0 fi done local fallback="${preferred:-${MX_APP_RUNTIME_BASE_URL:-${RPA_RUNTIME_BASE_URL:-$(pref_get defaultLocalBaseUrl)}}}" if [[ -n "$fallback" ]]; then printf '%s\n' "$fallback" else printf '%s\n' "${DEFAULT_RUNTIME_BASE_URLS[0]}" fi } ``` The automatically discovered administrator token is then attached to a request to that URL: ```bash fetch_trigger_services() { local base_url="$1" local token="$2" curl -fsS \ -H "Authorization: Bearer $token" \ "$base_url/trigger-services" } ``` ```bash LOCAL_RUNTIME_TOKEN="" EFFECTIVE_LOCAL_BASE_URL="" if [[ "$CONNECTION_MODE" == "local" || "$REFRESH_TRIGGERS" == "true" ]]; then LOCAL_RUNTIME_TOKEN="$(discover_runtime_admin_token "$APP_HOME")" ...[truncated 6170 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/export_preference.sh:173
Finding

Cloud bearer token can be stored and echoed in plaintext

Content
View full analysis
&2 exit 1 } ;; ``` The value is written directly into `preferences.json` without explicitly setting restrictive directory or file permissions: ```bash write_value() { local key="$1" local value="$2" local pref_path="$3" mkdir -p "$(dirname "$pref_path")" node -e ' const fs = require("node:fs"); const prefPath = process.argv[1]; const key = process.argv[2]; const rawValue = process.argv[3]; let data = {}; try { data = JSON.parse(fs.readFileSync(prefPath, "utf8")); } catch {} let value = rawValue; if (rawValue === "true") value = true; else if (rawValue === "false") value = false; else if (/^[0-9]+$/.test(rawValue)) value = Number(rawValue); else if (key === "triggerSnapshot" || key === "scriptSnapshot") value = JSON.parse(rawValue); data[key] = value; data.updatedAt = new Date().toISOString(); data.updatedBy = "user"; const tempPath = `${prefPath}.tmp-${process.pid}`; fs.writeFileSync(tempPath, JSON.stringify(data, null, 2) + "\n", "utf8"); fs.renameSync(tempPath, prefPath); ' "$pref_path" "$key" "$value" } ``` The `set-key` operation then prints the complete value: ```bash set-key) key="$(normalize_key "${2:-}")" value="${3:-}" [[ -n "$key" && -n "$value" ]] || { ...[truncated 2465 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (35)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

Reading sensitive token material from environment variables and local admin-token files, combined with runtime probing, creates a stronger capability set than the stated automation-entrypoint role suggests. Even if tokens are not printed, undisclosed credential access broadens the trust boundary and can enable privileged runtime interaction if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

Reading sensitive token material from environment variables and local admin-token files, combined with runtime probing, creates a stronger capability set than the stated automation-entrypoint role suggests. Even if tokens are not printed, undisclosed credential access broadens the trust boundary and can enable privileged runtime interaction if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

Reading sensitive token material from environment variables and local admin-token files, combined with runtime probing, creates a stronger capability set than the stated automation-entrypoint role suggests. Even if tokens are not printed, undisclosed credential access broadens the trust boundary and can enable privileged runtime interaction if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
91% confidence
Finding

Reading sensitive token material from environment variables and local admin-token files, combined with runtime probing, creates a stronger capability set than the stated automation-entrypoint role suggests. Even if tokens are not printed, undisclosed credential access broadens the trust boundary and can enable privileged runtime interaction if the skill is invoked in a permissive environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script accepts a bearer token, device ID, and dispatch parameters, then uses them to issue remote trigger.execute commands against a cloud API. For a skill described as local and read-only, this is an unjustified authenticated control path that could be abused to operate remote devices or workflows without appropriate disclosure or restriction.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script performs authenticated outbound HTTP dispatch and polling of cloud commands, which materially exceeds the stated skill purpose of local runtime automation and read-only browser sandbox inspection. This capability mismatch is dangerous because it can mislead users or reviewers about the trust boundary and allow covert remote device interaction under a benign-seeming skill description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises shell and environment-dependent execution pathways but declares no explicit tool scope or permissions boundary. In practice, this makes a powerful automation skill harder to govern and easier to invoke with broader-than-expected capabilities, especially since it can access local state, preference files, and wrapper scripts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script automatically discovers a runtime management token from environment variables or local admin-token.json files and then uses it to authenticate to the local browser runtime. Even though this is local-only by default, it silently expands the script's privilege and allows browser tab enumeration and snapshot access without explicit user confirmation, which can expose sensitive session or page content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script reads admin tokens from environment variables and local token files without any disclosure to the user. Silent credential discovery is risky because it uses privileged secrets the user may not intend this tool to access, and those credentials enable access to runtime-managed browser data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is described as read-only browser sandbox inspection, but the implementation performs authenticated POST requests to a management API endpoint using a bearer token. That mismatch reduces informed consent and increases risk because a user may not realize the operation depends on privileged runtime access and could retrieve sensitive browser metadata and snapshots.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script sends authenticated requests for tab metadata and snapshots without a user-facing warning, which can reveal sensitive URLs, page titles, and page text from an existing browser sandbox session. In the context of an agent skill, undisclosed collection from already-open tabs materially increases privacy and data exposure risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/browser_sandbox_bridge.sh (reported line 182)May include surrounding context.

sh
local endpoint="$1"
  local token="$2"
  local payload_json="$3"
  curl -sS \
    -H "Authorization: Bearer $token" \
    -H "Content-Type: application/json" \
    -d "$payload_json" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The script directly accepts a bearer token and transmits it in Authorization headers to a caller-supplied URL/path without any warning, disclosure, or trust restriction. This creates a credential-handling risk because users may supply sensitive tokens under the assumption the skill is local/read-only, and those credentials are then used for outbound authenticated requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

The curl POST sends JSON payloads and an Authorization bearer token to an external endpoint, constituting external data transmission. In isolation this can be legitimate, but in this skill context it is risky because the advertised purpose does not prepare the user for network egress or remote command dispatch.

Content

Scanner excerpt · scripts/cloud_dispatch_loop.sh (reported line 457)May include surrounding context.

sh
DISPATCH_URL="$(join_url "$BASE_URL" "$DISPATCH_PATH")"
log "dispatching target=$TARGET commandId=$COMMAND_ID"

dispatch_raw="$(curl -sS -w $'\n%{http_code}' -X POST \
  -H "Authorization: Bearer $TOKEN" \
  -H 'Content-Type: application/json' \
  -d "$ENVELOPE_JSON" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script accepts and stores a cloud token in a JSON preferences file under the user's home/state directory without any controls around secret storage, file permissions, or user warning. Persisting bearer-style credentials on disk increases the risk of credential disclosure through local compromise, backups, shared accounts, or accidental inspection by other tooling.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes the skill as an entrypoint for triggers, read-only browser sandbox inspection, and local script execution. This file is named and presented as an export/preferences utility, but it writes and unsets persistent preferences and snapshots in the skill state, which goes beyond read-only inspection semantics and includes configuration mutation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest does not mention destructive configuration management, but the clear subcommand removes the preferences file outright. File deletion is a stronger capability than inspection or execution entrypoint behavior and is not implied by the stated purpose.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The clear operation irreversibly removes the preferences file with no confirmation, dry-run option, or safety guard. In an automation context, a mistaken invocation or argument mix-up can silently wipe configuration, causing service disruption or loss of stored settings.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script automatically discovers a runtime admin token from environment variables or a local state file and then uses it for privileged operations. This is a sensitive credential-handling capability that materially expands what the skill can do, and it is not clearly justified by the high-level description, creating a hidden privilege escalation path within the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script silently reads a runtime admin token from the environment and uses it for authenticated requests without any user-visible disclosure or confirmation. In an agent skill context, undisclosed use of ambient credentials is dangerous because users may not realize the skill is acting with administrative authority on their local runtime.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script’s declared skill context emphasizes read-only browser inspection and local automation entrypoint behavior, but this code performs authenticated command dispatch to a runtime admin API capable of executing triggers and scripts. That mismatch is security-relevant because it hides an active execution capability behind a softer description, increasing the chance of users or orchestrators granting trust they would not otherwise give.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The script sends user-supplied payload data in an authenticated POST to the runtime command endpoint without any user-facing notice about what will be transmitted or executed. Because the payload is combined with an admin token and targets an execution API, this can trigger privileged actions that exceed a user’s expectation from the skill description.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/local_dispatch_loop.sh (reported line 219)May include surrounding context.

sh
SEND_URL="$(join_url "$BASE_URL" "/local/commands/send")"

raw="$(curl -sS -w $'\n%{http_code}' -X POST \
  -H "Authorization: Bearer $TOKEN" \
  -H 'Content-Type: application/json' \
  -d "$REQUEST_JSON" \

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script sources a runtime admin token from environment variables or a local admin-token.json file and then uses it for authenticated requests, meaning a low-friction preflight action gains privileged access to the local runtime. Reading and operationalizing admin credentials inside a broadly callable helper increases the chance of unintended privilege use, credential exposure through downstream components, or abuse by other skill flows.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The preflight script performs authenticated HTTP requests against localhost runtime endpoints, which goes beyond passive configuration validation and actively interacts with a privileged local service. In an agent-skill context, this expands the skill's capability surface to include local service discovery and authenticated probing, which can expose runtime state or be repurposed to access sensitive local APIs if invoked unexpectedly.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/preflight_check.sh:412