Back to skill

Security audit

新环境测试

Security checks for vulnerabilities and agentic risk

Overview

This is a real Tencent COS helper, but it deserves review because it can mutate cloud storage and locally store or decrypt powerful credentials with weakly protected persistence.

Install only if you are comfortable giving an agent Tencent COS/CI authority. Use short-lived STS credentials and a least-privilege sub-account limited to test buckets where possible. Avoid --persist and decrypt-env in shared or logged workspaces, do not rely on .env.enc as strong encryption, and require manual review before delete, delete-multiple, ACL/CORS, dataset binding, or ci-request actions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cos_node.mjs:33
Finding

Credential Encryption Uses Predictable Non-Secret Key Material

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:199
Finding

Setup Installs an Unpinned npm Dependency

Content
View full analysis
&1 | tail -3) ``` ### Technical Analysis The setup script installs `cos-nodejs-sdk-v5` without specifying an exact version. The audited project structure also does not contain a committed `package-lock.json` that would provide a reproducible dependency graph. Consequently, each setup run resolves whatever package version and transitive dependencies the npm registry serves at that time. Future upstream changes therefore become part of the effective Skill implementation without undergoing this audit. npm packages may execute lifecycle scripts during installation. If the named package, one of its transitive dependencies, or the package publisher’s account is compromised, malicious code could execute during setup with the privileges of the user running the script. The official-looking and documented package source reduces the likelihood of dependency confusion, but it does not eliminate supply-chain risk from mutable releases or transitive dependencies. ### Attack Path 1. An attacker compromises the publisher account, release process, registry delivery path, or a transitive dependency used by a future SDK release. 2. A malicious or compromised package version is published under the dependency name accepted by the unpinned installation command. 3. A user follows the documented setup process and runs `setup.sh --from-env`. 4. npm resolves and downloads the compromised release because no exact version or audited lockfile constrains resolution. 5. Malicious lifecycle code executes during installation, or malicious SDK code executes when `cos_node.mjs` imports the package. 6. The malicious code reads exported Tencent Cloud credentials or local credential files and performs actions with the user’s lo ...[truncated 645 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (58)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill is described primarily as a COS/CI operations integration, but the visible content heavily emphasizes local bootstrap behavior such as dependency installation, environment setup, credential persistence, and local secret encryption/decryption. This mismatch can mislead users and reviewers about the actual trust boundary, especially because local shell execution and credential storage are materially riskier than ordinary remote API calls.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 681)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 684)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 691)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 730)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill explicitly supports persisting cloud credentials to a local .env file. Even with permission controls and optional later encryption, writing plaintext credentials to disk materially increases exposure through local compromise, backups, editor history, accidental disclosure, and operational mistakes.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

默认模式:凭证仅存于当前 session,关闭终端后需重新 export

{baseDir}/scripts/setup.sh --from-env

持久化模式:凭证写入项目本地 .env 文件,下次自动读取

{baseDir}/scripts/setup.sh --from-env --persist

text

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

Advertising encrypt-env and decrypt-env as built-in credential-management actions confirms the skill handles local secret material beyond transient use. In particular, a decrypt capability increases the chance that plaintext credentials are recreated on disk during routine agent operation, widening the exposure window.

Content

Scanner excerpt · SKILL.md (reported line 657)May include surrounding context.

md
| | `upload` → 指向知识库桶 | "上传到知识库" → 上传文档 |
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |

## 安全注意事项

Credential Access

High
Category
Privilege Escalation
Confidence
87% confidence
Finding

The presence of a documented decryption path for .env.enc back to .env reinforces that the skill is designed to materialize sensitive credentials into plaintext locally. That capability is risky in shared workspaces or automated environments because it normalizes turning encrypted secrets back into broadly accessible files.

Content

Scanner excerpt · SKILL.md (reported line 658)May include surrounding context.

md
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |

## 安全注意事项

Credential Access

High
Category
Privilege Escalation
Confidence
94% confidence
Finding

The documented encryption scheme stores credentials in .env.enc and derives the key from predictable host/user/path material (SHA-256(hostname + username + project path)) rather than a high-entropy secret. This is not a robust secret-management design: an attacker with knowledge of the environment can likely reproduce the key, defeating the claimed protection and creating a false sense of safety around stored cloud credentials.

Content

Scanner excerpt · SKILL.md (reported line 692)May include surrounding context.

md
- 密钥派生:`SHA-256(hostname + username + 项目绝对路径)`
- **加密文件绑定当前机器和用户**,拷贝到其他机器/用户无法解密
- 如需还原明文:`node scripts/cos_node.mjs decrypt-env`
- 清理凭证:`rm -f .env .env.enc`

**其他安全要求**:
- **永远不要在对话中回显** SecretId/SecretKey

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 28)May include surrounding context.

js
// ========== 凭证加解密工具 ==========

const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");

// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 29)May include surrounding context.

sh
// ========== 凭证加解密工具 ==========

const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");

// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 137)May include surrounding context.

sh
// ========== 凭证加解密工具 ==========

const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");

// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 74)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 94)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1206)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1208)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1211)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1215)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1228)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1252)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1262)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1264)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Static analysis

No suspicious patterns detected.