Back to skill

Security audit

测试测试测试

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed Tencent Cloud COS tool, but it asks for powerful cloud credentials and has weak local credential-storage and install-supply-chain safeguards.

Install only if you are comfortable giving this skill Tencent Cloud credentials with COS/CI authority. Prefer short-lived STS credentials with the smallest possible bucket-scoped policy, install dependencies before exporting credentials, avoid --persist when possible, and do not rely on .env.enc as strong secret storage.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
scripts/setup.sh:182
Finding

Unpinned npm Dependency Installation During Credentialed Setup

Content
View full analysis
&1 | tail -3) ok "cos-nodejs-sdk-v5 installation completed" ``` The corresponding skill metadata also declares the package without an exact version: ```json { "id": "node-cos-sdk", "kind": "node", "package": "cos-nodejs-sdk-v5", "label": "Install COS Node.js SDK" } ``` ### Technical Analysis The setup script installs `cos-nodejs-sdk-v5` without an exact version, committed lockfile, or integrity constraint. npm will resolve whichever package version currently satisfies the unspecified version requirement. Default npm behavior also permits package lifecycle scripts to execute during installation. The package name appears to refer to Tencent Cloud's official SDK; the audit found no evidence that the currently referenced package is malicious. The vulnerability is nevertheless an unsafe supply-chain boundary: the effective code installed in the future can differ from the code reviewed with this skill. This is particularly sensitive because users are instructed to export Tencent Cloud credentials before running: ```bash setup.sh --from-env ``` Consequently, npm and any dependency lifecycle process launched during installation may inherit `TENCENT_COS_SECRET_ID`, `TENCENT_COS_SECRET_KEY`, and an optional STS token. ### Attack Path 1. An attacker compromises the npm account, registry distribution channel, or a transitive dependency associated with the package. 2. The attacker publishes a modified package version or dependency containing a malicious npm lifecycle script. 3. A user exports Tencent Cloud credentials as directed by the skill. 4. The user runs `scripts/setup.sh --from-env` ...[truncated 1044 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/cos_node.mjs:31
Finding

Credential Encryption Uses Predictable Public Machine Attributes as the Key

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (56)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description presents a cloud storage/processing skill, but the body also performs local bootstrap, dependency installation, writes credentials to .env, edits .gitignore, and supports encrypt/decrypt of stored secrets. This mismatch can mislead users and reviewers about the real trust boundary and local side effects, increasing the chance of unintended credential exposure or workstation modification.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 145)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 204)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 681)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 684)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 691)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 730)May include surrounding context.

md
所有操作通过 `scripts/cos_node.mjs` 单一脚本完成,输出 JSON 格式。

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The skill instructs persisting cloud credentials to a local .env file via --persist. Even with chmod 600 and .gitignore, plaintext credentials on disk materially increase exposure through local compromise, backups, editor history, accidental copying, or later misuse by other tools on the same host.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

默认模式:凭证仅存于当前 session,关闭终端后需重新 export

{baseDir}/scripts/setup.sh --from-env

持久化模式:凭证写入项目本地 .env 文件,下次自动读取

{baseDir}/scripts/setup.sh --from-env --persist

text

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

Documenting built-in encrypt/decrypt support for .env-based credential storage confirms the skill manages recoverable local secret material rather than avoiding disk persistence. This increases the attack surface because any feature that decrypts secrets for use can also expose them if invoked in the wrong context or implemented unsafely.

Content

Scanner excerpt · SKILL.md (reported line 657)May include surrounding context.

md
| | `upload` → 指向知识库桶 | "上传到知识库" → 上传文档 |
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |

## 安全注意事项

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The presence of a decrypt-env action means the skill explicitly supports restoring plaintext secrets to disk. That undermines the claimed security posture because it normalizes a reversible secret-handling pattern and creates opportunities for accidental disclosure, malware scraping, or misuse by unrelated local processes.

Content

Scanner excerpt · SKILL.md (reported line 658)May include surrounding context.

md
| | `hybrid-search` → 指向知识库数据集 | "查询知识库" → 语义检索文档内容 |
| **🚫 禁止** | ~~deleteBucket~~ | **不允许删除/清空存储桶** |
| **🔐 凭证管理** | `encrypt-env` | 加密 .env → .env.enc 并删除明文 |
| | `decrypt-env` | 解密 .env.enc → .env 还原明文 |

## 安全注意事项

Credential Access

High
Category
Privilege Escalation
Confidence
98% confidence
Finding

The documented key derivation for .env encryption uses predictable local attributes (hostname, username, project path) rather than a high-entropy user secret or platform-protected key. If implemented as described, an attacker with knowledge of the host context or local access may be able to derive the same key, making the encryption far weaker than intended.

Content

Scanner excerpt · SKILL.md (reported line 692)May include surrounding context.

md
- 密钥派生:`SHA-256(hostname + username + 项目绝对路径)`
- **加密文件绑定当前机器和用户**,拷贝到其他机器/用户无法解密
- 如需还原明文:`node scripts/cos_node.mjs decrypt-env`
- 清理凭证:`rm -f .env .env.enc`

**其他安全要求**:
- **永远不要在对话中回显** SecretId/SecretKey

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 28)May include surrounding context.

js
// ========== 凭证加解密工具 ==========

const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");

// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 29)May include surrounding context.

sh
// ========== 凭证加解密工具 ==========

const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");

// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/setup.sh (reported line 137)May include surrounding context.

sh
// ========== 凭证加解密工具 ==========

const __dirname = dirname(fileURLToPath(import.meta.url));
const envPath = resolve(__dirname, "..", ".env");
const envEncPath = resolve(__dirname, "..", ".env.enc");

// 基于机器特征派生 AES-256 密钥(hostname + username + 项目绝对路径)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 74)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 94)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1206)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1208)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1211)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1215)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1228)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1252)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1262)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/cos_node.mjs (reported line 1264)May include surrounding context.

js
# 用法:
#   setup.sh --check-only              仅检查环境状态
#   setup.sh --from-env                从已有环境变量读取凭证并安装依赖(不持久化)
#   setup.sh --from-env --persist      从已有环境变量读取凭证并写入项目本地 .env 文件
#
# 安全默认行为:
#   - 默认凭证仅存于当前 shell session 环境变量,不写入磁盘

Static analysis

No suspicious patterns detected.