Back to skill

Security audit

carl's corkie -- a digitial corkboard for your agent

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real dashboard helper, but it installs and runs unverified remote code and exposes a shared bearer-token service in ways users should review carefully.

Install only if you trust the upstream GitHub repository and are comfortable running its npm and PM2 scripts locally. Keep it on localhost or behind a trusted authenticated proxy, avoid plaintext LAN or public exposure, rotate the shared token if exposed, and treat the .env token as a real credential.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T03 · Remote Payload Retrieval and Execution

Warning
Location
scripts/install.sh:76
Finding

Mutable Remote Repository Is Retrieved and Executed Without Integrity Verification

Content
View full analysis
/dev/null || warn "Could not pull (may have local changes)" fi else log "Cloning dashboard to $INSTALL_DIR..." mkdir -p "$(dirname "$INSTALL_DIR")" git clone "$REPO_URL" "$INSTALL_DIR" fi cd "$INSTALL_DIR" # --- Install dependencies --- log "Installing dependencies..." npm install ``` ```bash # --- Build --- log "Building project..." npm run build # --- Start --- if [[ $HAS_PM2 -eq 1 ]]; then log "Starting with PM2..." # Stop existing instances if running pm2 delete corkie-server 2>/dev/null || true pm2 delete corkie-client 2>/dev/null || true npm run pm2:start ``` ### Technical Analysis The installer clones or updates a mutable Git repository and immediately executes repository-controlled npm lifecycle, build, and PM2 scripts. It does not pin a reviewed commit or signed release and does not verify a cryptographic checksum, Git signature, or expected revision. `git pull --ff-only` prevents non-fast-forward history changes but does not establish trust in newly fetched commits. Likewise, `npm install` can execute lifecycle hooks from the project and its dependencies. The subsequent `npm run build` and `npm run pm2:start` commands execute scripts defined by the remotely retrieved project. Although remote installation is part of the declared setup behavior, the absence of integrity controls means the code executed at installation time can differ from the code reviewed in this Skill package. ### Attack Path 1. An attacker compromises the upstream repository, a maintainer account, or a dependency referenced ...[truncated 1052 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/setup.md:27
Finding

Server Bearer Token Is Embedded in the Public Client Bundle

Content
View full analysis
VITE_CORKBOARD_TOKEN= ``` ### Technical Analysis Values exposed through Vite client configuration are incorporated into frontend assets and must be treated as public information. The documented setup places the same value in both `CORKBOARD_TOKEN` and `VITE_CORKBOARD_TOKEN`, meaning the credential used by the backend is recoverable from the client bundle. Bearer credentials provide access based solely on possession. Consequently, any party that can load, download, or otherwise inspect the dashboard's JavaScript assets can recover the shared token and use it independently of the frontend. This issue is particularly significant because the documented API supports reading and mutating pins and projects, restoring deleted records, changing project state, and controlling lamp state. The documentation also states that the backend binds to `0.0.0.0` by default, making the service reachable from the local network unless external controls prevent access. ### Attack Path 1. An attacker obtains network access to the dashboard frontend or acquires a copy of its generated static assets. 2. The attacker searches the JavaScript bundle or network requests for the embedded `VITE_CORKBOARD_TOKEN`. 3. Because the client token matches `CORKBOARD_TOKEN`, the attacke ...[truncated 1079 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/corkboard.sh:14
Finding

Bearer Token Can Be Sent Over Plaintext HTTP to Non-Loopback Endpoints

Content
View full analysis
:3010" ``` The setup guide also states: ```text The backend binds to `0.0.0.0` by default, so the production app is reachable at both `http://localhost:3010` and `http://:3010`. ``` ### Technical Analysis The CLI attaches a reusable bearer token to requests but does not validate the destination scheme or distinguish loopback endpoints from remote hosts. Plaintext HTTP does not protect request headers from observation or modification. Using HTTP on `localhost` normally avoids transmission over the physical network. However, the documented LAN mode sends the same bearer credential over an unencrypted network connection. A network-adjacent attacker capable of traffic capture, ARP spoofing, malicious access-point operation, DNS manipulation, or gateway control may obtain the token. Because the credential is reusable and not cryptographically bound to a specific request, client, or TLS session, a captured token can be replayed directly. ### Attack Path 1. A user configures `CORKBOARD_API` with the documented `http://:3010` form. 2. The CLI reads `CORKBOARD_TOKEN` from the environment or `.env`. 3. The CLI includes the token in the plaintext HTTP `Authorization` header. 4. A network-adjacent attacker intercepts the request or redirects it through an attacker-controlled endpoint. 5. The attacker extracts ...[truncated 726 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as board management, but the instructions include cloning a remote repository, running an installer, reading and writing environment configuration, and managing services. This is a significant trust-boundary violation because it can lead to local code execution and persistent system changes under the guise of a simple dashboard skill.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The skill presents itself as board management, but the instructions include cloning a remote repository, running an installer, reading and writing environment configuration, and managing services. This is a significant trust-boundary violation because it can lead to local code execution and persistent system changes under the guise of a simple dashboard skill.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
93% confidence
Finding

The skill instructs extracting a bearer token directly from a local .env file and exporting it into the shell environment. This is sensitive credential access; in an agent or shared-shell context it can expose the token to logs, subprocesses, command history, or unrelated tasks, enabling unauthorized dashboard access.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

CORKBOARD_API=https://corkie-api.example.com

CORKBOARD_TOKEN is auto-loaded from .env. To set it manually:

export CORKBOARD_TOKEN="$(grep '^CORKBOARD_TOKEN=' /path/to/dashboard/.env | cut -d= -f2-)"

text

3. Post work with the bundled helper (it adds the auth header for you):

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · references/setup.md (reported line 154)May include surrounding context.

Reset local data:

bash
rm server/data/corkboard.db

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/api.md (reported line 24)May include surrounding context.

md
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 65)May include surrounding context.

md
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/setup.md (reported line 67)May include surrounding context.

md
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corkboard.sh (reported line 8)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corkboard.sh (reported line 10)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corkboard.sh (reported line 17)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corkboard.sh (reported line 26)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corkboard.sh (reported line 28)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corkboard.sh (reported line 89)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/corkboard.sh (reported line 90)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 91)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 93)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 94)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 96)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 98)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 100)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 104)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/install.sh (reported line 111)May include surrounding context.

sh
# Environment:
#   CORKBOARD_API       - API endpoint (default: http://localhost:3010)
#   CORKBOARD_TOKEN     - Bearer token for the corkboard server. If unset, the
#                         script reads it from $CORKBOARD_ENV_FILE (default .env
#                         in the current directory).
#   CORKBOARD_ENV_FILE  - .env file to load CORKBOARD_TOKEN from (default: ./.env)
#   CORKBOARD_AUTH      - set to "disabled" to skip auth (matches server flag)

Credential Access

High
Category
Privilege Escalation
Confidence
84% confidence
Finding

The script reads CORKBOARD_TOKEN directly from the application's .env file for reuse in a request header. While this is likely intended for a local health check, it normalizes plaintext secret storage and shell-level secret handling, which increases exposure through local file compromise, process inspection, debugging, or accidental logging in adjacent tooling.

Content

Scanner excerpt · scripts/install.sh (reported line 138)May include surrounding context.

sh
log "Checking if server is responding..."
HEALTHY=0
HEALTH_TOKEN=""
if [[ -f "$INSTALL_DIR/.env" ]]; then
    HEALTH_TOKEN=$(grep -E '^CORKBOARD_TOKEN=' "$INSTALL_DIR/.env" | tail -n1 | cut -d= -f2- | tr -d '"' | tr -d "'" | xargs || true)
fi
for i in 1 2 3 4 5; do

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

This line extracts a bearer token from .env into a shell variable, increasing the risk of credential exposure through shell tracing, inherited environments, crash dumps, or future script modifications that may print variables. In the context of an installer for a dashboard skill, this is more concerning because the same script also configures a service that binds to 0.0.0.0 by default, making token-protected API access operationally important.

Content

Scanner excerpt · scripts/install.sh (reported line 139)May include surrounding context.

sh
HEALTHY=0
HEALTH_TOKEN=""
if [[ -f "$INSTALL_DIR/.env" ]]; then
    HEALTH_TOKEN=$(grep -E '^CORKBOARD_TOKEN=' "$INSTALL_DIR/.env" | tail -n1 | cut -d= -f2- | tr -d '"' | tr -d "'" | xargs || true)
fi
for i in 1 2 3 4 5; do
    if curl -sf -H "Authorization: Bearer $HEALTH_TOKEN" "http://localhost:$PORT/api/pins" >/dev/null 2>&1; then

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill clearly instructs use of shell commands and network access, but it declares no explicit tool scope or permission boundaries. In an agent environment, that omission increases the chance the skill is invoked with broader capabilities than users expect, enabling unintended installs, API calls, or system changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.