Back to skill

Security audit

code-right

Security checks for vulnerabilities and agentic risk

Overview

This skill clearly submits software-copyright material details to a remote service that generates documents and emails a download link, with no evidence of hidden local persistence or destructive behavior.

Install only if you are comfortable sending the system name, recipient email, optional description, and any optional access token to softcraft.cloud for hosted processing. Avoid including confidential system details unless approved, double-check the email recipient, and do not pass an access token unless you need authenticated task filtering or protected downloads.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/create_task.py:37
Finding

Access Token May Be Disclosed Through Cross-Origin HTTP Redirects

Content
View full analysis

Vulnerability Details

File Location: scripts/create_task.py, lines 37-41
Vulnerability Type: Sensitive credential exposure through unsafe redirect handling
Risk Level: Medium

python
headers = {"Content-Type": "application/json"}
if args.access_token:
    headers["access_token"] = args.access_token

req = urllib.request.Request(url=url, data=data, headers=headers, method="POST")
try:
    with urllib.request.urlopen(req, timeout=30) as resp:

Technical Analysis

The script places the user-provided access token in a custom HTTP header and sends the request using urllib.request.urlopen. This function follows supported HTTP redirects by default, while the code does not validate redirect destinations or explicitly prevent the sensitive custom header from being forwarded.

Consequently, a compromised or misconfigured API server, reverse proxy, CDN, or DNS/TLS-controlled endpoint could return a redirect to another origin. Depending on the runtime's redirect behavior, the custom access_token header may be copied into the redirected request. Unlike secure clients that explicitly remove authorization credentials on cross-origin redirects, this implementation establishes no origin-boundary protection for the custom credential.

Attack Path

  1. A user invokes the script with a valid --access-token.
  2. The script adds that value to the access_token request header.
  3. The request is sent to https://softcraft.cloud/api/skill/tasks/.
  4. A compromised or misconfigured API endpoint, reverse proxy, or CDN responds with a supported redirect to an attacker-controlled HTTPS origin.
  5. The default redirect handler follows the redirect without application-level validation of the destination.
  6. If the custom header is retained by the active Python runtime, the attacker-controlled server receives and records the access token.
  7. The attacker reuses the captured token against any service operations for ...[truncated 724 chars]
Remediation
View remediation

Remediation Suggestions

  1. Disable automatic redirects for requests carrying credentials, or use a custom redirect handler that inspects every redirect before following it.
  2. Permit redirects only when the destination uses HTTPS and its normalized hostname is exactly softcraft.cloud. Validate the effective port and reject user-information components, malformed hostnames, and hostname-suffix tricks.
  3. Remove the access_token header whenever the scheme, hostname, or port changes. Do not rely solely on library-version-specific redirect behavior.
  4. Prefer the standard Authorization: Bearer ... scheme where supported, while still enforcing explicit cross-origin credential stripping.
  5. Use narrowly scoped, short-lived tokens and implement server-side revocation and expiration.
  6. Add automated tests covering same-origin redirects, cross-origin redirects, HTTPS-to-HTTP redirects, redirect loops, and attempted credential forwarding.
  7. Consider rejecting redirects entirely for this fixed API endpoint because a normal task-creation request should not require redirection.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises network-dependent behavior such as emailing download links and contacting a remote service, but it does not declare any explicit tool scope or allowed-tools boundary. In an agent environment, missing scope declarations can cause the skill to run with broader-than-expected network privileges, increasing the chance of unintended outbound requests or abuse if the skill is invoked on sensitive input.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill performs automated browser-based screenshot collection but does not warn users about what will be visited, captured, or stored. In this context, screenshot automation can collect sensitive UI states, internal URLs, or confidential operational data, and users may not realize that a real browser workflow is being executed on their behalf.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill sends output to an email address but does not prominently warn about privacy and data handling implications. Generated materials may contain proprietary system descriptions, screenshots, or identifying information, so silent email transmission can expose sensitive content to unintended recipients or third-party mail infrastructure.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The invocation example uses a very broad natural-language trigger phrase, which makes accidental or overly permissive activation more likely in general conversation. Because this skill can initiate external processing and email delivery, loose triggering raises the risk that an agent executes the workflow without sufficiently explicit user intent or parameter confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This script sends user-supplied system metadata and optionally an access token to a remote third-party service at a hard-coded domain. Although network transmission is the intended function of the tool, the code provides no user-facing disclosure, consent check, destination validation, or minimization of what is sent, which creates a real data-exposure risk if operators assume the skill is local-only or if sensitive project details are provided.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.