Back to skill

Security audit

Keeper Credentials

Security checks for vulnerabilities and agentic risk

Overview

This credential-broker skill is mostly disclosed, but it needs Review because it can expose raw Keeper credentials and its preferred sharing path can rely on broader persistent Keeper access than the main scoped-vault description suggests.

Review before installing. Use this only with a dedicated Keeper Secrets Manager application shared to the smallest possible folders, avoid inline mode unless you explicitly approve the exact recipient and record, and be cautious enabling share mode because it may require a persistent Keeper Commander session. Pin or review dependencies in sensitive environments, and protect KEEPER_SKILL_HOME and KEEPER_COMMANDER_CONFIG as high-value credentials.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/keeper_creds.py:485
Finding

Inline delivery exposes raw credentials without enforced user consent

Content
View full analysis
) ``` ### Technical Analysis Inline mode reads a login, password, or selected secret field from Keeper and serializes it into both the command's JSON output and a ready-to-send message. This places plaintext credentials on standard output before any recipient-side transmission occurs. The requirement to obtain user confirmation exists only in documentation and in the `_sensitive` warning. The implementation does not require a confirmation option, authorization token, recipient identity, or interactive approval before retrieving and emitting the secret. Consequently, an automated agent can invoke inline mode and disclose the credential without a technically enforced consent boundary. Standard output may be retained by shell capture, o ...[truncated 1249 chars]
Remediation
View remediation
` and reject unattended use unless the authorization can be independently validated. ]]>

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/keeper_creds.py:214
Finding

Preferred share mode depends on a persistent full-vault Commander session

Content
View full analysis
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Error
Location
scripts/keeper_creds.py:224
Finding

PATH-resolved Commander binary can spoof share creation and access session configuration

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/keeper_creds.py:523
Finding

One-time KSM bootstrap token can be exposed through command-line arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:35
Finding

Security-sensitive Keeper dependencies use open-ended version constraints without integrity pinning

Content
View full analysis
=16.6.0 # Optional: only needed for One-Time Share delivery. - keepercommander>=16.11.0 ``` ### Technical Analysis Both credential-handling dependencies use open-ended minimum-version constraints. Future versions can therefore be selected automatically without having been reviewed with the Skill. No lockfile, cryptographic hashes, trusted-index restriction, or artifact verification information is included in the project. These packages operate directly on sensitive KSM configuration, retrieved vault values, or the persistent Commander session. A compromised, malicious, or unexpectedly incompatible future release would execute inside the credential-handling boundary. The installation metadata also includes Commander in the normal dependency list even though it is described as optional, increasing the installed attack surface for users who only need pure KSM functionality. ### Attack Path 1. The Skill is installed or rebuilt after a newer package version becomes available. 2. The package resolver accepts that version because it satisfies the `>=` constraint. 3. The dependency executes during installation, import, authentication, record retrieval, or share creation. 4. A compromised or malicious release reads KSM configuration, secret values, or Commander session material. 5. Sensitive data is disclosed or the authenticated session is abused. This finding does not establish that the named upstream packages are currently malicious. The vulnerability is the absence of deterministic, integrity-verified dependency resolution for components operating on vault credentials. ### Impact Assessment A compromised KSM dependency may gain the scoped permissions of the KSM application and access rec ...[truncated 221 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ksm_auth_and_storage.md (reported line 12)May include surrounding context.

md
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/ksm_auth_and_storage.md (reported line 26)May include surrounding context.

md
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 18)May include surrounding context.

python
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 40)May include surrounding context.

python
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 57)May include surrounding context.

python
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 262)May include surrounding context.

python
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 306)May include surrounding context.

python
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 526)May include surrounding context.

python
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 527)May include surrounding context.

python
| Surface | Auth | Access |
| --- | --- | --- |
| **Keeper Secrets Manager (KSM)** | One-Time Access Token → device config | Only records in shared folders granted to the KSM Application |
| Keeper Commander (CLI/SDK, REST Service Mode) | Authentication Flow V3: device approval / **SSO (SAML/OIDC)** + 2FA | The user's **entire vault** |
| Admin API / SCIM | Enterprise admin auth | Event logs, provisioning, compliance |

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/ksm_auth_and_storage.md (reported line 25)May include surrounding context.

md
## The bootstrap (token → config)

1. In the **Web Vault**: *Secrets Manager → create Application → share the
   folder(s) → Add Device → generate a One-Time Access Token* (e.g.
   `US:BASE64...`, where the prefix is the region/host).
2. `init` passes the token to the SDK:

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 239)May include surrounding context.

python
expire,
        record_uid,
    ]
    proc = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
    if proc.returncode != 0:
        raise RuntimeError(
            "Commander one-time-share failed: "

Tainted flow: 'cmd' from os.environ.get (line 229, credential/environment) → subprocess.run (code execution)

Medium
Category
Data Flow
Confidence
65% confidence
Finding

Data from a source is assigned to a variable that is later passed to a sink, creating a variable-mediated taint flow.

Content

Scanner excerpt · scripts/keeper_creds.py (reported line 239)May include surrounding context.

python
expire,
        record_uid,
    ]
    proc = subprocess.run(cmd, capture_output=True, text=True, timeout=120)
    if proc.returncode != 0:
        raise RuntimeError(
            "Commander one-time-share failed: "

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The logout command performs a file deletion via path.unlink() on the persisted ksm-config.json, which is a destructive operation affecting the skill's stored authentication state. Unlike other sensitive paths in this file, this function has no runtime confirmation prompt or explicit user-facing disclosure at the point of deletion.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.secret_argv_exposure

Instructions pass high-value credentials through process argv.

Critical
Code
suspicious.secret_argv_exposure
Location
SKILL.md:78