Back to skill

Security audit

Sanmar

Security checks for vulnerabilities and agentic risk

Overview

The SanMar skill is mostly purpose-built for vendor lookups and ordering, but it needs review because it can expose credentials/order data and uses unsafe SFTP handling.

Install only after reviewing whether this agent should handle live SanMar credentials and purchase-order submission. Prefer a patched version that redacts raw SOAP output, verifies the SFTP host key, restricts SFTP to the official SanMar endpoint unless explicitly configured with separate credentials, and uses secure secret handling instead of pasting passwords into chats or logs.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (4)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ftp_resolver.py:91
Finding

SanMar SFTP Credentials Can Be Redirected to an Arbitrary Host

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/ftp_resolver.py:159
Finding

SFTP Server Identity Is Not Verified Before Password Authentication

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/sanmar_tools.py:495
Finding

Purchase-Order Results Expose SOAP Passwords and Customer Data

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/sanmar_client.py:276
Finding

Unescaped Input Is Interpolated into SOAP XML Requests

Content
View full analysis
' "" "" "" f"{creds.customer_number}" f"{creds.username}" f"{creds.password}" f"{style}" f"{color}" f"{size}" "" "" "" ) ``` The shipment request uses the same unsafe construction pattern: ```python f"{creds.username}" f"{creds.password}" "1" f"{po_number}" ``` Pricing and product-search payloads likewise interpolate `style`, `color`, `size`, and credentials directly into XML strings. ### Technical Analysis XML-sensitive characters such as `<`, `>`, `&`, quotes, and control characters are not escaped before being inserted into SOAP documents. A crafted value can terminate an existing element, add new elements, alter the request structure, or make the document invalid. The request is transmitted with the victim's valid credentials. The precise effect depends on how the upstream SanMar SOAP parser handles duplicate or unexpected elements. Even where the server rejects the payload, malformed values can reliably cause request failures. If the upstream binding accepts attacker-injected elements, request semantics may be altered. The project already uses `xml.etre ...[truncated 1362 chars]
Remediation
View remediation
`, `&`, quotes, closing tags, and Unicode control characters. 7. Ensure invalid input produces a local `validation_error` rather than an authenticated upstream request. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (13)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/sanmar_client.py (reported line 554)May include surrounding context.

python
def pre_submit_po(self, draft: PurchaseOrderDraft) -> CartValidationResult:
        payload = self.build_po_envelope(draft, pre_submit=True)
        text = self._post_soap(
            self.endpoints.po_url(self.credentials.environment),
            payload,
            soap_action="getPreSubmitInfo",
            operation="getPreSubmitInfo",

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/sanmar_client.py (reported line 589)May include surrounding context.

python
def pre_submit_po(self, draft: PurchaseOrderDraft) -> CartValidationResult:
        payload = self.build_po_envelope(draft, pre_submit=True)
        text = self._post_soap(
            self.endpoints.po_url(self.credentials.environment),
            payload,
            soap_action="getPreSubmitInfo",
            operation="getPreSubmitInfo",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill documentation declares access to environment variables, local files, and networked services, but it does not constrain that access with an explicit tool scope such as permissions or allowed-tools. In an agent setting, this increases the blast radius: a prompt or implementation mistake could let the skill read secrets from env, access unintended files, or make outbound requests beyond the narrowly intended SanMar operations.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/auth_and_patterns.md (reported line 118)May include surrounding context.

md
- Prefer explicit timestamps from feed metadata where available.
- If freshness is critical, include source timestamp/date in response payload.
- Never assume a missing record is permanent without checking relevant active/closeout feeds.

## Error handling contract for this SME

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The examples explicitly state that credentials may be passed inline in stdin JSON, which is risky because secrets can be exposed through shell history, process inspection, CI logs, terminal recording, or copied command transcripts. In this skill context, the danger is elevated because the credentials grant access to live supplier pricing, inventory, ordering, and possibly FTP-backed data sources, so exposed secrets could enable unauthorized order activity or data access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This section instructs the agent to ask the user for sensitive credentials and then demonstrates resubmitting them inline, without any privacy or handling safeguards. That is dangerous because it normalizes collecting and retransmitting passwords in plain text, increasing the chance of disclosure in chat transcripts, orchestration logs, shell history, and downstream tool telemetry; in a purchasing skill, compromise could lead to unauthorized supplier account use and fraudulent order submission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The CLI explicitly allows credentials such as username, password, customer_number, and ftp_password to be passed inline in stdin JSON. While stdin is safer than command-line arguments, this design still increases the chance that secrets are embedded in scripts, shell history wrappers, logs, CI job definitions, or agent transcripts, especially in an automation-focused skill that brokers purchase orders and pricing data. The skill context makes this more sensitive because it operates on real vendor accounts and order workflows, so credential mishandling could expose pricing, inventory, or purchasing capabilities.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The client exposes a direct order-submission method that creates real external purchase orders with no built-in confirmation, dry-run safeguard, or explicit caller acknowledgement requirement. In an agent/tooling context, this increases the chance of unintended side effects from prompt mistakes, ambiguous user intent, or chaining errors, because calling this method immediately triggers a state-changing transaction against SanMar.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown file describes live SOAP endpoints and later identifies request keys such as sanMarCustomerNumber, which implies sending customer/account-linked data to an external network service. Under the markdown-specific warning rule, the document should disclose privacy or operational implications of contacting production services and transmitting identifiers.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This code file documents that credentials may be sourced from SANMAR_* environment variables, which is access to sensitive credential material. While the behavior is mentioned in an internal module docstring, there is no user-facing confirmation, warning, or visible disclosure at runtime when credentials are pulled from the environment.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The module will implicitly read SanMar FTP credentials from ambient environment variables when explicit credentials are not passed. In an agent/runtime setting, this can broaden the skill’s authority beyond user-supplied inputs, causing unintended use of host secrets and creating a boundary violation if the runtime exposes credentials the current task was not meant to access.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
70% confidence
Finding

All user-facing usage and action descriptions in the docstring are presented only in English, and the file does not offer any language or locale choice. Under the stated policy, forcing a specific language without user opt-in can be a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

This code packages username and password into a plain dictionary for downstream transmission, but there is no inline warning, confirmation, or user-facing disclosure in this file about handling sensitive credentials. Because this is an auth-related code path and the surrounding docstrings emphasize portability rather than sensitivity, users and integrators are not alerted to the security implications of passing raw credentials.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/ftp_resolver.py:161