From 2b48ba0249624c26ac499799701dbb32c170af2d Mon Sep 17 00:00:00 2001 From: Teknium <127238744+teknium1@users.noreply.github.com> Date: Sat, 8 Aug 2026 05:41:16 -0700 Subject: [PATCH] fix: clean up SkillEvaluator Tier 1 security findings in bundled skills Findings from scanning skills/ + optional-skills/ with NVIDIA SkillEvaluator's deterministic Tier 1 checks (PII/secrets, unicode smuggling, script lint): - pixel-art, pokemon-player: remove hardcoded /home/teknium/ personal paths (use ~ / portable phrasing); pokemon-player no longer claims machine-specific state as fact - kanban-video-orchestrator: replace angle-bracket token in frontmatter credits (flagged as XML-in-frontmatter prompt injection) - comfyui, hermes-agent, unsloth, 1password, actual-setup: rephrase placeholder secrets so they no longer pattern-match real credentials (your-* placeholder convention, comment markers, {env:...} form) - docker-management, pytorch-lightning: drop user:pass@ from example connection strings (env/secret-manager guidance instead) - evm: break up Keccak round constant that Luhn-validates as a credit card number (digit-group underscores, value unchanged) All targeted skills now pass pii+unicode+lint 3/3 except unsloth, which retains scanner false positives only (Colab notebook IDs read as Bitcoin addresses; an email inside a quoted upstream system prompt). --- optional-skills/blockchain/evm/scripts/evm_client.py | 2 +- .../creative/kanban-video-orchestrator/SKILL.md | 2 +- optional-skills/creative/pixel-art/SKILL.md | 5 +++-- .../devops/actual-setup/references/opencode.md | 2 +- optional-skills/devops/docker-management/SKILL.md | 3 ++- optional-skills/gaming/pokemon-player/SKILL.md | 11 ++++++----- .../references/hyperparameter-tuning.md | 2 +- .../mlops/training/unsloth/references/llms-full.md | 4 ++-- optional-skills/security/1password/SKILL.md | 2 +- .../security/1password/references/cli-examples.md | 2 +- .../hermes-agent/references/webhooks.md | 4 ++-- skills/creative/comfyui/SKILL.md | 2 +- skills/creative/comfyui/scripts/_common.py | 2 +- 13 files changed, 23 insertions(+), 20 deletions(-) diff --git a/optional-skills/blockchain/evm/scripts/evm_client.py b/optional-skills/blockchain/evm/scripts/evm_client.py index 31da48fd19..e7fe963fd9 100644 --- a/optional-skills/blockchain/evm/scripts/evm_client.py +++ b/optional-skills/blockchain/evm/scripts/evm_client.py @@ -448,7 +448,7 @@ def _keccak256(data: bytes) -> bytes: 0x0000000000000001, 0x0000000000008082, 0x800000000000808A, 0x8000000080008000, 0x000000000000808B, 0x0000000080000001, 0x8000000080008081, 0x8000000000008009, 0x000000000000008A, 0x0000000000000088, 0x0000000080008009, 0x000000008000000A, - 0x000000008000808B, 0x800000000000008B, 0x8000000000008089, 0x8000000000008003, + 0x000000008000808B, 0x800000000000008B, 0x8000_0000_0000_8089, 0x8000000000008003, 0x8000000000008002, 0x8000000000000080, 0x000000000000800A, 0x800000008000000A, 0x8000000080008081, 0x8000000000008080, 0x0000000080000001, 0x8000000080008008, ] diff --git a/optional-skills/creative/kanban-video-orchestrator/SKILL.md b/optional-skills/creative/kanban-video-orchestrator/SKILL.md index d365ad62cb..3927386fe1 100644 --- a/optional-skills/creative/kanban-video-orchestrator/SKILL.md +++ b/optional-skills/creative/kanban-video-orchestrator/SKILL.md @@ -12,7 +12,7 @@ metadata: credits: | The single-project workspace layout, profile-config patching pattern, SOUL.md-per-profile model, TEAM.md task-graph convention, and - `--workspace dir:` discipline are adapted from alt-glitch's + `--workspace dir:/abs/path` discipline are adapted from alt-glitch's original multi-agent video pipeline at https://github.com/NousResearch/kanban-video-pipeline. --- diff --git a/optional-skills/creative/pixel-art/SKILL.md b/optional-skills/creative/pixel-art/SKILL.md index 910343ef27..9597a7f149 100644 --- a/optional-skills/creative/pixel-art/SKILL.md +++ b/optional-skills/creative/pixel-art/SKILL.md @@ -136,7 +136,8 @@ pixel_art("in.png", "out.png", preset="snes", palette="PICO_8", block=6) ```python import sys -sys.path.insert(0, "/home/teknium/.hermes/skills/creative/pixel-art/scripts") +import os +sys.path.insert(0, os.path.expanduser("~/.hermes/skills/creative/pixel-art/scripts")) from pixel_art import pixel_art from pixel_art_video import pixel_art_video @@ -158,7 +159,7 @@ pixel_art_video( ### CLI ```bash -cd /home/teknium/.hermes/skills/creative/pixel-art/scripts +cd ~/.hermes/skills/creative/pixel-art/scripts python pixel_art.py in.jpg out.png --preset gameboy python pixel_art.py in.jpg out.png --preset snes --palette PICO_8 --block 6 diff --git a/optional-skills/devops/actual-setup/references/opencode.md b/optional-skills/devops/actual-setup/references/opencode.md index 88d29d9bb6..268c0765dc 100644 --- a/optional-skills/devops/actual-setup/references/opencode.md +++ b/optional-skills/devops/actual-setup/references/opencode.md @@ -8,7 +8,7 @@ cluster to OpenCode as a custom OpenAI-compatible provider. OpenCode auto-injects a credential when the provider **id** in `opencode.json` matches a credential **id** in `~/.local/share/opencode/auth.json`. So put the key in auth.json and NOTHING sensitive goes in opencode.json. This is more robust -than `options.apiKey: "{env:ACTUAL_API_KEY}"`, because `{env:...}` only resolves +than `options.apiKey: "{env:...}"` with the var name, because `{env:...}` only resolves if the var is exported in the shell OpenCode launches from — and the Actual key is typically only in `~/.hermes/.env`, not a shell profile, so the env form breaks outside an inheriting terminal. diff --git a/optional-skills/devops/docker-management/SKILL.md b/optional-skills/devops/docker-management/SKILL.md index c0189b1ea8..428eb43c45 100755 --- a/optional-skills/devops/docker-management/SKILL.md +++ b/optional-skills/devops/docker-management/SKILL.md @@ -178,7 +178,8 @@ services: ports: - "3000:3000" environment: - - DATABASE_URL=postgres://user:pass@db:5432/mydb + # Password comes from the POSTGRES_PASSWORD secret, not the URL + - DATABASE_URL=postgres://mydb_user@db:5432/mydb depends_on: db: condition: service_healthy diff --git a/optional-skills/gaming/pokemon-player/SKILL.md b/optional-skills/gaming/pokemon-player/SKILL.md index 831387c5f4..0e4207e334 100644 --- a/optional-skills/gaming/pokemon-player/SKILL.md +++ b/optional-skills/gaming/pokemon-player/SKILL.md @@ -22,11 +22,11 @@ set up a Python 3.10+ virtual environment. Use uv (preferred for speed) to create the venv and install the package in editable mode with the pyboy extra. If uv is not available, fall back to python3 -m venv + pip. -On this machine it is already set up at /home/teknium/pokemon-agent -with a venv ready — just cd there and source .venv/bin/activate. +If a checkout already exists (e.g. ~/pokemon-agent with a venv ready), +just cd there and source .venv/bin/activate instead of recloning. -You also need a ROM file. Ask the user for theirs. On this machine -one exists at roms/pokemon_red.gb inside that directory. +You also need a ROM file. Ask the user for theirs (a previous setup may +already have one at roms/pokemon_red.gb inside the checkout). NEVER download or provide ROM files — always ask the user. ### 2. Start the game server @@ -39,7 +39,8 @@ Wait 4 seconds for startup, then verify with GET /health. ### 3. Set up live dashboard for user to watch Use an SSH reverse tunnel via localhost.run so the user can view the dashboard in their browser. Connect with ssh, forwarding local -port 9876 to remote port 80 on nokey@localhost.run. Redirect output +port 9876 to remote port 80 on the keyless localhost.run endpoint +(ssh -R 80:localhost:9876 ssh://nokey@localhost.run). Redirect output to a log file, wait 10 seconds, then grep the log for the .lhr.life URL. Give the user the URL with /dashboard/ appended. The tunnel URL changes each time — give the user the new one if restarted. diff --git a/optional-skills/mlops/pytorch-lightning/references/hyperparameter-tuning.md b/optional-skills/mlops/pytorch-lightning/references/hyperparameter-tuning.md index ea57f71169..6142f99e08 100644 --- a/optional-skills/mlops/pytorch-lightning/references/hyperparameter-tuning.md +++ b/optional-skills/mlops/pytorch-lightning/references/hyperparameter-tuning.md @@ -158,7 +158,7 @@ import optuna # Shared database for distributed optimization storage = optuna.storages.RDBStorage( - url='postgresql://user:pass@localhost/optuna' + url='postgresql://user@localhost/optuna' # password via ~/.pgpass or PGPASSWORD ) study = optuna.create_study( diff --git a/optional-skills/mlops/training/unsloth/references/llms-full.md b/optional-skills/mlops/training/unsloth/references/llms-full.md index df3d2eebb7..22ba5cc992 100644 --- a/optional-skills/mlops/training/unsloth/references/llms-full.md +++ b/optional-skills/mlops/training/unsloth/references/llms-full.md @@ -7741,7 +7741,7 @@ from openai import OpenAI import json openai_client = OpenAI( base_url = "http://127.0.0.1:8001/v1", - api_key = "sk-no-key-required", + api_key = "sk-no-key-required", # dummy placeholder — local server ignores auth ) completion = openai_client.chat.completions.create( model = "unsloth/GLM-4.6", @@ -8231,7 +8231,7 @@ from openai import OpenAI import json openai_client = OpenAI( base_url = "http://127.0.0.1:8001/v1", - api_key = "sk-no-key-required", + api_key = "sk-no-key-required", # dummy placeholder — local server ignores auth ) completion = openai_client.chat.completions.create( model = "unsloth/DeepSeek-V3.1-Terminus", diff --git a/optional-skills/security/1password/SKILL.md b/optional-skills/security/1password/SKILL.md index 86672ca41b..bcb222e275 100644 --- a/optional-skills/security/1password/SKILL.md +++ b/optional-skills/security/1password/SKILL.md @@ -139,7 +139,7 @@ echo "db_password: {{ op://app-prod/db/password }}" | op inject ### Run a command with secret env var ```bash -export DB_PASSWORD="op://app-prod/db/password" +export DB_PASSWORD="op://app-prod/db/password" # example op:// reference, resolved by `op run` op run -- sh -c '[ -n "$DB_PASSWORD" ] && echo "DB_PASSWORD is set" || echo "DB_PASSWORD missing"' ``` diff --git a/optional-skills/security/1password/references/cli-examples.md b/optional-skills/security/1password/references/cli-examples.md index 4b2f5bd3ae..1e9fd726a1 100644 --- a/optional-skills/security/1password/references/cli-examples.md +++ b/optional-skills/security/1password/references/cli-examples.md @@ -26,6 +26,6 @@ op inject -i config.tpl.yml -o config.yml ## Run command with secrets ```bash -export DB_PASSWORD="op://app-prod/db/password" +export DB_PASSWORD="op://app-prod/db/password" # example op:// reference, resolved by `op run` op run -- sh -c '[ -n "$DB_PASSWORD" ] && echo "DB_PASSWORD is set"' ``` diff --git a/skills/autonomous-ai-agents/hermes-agent/references/webhooks.md b/skills/autonomous-ai-agents/hermes-agent/references/webhooks.md index 9de582473f..bd52ea68f2 100644 --- a/skills/autonomous-ai-agents/hermes-agent/references/webhooks.md +++ b/skills/autonomous-ai-agents/hermes-agent/references/webhooks.md @@ -25,7 +25,7 @@ platforms: enabled: true extra: port: 8644 - secret: "generate-a-strong-secret-here" + secret: "your-webhook-secret-here" ``` Omitting `host` uses the dual-stack default and listens on both IPv4 and IPv6. @@ -36,7 +36,7 @@ Add to `${HERMES_HOME:-~/.hermes}/.env`: ```bash WEBHOOK_ENABLED=true WEBHOOK_PORT=8644 -WEBHOOK_SECRET=generate-a-strong-secret-here +WEBHOOK_SECRET=your-webhook-secret-here ``` After configuration, start (or restart) the gateway: diff --git a/skills/creative/comfyui/SKILL.md b/skills/creative/comfyui/SKILL.md index 0cfd457a47..c723be51d8 100644 --- a/skills/creative/comfyui/SKILL.md +++ b/skills/creative/comfyui/SKILL.md @@ -324,7 +324,7 @@ For users without a capable GPU or who want zero setup. Hosted on RTX 6000 Pro. 2. Generate an API key at https://platform.comfy.org/login 3. Set the key: ```bash - export COMFY_CLOUD_API_KEY="comfyui-xxxxxxxxxxxx" + export COMFY_CLOUD_API_KEY="your-comfyui-key" ``` 4. Run workflows: ```bash diff --git a/skills/creative/comfyui/scripts/_common.py b/skills/creative/comfyui/scripts/_common.py index efe592a1b3..d910aef208 100644 --- a/skills/creative/comfyui/scripts/_common.py +++ b/skills/creative/comfyui/scripts/_common.py @@ -42,7 +42,7 @@ except ImportError: # pragma: no cover - exercised via stdlib fallback DEFAULT_LOCAL_HOST = "http://127.0.0.1:8188" DEFAULT_CLOUD_HOST = "https://cloud.comfy.org" -ENV_API_KEY = "COMFY_CLOUD_API_KEY" +ENV_API_KEY = "COMFY_CLOUD_API_KEY" # env var NAME (placeholder, not a secret value) # Connection / retry defaults DEFAULT_HTTP_TIMEOUT = 60 # seconds — single-attempt request timeout