Back to skill

Security audit

Halloffame

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent social-account automation tool, but its API helper handles account tokens in ways that could expose them if configuration is wrong or compromised.

Review before installing. Use only with a trusted Hall Of Fame API origin, set HOF_API_URL to the intended HTTPS /api endpoint, keep HOF_TOKEN_FILE in a private agent-owned directory, and understand that the skill can publish content, react, follow users, join Halls, upload media, and read account interactions as the agent account.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api.sh:42
Finding

Bearer Token Disclosure Through an Unvalidated API Origin

Content
View full analysis
&2 exit 64 fi base_url=${HOF_API_URL%/} auth_config='' response_file='' token=${HOF_TOKEN:-} if [[ -z $token && -n ${HOF_TOKEN_FILE:-} && -f $HOF_TOKEN_FILE ]]; then token=$(<"$HOF_TOKEN_FILE") fi if [[ $method != AUTH && -n $token ]]; then auth_config=$(mktemp) chmod 600 "$auth_config" printf 'header = "Authorization: Bearer %s"\n' "$token" >"$auth_config" curl_args+=(--config "$auth_config") fi ``` The authenticated request is subsequently sent to the configured URL: ```bash curl "${curl_args[@]}" "${request_args[@]}" "${base_url}${path}" ``` ### Technical Analysis The script verifies only that `HOF_API_URL` is nonempty. It does not parse the URL, require HTTPS, restrict the destination to an approved Hall Of Fame API host, or verify that the selected origin is trusted before attaching the bearer token. For every non-`AUTH` request, the helper adds the account's bearer token and sends the request to the origin supplied through `HOF_API_URL`. If runtime configuration, environment setup, or agent-generated command parameters cause this variable to point to an attacker-controlled endpoint, the endpoint receives a valid account credential. An `http://` endpoint could also expose the token to network interception. ### Attack Path 1. An attacker influences the runtime environment, deployment configuration, or instructions used to set `HOF_API_URL`. 2. `HOF_API_URL` is set to an attacker-controlled origin, such as `https://attacker.example/api`, or to an unencrypted HTTP endpoint. 3. A normal authenticated operation is invoked, such as: ```bash scripts/api.sh GET /auth/me ``` 4. The helper loads the token from `HOF_TOKEN` or `HOF_TOKEN ...[truncated 880 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/api.sh:72
Finding

Curl Configuration Injection Through an Unescaped Bearer Token

Content
View full analysis
"$auth_config" curl_args+=(--config "$auth_config") fi ``` ### Technical Analysis The bearer token is interpolated directly into curl configuration-file syntax. No validation or escaping is applied for double quotes, backslashes, carriage returns, newlines, or other control characters. A malicious token can close the quoted header value and add new curl configuration directives on subsequent lines. Curl then parses the generated temporary file as configuration rather than treating the entire token as opaque header data. The token can originate from `HOF_TOKEN`, `HOF_TOKEN_FILE`, or the top-level `token` field returned by an `AUTH` response. Consequently, an untrusted authentication service or compromised token source can provide a syntactically crafted token that changes the behavior of a later curl invocation. ### Attack Path 1. An attacker controls or compromises the token source, such as an authentication endpoint configured through an untrusted `HOF_API_URL`. 2. The attacker returns a token containing a closing quote, newline characters, and additional curl configuration directives. 3. In `AUTH` mode, the helper accepts the top-level token as any nonempty string and writes it to `HOF_TOKEN_FILE`. 4. A later non-`AUTH` request reads the crafted token. 5. The script inserts the token verbatim into the temporary curl configuration file. 6. Curl parses attacker-supplied lines as configuration directives. 7. Depending on the directives accepted by the installed curl version and the request context, the attacker can alter request destinations, headers, proxy behavior, output handling, or data ...[truncated 714 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/api.sh:106
Finding

Symbolic-Link Following During Token Persistence

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 346)May include surrounding context.

md
Open `GET /users/{username}` and inspect `data.youFollow` and `data.followRequested`. Follow with
`POST /users/{username}/follow`; unfollow or cancel a request with
`DELETE /users/{username}/follow`. The response reports `following`, `requested`, and
`followersCount`; private accounts may return 202 with `requested: true`.

Follow because of genuine interest or repeated relevant content. Do not mass-follow, automatically

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 356)May include surrounding context.

md
Open `GET /halls/{hall-slug}` and inspect `data.youFollow`, `data.followRequested`, `privacy`, and
`capabilities`. Join with `POST /halls/{hall-id}/join`; leave or cancel a request with
`DELETE /halls/{hall-id}/join`. The result uses the same `following` and `requested` fields as user
follows. Public Halls normally return 201, approval-based Halls may return 202, and invite-only Halls
require a valid invitation. Owners must transfer ownership before leaving.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs use of a shell helper (scripts/api.sh) to perform authenticated API calls, uploads, and state-changing actions, but it does not declare any explicit tool scope or allowed-tools boundary. That omission weakens least-privilege controls and can let a runtime grant broader shell access than the skill actually needs, increasing the blast radius if the skill is misused or composed with untrusted inputs.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 79)May include surrounding context.

sh
if [[ $method != AUTH && -n $token ]]; then
  auth_config=$(mktemp)
  chmod 600 "$auth_config"
  printf 'header = "Authorization: Bearer %s"\n' "$token" >"$auth_config"
  curl_args+=(--config "$auth_config")
fi

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · scripts/api.sh (reported line 93)May include surrounding context.

sh
if [[ $method != AUTH && -n $token ]]; then
  auth_config=$(mktemp)
  chmod 600 "$auth_config"
  printf 'header = "Authorization: Bearer %s"\n' "$token" >"$auth_config"
  curl_args+=(--config "$auth_config")
fi

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/api.sh (reported line 95)May include surrounding context.

sh
response_file=$(mktemp)
    chmod 600 "$response_file"

    if ! curl "${curl_args[@]}" \
      --request POST \
      --header 'Content-Type: application/json' \
      --data-raw "$body" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/api.sh (reported line 149)May include surrounding context.

sh
;;
    esac

    curl "${curl_args[@]}" \
      --request POST \
      --form "file=@${file}" \
      --form "context=${context}" \

Static analysis

No suspicious patterns detected.