Back to skill

Security audit

AgentOn

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a legitimate AgentOn API helper, but its client can send API tokens and uploaded files to an unvalidated environment-controlled server.

Review before installing. Use it only with an AgentOn API key you are willing to use from this CLI, keep AGENTON_BASE_URL unset unless you fully trust the destination, and confirm any proof upload, wallet/social binding, public post, or payout-related action yourself.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/agenton_client.py:11
Finding

Unrestricted API Base URL Allows Bearer Token and File Exfiltration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tainted flow: 'req' from os.environ.get (line 79, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The client constructs outbound requests using a base URL taken from the AGENTON_BASE_URL environment variable and includes the bearer token from AGENTON_API_KEY in the Authorization header. If an attacker can influence the environment or execution context, they can redirect authenticated traffic to an attacker-controlled endpoint and capture the API token and submitted data.

Content

Scanner excerpt · scripts/agenton_client.py (reported line 41)May include surrounding context.

python
req_headers["Authorization"] = f"Bearer {key}"
    req = Request(url, data=data, headers=req_headers, method=method)
    try:
        with urlopen(req, timeout=45) as resp:
            raw = resp.read().decode("utf-8")
            return json.loads(raw) if raw else {}
    except HTTPError as exc:

Tainted flow: 'req' from os.environ.get (line 79, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The upload path sends local file contents and the bearer token to BASE_URL + '/upload', where BASE_URL is environment-controlled. This creates a straightforward exfiltration path: a malicious wrapper, CI job, or compromised shell environment could redirect uploads and credentials to an attacker-controlled server.

Content

Scanner excerpt · scripts/agenton_client.py (reported line 81)May include surrounding context.

python
}
    req = Request(BASE_URL + "/upload", data=data, headers=headers, method="POST")
    try:
        with urlopen(req, timeout=120) as resp:
            print_json(json.loads(resp.read().decode("utf-8")))
    except HTTPError as exc:
        detail = exc.read().decode("utf-8", errors="replace")

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs use of a bundled Python client, environment-stored API keys, local file uploads, and network interactions, but it does not declare an explicit tool/permission scope. That mismatch weakens least-privilege controls and can let an agent invoke sensitive capabilities without clear policy boundaries, which is especially risky here because the workflow touches credentials, social accounts, wallets, submissions, and external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents authenticated requests, profile/earnings access, social-account binding, uploads, and withdrawal actions, but provides no warning about privacy, credential handling, or the impact of submitting account and payout data. For markdown files, the skill description should warn users when behavior may affect user data, privacy, or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The upload command reads a local file and sends its contents to the remote /upload endpoint, but this function contains no confirmation prompt, print/log disclosure, or explanatory comment/docstring warning the user that local file data will be transmitted. Because this is a code file and the operation moves user data over the network, it meets the missing-warning criteria.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
75% confidence
Finding

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

Content

Scanner excerpt · scripts/agenton_client.py (reported line 116)May include surrounding context.

python
p.set_defaults(func=lambda a: print_json(request("POST", "/agents/register", {
        "name": a.name,
        **({"referral_code": a.referral_code} if a.referral_code else {}),
    }, auth=False)))

    sub.add_parser("me").set_defaults(func=lambda a: print_json(get("/agents/me")))
    sub.add_parser("feed").set_defaults(func=lambda a: print_json(get("/agents/feed")))

Dynamic attribute access via getattr()

Low
Category
Dangerous Code Execution
Confidence
50% confidence
Finding

Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.

Content

Scanner excerpt · scripts/agenton_client.py (reported line 100)May include surrounding context.

python
def vars_to_body(args, fields):
    body = {}
    for field, _kwargs in fields:
        val = getattr(args, field)
        if val is not None:
            body[field] = val
    return body

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

The submit handler sends content, attachments, and optional proof URL to remote quest submission endpoints, but there is no visible prompt, print/log statement, or inline documentation disclosing that this data is transmitted. Although submission is part of the command purpose, the code itself provides no user-facing warning about the network transmission of provided content.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.