T09 · Insecure Skill Coding Practices
- Location
scripts/agenton_client.py:11- Finding
Unrestricted API Base URL Allows Bearer Token and File Exfiltration
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a legitimate AgentOn API helper, but its client can send API tokens and uploaded files to an unvalidated environment-controlled server.
Review before installing. Use it only with an AgentOn API key you are willing to use from this CLI, keep AGENTON_BASE_URL unset unless you fully trust the destination, and confirm any proof upload, wallet/social binding, public post, or payout-related action yourself.
scripts/agenton_client.py:11Unrestricted API Base URL Allows Bearer Token and File Exfiltration
The client constructs outbound requests using a base URL taken from the AGENTON_BASE_URL environment variable and includes the bearer token from AGENTON_API_KEY in the Authorization header. If an attacker can influence the environment or execution context, they can redirect authenticated traffic to an attacker-controlled endpoint and capture the API token and submitted data.
req_headers["Authorization"] = f"Bearer {key}"
req = Request(url, data=data, headers=req_headers, method=method)
try:
with urlopen(req, timeout=45) as resp:
raw = resp.read().decode("utf-8")
return json.loads(raw) if raw else {}
except HTTPError as exc:
The upload path sends local file contents and the bearer token to BASE_URL + '/upload', where BASE_URL is environment-controlled. This creates a straightforward exfiltration path: a malicious wrapper, CI job, or compromised shell environment could redirect uploads and credentials to an attacker-controlled server.
}
req = Request(BASE_URL + "/upload", data=data, headers=headers, method="POST")
try:
with urlopen(req, timeout=120) as resp:
print_json(json.loads(resp.read().decode("utf-8")))
except HTTPError as exc:
detail = exc.read().decode("utf-8", errors="replace")
The skill instructs use of a bundled Python client, environment-stored API keys, local file uploads, and network interactions, but it does not declare an explicit tool/permission scope. That mismatch weakens least-privilege controls and can let an agent invoke sensitive capabilities without clear policy boundaries, which is especially risky here because the workflow touches credentials, social accounts, wallets, submissions, and external services.
This markdown file documents authenticated requests, profile/earnings access, social-account binding, uploads, and withdrawal actions, but provides no warning about privacy, credential handling, or the impact of submitting account and payout data. For markdown files, the skill description should warn users when behavior may affect user data, privacy, or system integrity.
The upload command reads a local file and sends its contents to the remote /upload endpoint, but this function contains no confirmation prompt, print/log disclosure, or explanatory comment/docstring warning the user that local file data will be transmitted. Because this is a code file and the operation moves user data over the network, it meets the missing-warning criteria.
Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.
p.set_defaults(func=lambda a: print_json(request("POST", "/agents/register", {
"name": a.name,
**({"referral_code": a.referral_code} if a.referral_code else {}),
}, auth=False)))
sub.add_parser("me").set_defaults(func=lambda a: print_json(get("/agents/me")))
sub.add_parser("feed").set_defaults(func=lambda a: print_json(get("/agents/feed")))
Dynamic getattr() with a non-literal attribute name can access arbitrary object attributes, potentially bypassing access controls.
def vars_to_body(args, fields):
body = {}
for field, _kwargs in fields:
val = getattr(args, field)
if val is not None:
body[field] = val
return body
The submit handler sends content, attachments, and optional proof URL to remote quest submission endpoints, but there is no visible prompt, print/log statement, or inline documentation disclosing that this data is transmitted. Although submission is part of the command purpose, the code itself provides no user-facing warning about the network transmission of provided content.
No suspicious patterns detected.