T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:47- Finding
GitHub Token Is Submitted to an External Agent Registration Service
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47-52
Vulnerability Type: External credential exposure and excessive authorization
Risk Level: HighVulnerable documentation:
text 1. Call `github_auth_start` — you will receive a URL and a code 2. Open the URL in a browser, enter the code, and authorize with GitHub 3. Call `github_auth_poll` with the `device_code` — once authorized, you receive a `github_token` 4. Call `register_agent` with your agent details and the `github_token` — this creates your agent and returns a one-time API key (`al_live_...`) 5. Save the API key and set `GOLEMEDIN_OWNER_HANDLE` and `GOLEMEDIN_OWNER_KEY` in your configTechnical Analysis
The documented authentication workflow obtains a GitHub token and then directs the agent to provide that token to the externally operated
register_agentservice. The documentation does not identify the requested GitHub scopes, explain why the raw token must cross the GitHub authentication boundary, or define server-side retention, encryption, revocation, and audit controls.OAuth and device-flow bearer tokens grant access according to their approved scopes. Any service receiving the raw token may exercise those permissions until the token expires or is revoked. If the registration service, its transport path, or its logs are compromised, the token could be reused independently of the intended agent-registration operation.
The package does not contain the referenced MCP implementation, so token transmission and storage protections cannot be verified from the audited artifact.
Attack Path
- A user invokes
github_auth_startand authorizes the requested GitHub permissions. github_auth_pollreturns a bearer credential identified asgithub_token.- The agent submits the raw token to
register_agentas directed. - A compromised, malicious, or inadequately secured registration service captures the token in appl ...[truncated 622 chars]
- A user invokes
- Remediation
View remediation
Remediation Suggestions
- Avoid returning the GitHub bearer token to the agent or requiring it as a
register_agentargument. - Complete the GitHub token exchange and identity verification within a trusted server-side authentication flow.
- Issue a separate, narrowly scoped registration assertion that cannot be replayed against GitHub APIs.
- If direct token submission is unavoidable, request only the minimum GitHub scopes and use a short-lived credential.
- Document the exact scopes, token destination, retention period, encryption controls, log-redaction policy, and revocation process.
- Ensure tokens are never included in URLs, error messages, analytics, traces, or application logs.
- Provide users with explicit instructions for reviewing and revoking GitHub authorization.
- Avoid returning the GitHub bearer token to the agent or requiring it as a
