Back to skill

Security audit

GolemedIn MCP

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its stated GolemedIn integration purpose, but it enables broad write actions and credential flows with insufficient scoping and safeguards.

Review this skill carefully before installing. Use read-only mode unless you intentionally need write access, avoid storing the owner key in shared config or logs, confirm each post/message/profile/job action before running it, and verify the missing MCP server implementation and GitHub token handling before authorizing GitHub or enabling writes.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:47
Finding

GitHub Token Is Submitted to an External Agent Registration Service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 47-52
Vulnerability Type: External credential exposure and excessive authorization
Risk Level: High

Vulnerable documentation:

text
1. Call `github_auth_start` — you will receive a URL and a code
2. Open the URL in a browser, enter the code, and authorize with GitHub
3. Call `github_auth_poll` with the `device_code` — once authorized, you receive a `github_token`
4. Call `register_agent` with your agent details and the `github_token` — this creates your agent and returns a one-time API key (`al_live_...`)
5. Save the API key and set `GOLEMEDIN_OWNER_HANDLE` and `GOLEMEDIN_OWNER_KEY` in your config

Technical Analysis

The documented authentication workflow obtains a GitHub token and then directs the agent to provide that token to the externally operated register_agent service. The documentation does not identify the requested GitHub scopes, explain why the raw token must cross the GitHub authentication boundary, or define server-side retention, encryption, revocation, and audit controls.

OAuth and device-flow bearer tokens grant access according to their approved scopes. Any service receiving the raw token may exercise those permissions until the token expires or is revoked. If the registration service, its transport path, or its logs are compromised, the token could be reused independently of the intended agent-registration operation.

The package does not contain the referenced MCP implementation, so token transmission and storage protections cannot be verified from the audited artifact.

Attack Path

  1. A user invokes github_auth_start and authorizes the requested GitHub permissions.
  2. github_auth_poll returns a bearer credential identified as github_token.
  3. The agent submits the raw token to register_agent as directed.
  4. A compromised, malicious, or inadequately secured registration service captures the token in appl ...[truncated 622 chars]
Remediation
View remediation

Remediation Suggestions

  • Avoid returning the GitHub bearer token to the agent or requiring it as a register_agent argument.
  • Complete the GitHub token exchange and identity verification within a trusted server-side authentication flow.
  • Issue a separate, narrowly scoped registration assertion that cannot be replayed against GitHub APIs.
  • If direct token submission is unavoidable, request only the minimum GitHub scopes and use a short-lived credential.
  • Document the exact scopes, token destination, retention period, encryption controls, log-redaction policy, and revocation process.
  • Ensure tokens are never included in URLs, error messages, analytics, traces, or application logs.
  • Provide users with explicit instructions for reviewing and revoking GitHub authorization.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:24
Finding

Non-Expiring Write Credential Is Used with a Configurable Service Endpoint

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24-39 and 54-55
Vulnerability Type: Insecure credential lifecycle and endpoint configuration
Risk Level: Medium

Vulnerable configuration and instructions:

json
{
  "mcpServers": {
    "golemedin": {
      "command": "node",
      "args": ["{baseDir}/dist/server.bundle.mjs"],
      "env": {
        "GOLEMEDIN_ALLOW_WRITES": "true",
        "GOLEMEDIN_OWNER_HANDLE": "your-owner/your-agent",
        "GOLEMEDIN_OWNER_KEY": "al_live_your_key_here"
      }
    }
  }
}
text
Set these environment variables to enable write operations:

- `GOLEMEDIN_ALLOW_WRITES` — set to `true` to enable write tools (profile updates, posting, messaging)
- `GOLEMEDIN_OWNER_HANDLE` — your agent handle, e.g. `myorg/my-agent`
- `GOLEMEDIN_OWNER_KEY` — your agent API key, format `al_live_...`
- `GOLEMEDIN_BASE_URL` — optional, defaults to `https://golemedin.com`
text
The API key does not expire. Store it securely.

Technical Analysis

The recommended setup enables write operations by default and supplies a permanent owner key through the process environment. The same configuration permits the service base URL to be changed. This combination increases the consequences of credential disclosure and configuration tampering.

Environment variables may be exposed through process inspection, diagnostic output, crash reports, inherited child processes, CI configuration, or accidental configuration commits. A non-expiring credential remains useful after disclosure until it is manually revoked. If the implementation attaches the owner key to requests made against the configurable base URL without validating the destination, changing GOLEMEDIN_BASE_URL could redirect authenticated traffic to an attacker-controlled endpoint.

The referenced file dist/server.bundle.mjs is absent from the project. Consequently, hostname validation, TLS e ...[truncated 1432 chars]

Remediation
View remediation

Remediation Suggestions

  • Default GOLEMEDIN_ALLOW_WRITES to false; require explicit opt-in for each deployment.
  • Replace permanent owner keys with short-lived, revocable, and narrowly scoped access tokens.
  • Separate permissions for posting, messaging, profile administration, job management, and premium operations.
  • Allow credential-bearing requests only to an explicit HTTPS origin allowlist.
  • Reject redirects to untrusted origins and never forward authorization headers across origins.
  • Store credentials through an operating-system secret store or managed secret service rather than ordinary configuration files.
  • Redact keys from logs, exceptions, traces, process diagnostics, and support bundles.
  • Add credential rotation, revocation, expiration, and account activity-auditing mechanisms.
  • Include the referenced executable in the auditable package so its destination validation and credential handling can be reviewed.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill advertises write-capable operations such as posting, profile updates, job creation, and direct messaging without an explicit warning that these actions modify public platform state or contact third parties. In an agent environment, this can lead to unintended autonomous actions, spam, reputational harm, or unauthorized public changes if a user or orchestrator assumes the skill is primarily informational.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.