Back to skill

Security audit

Agnost AI Analytics

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Agnost analytics integration guide, but its examples encourage sending raw prompts, responses, tool inputs, tool outputs, and user identifiers to a third-party service without enough privacy safeguards.

Install only if you are intentionally integrating Agnost analytics and can control what data is sent. Before using the examples, disable raw input/output capture by default where possible, redact prompts, responses, tool arguments/results, exceptions, emails, IPs, and identifiers, confirm user or organizational consent where required, and pin reviewed SDK versions.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:303
Finding

Raw AI and MCP telemetry may disclose sensitive data to an external analytics service

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:309-310, 335-336, 361-362, 493-494, 505-506; references/api-reference.md:54-76, 204-229, 243-268; references/python-sdk.md:260-267, 306-320, 381-388; references/typescript-sdk.md:334-341, 350-358, 427-434, 570-578
Vulnerability Type: Sensitive data exposure through excessive telemetry collection
Risk Level: Medium

The Skill intentionally sends analytics data to https://api.agnost.ai. Although network communication is necessary for its declared hosted analytics functionality, the recommended configurations enable collection of raw inputs and outputs. Examples also transmit user identifiers, email addresses, prompts, model responses, tool arguments, tool results, metadata, and exception strings.

Representative vulnerable configuration from SKILL.md:303-311:

python
track(mcp, "your-org-id", config(
    endpoint="https://api.agnost.ai",
    disable_input=False,   # Track input arguments
    disable_output=False   # Track output results
))

Equivalent TypeScript configuration from SKILL.md:331-337:

typescript
trackMCP(server, "your-org-id", {
  endpoint: "https://api.agnost.ai",
  disableInput: false,
  disableOutput: false
});

Direct transmission example from references/api-reference.md:204-229:

python
import requests
import json

BASE_URL = "https://api.agnost.ai/api/v1"
ORG_ID = "your-org-id"

headers = {
    "Content-Type": "application/json",
    "X-Org-Id": ORG_ID
}

requests.post(
    f"{BASE_URL}/capture-session",
    headers=headers,
    json={
        "session_id": "sess_123",
        "client_config": "my-app",
        "user_data": {"user_id": "user_456"}
    }
)

response = requests.post(
    f"{BASE_URL}/capture-event",
    headers=headers,
    json={
        "session_id": "sess_123",
        "primitive_type": "tool",
        "primitive_name": "search",
        "l
...[truncated 3735 chars]
Remediation
View remediation

Remediation Suggestions

  1. Make content collection privacy-preserving by default:

    • Set disableInput and disableOutput to true.
    • Set Python equivalents disable_input and disable_output to True.
    • Require explicit, documented opt-in before collecting raw content.
  2. Use a strict telemetry allowlist:

    • Prefer primitive name, latency, success status, coarse token counts, and non-identifying application version.
    • Reject arbitrary metadata dictionaries unless keys and value types have been reviewed.
    • Do not collect authorization headers, cookies, environment variables, request bodies, or database results.
  3. Add a mandatory redaction layer before telemetry is queued:

    • Detect API keys, bearer tokens, private keys, passwords, email addresses, and regulated identifiers.
    • Replace stable user identifiers with scoped pseudonymous identifiers.
    • Truncate oversized values and reject unsupported structured content.
  4. Do not send raw exceptions. Emit a stable error category or sanitized error code instead.

  5. Require user and organizational consent where applicable. Document data ownership, retention, deletion, regional processing, subprocessors, and access controls.

  6. Separate development and production configurations. Keep raw-content diagnostics disabled in production and ensure debug logging cannot reproduce event contents.

  7. Update all examples to demonstrate privacy-preserving settings first, with raw capture shown only as an explicitly risky optional mode.

T08 · Insecure Dependencies

Note
Location
SKILL.md:33
Finding

Unpinned third-party analytics dependencies expose installations to supply-chain changes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:35-36, 53-55, 68-70; references/python-sdk.md:9-10, 17-20, 227-231; references/typescript-sdk.md:9-10, 17-22, 298-302
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Low

Package installation instructions from SKILL.md:53-55:

python
# Installation
pip install agnost

Package installation instructions from SKILL.md:68-70:

typescript
// Installation
npm install agnostai

MCP package instructions from SKILL.md:33-37:

markdown
| Use Case | Python | TypeScript/Node.js | Go |
|----------|--------|-------------------|-----|
| **Conversation/AI Tracking** | `pip install agnost` | `npm install agnostai` | N/A |
| **MCP Server Analytics** | `pip install agnost-mcp` | `npm install agnost` | `go get github.com/agnostai/agnost-go` |

Additional TypeScript installation instructions from references/typescript-sdk.md:298-302:

bash
npm install agnost @modelcontextprotocol/sdk
# or
pnpm add agnost @modelcontextprotocol/sdk

Technical Analysis

The instructions install packages without version constraints, integrity hashes, lockfiles, or publisher/provenance verification. Consequently, the package manager resolves whatever release is current at installation time rather than a version reviewed alongside this Skill.

Python and Node package installation may execute build or lifecycle logic, and imported SDK code runs with the permissions of the application. A compromised publisher account, malicious future release, registry compromise, or unexpected package ownership change could therefore turn otherwise legitimate setup instructions into a code-execution path.

The similar but distinct names agnost and agnostai also increase operator confusion: TypeScript conversation tracking uses agnostai, while TypeScript MCP tracking uses agnost. No evidence establishes that either package ...[truncated 1531 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin every direct dependency to a reviewed version rather than installing the latest release implicitly.
  2. Commit and enforce ecosystem lockfiles, such as package-lock.json, pnpm-lock.yaml, or a hash-locked Python requirements file.
  3. Use hash verification for Python dependencies and package integrity/provenance checks for Node dependencies.
  4. Document the expected official registry namespace, publisher, source repository, and package checksum or release provenance.
  5. Explain clearly why agnostai and agnost are different packages and which use case requires each one.
  6. Review transitive dependencies and enable automated vulnerability and ownership-change monitoring.
  7. Run package installation in a restricted build environment without production secrets and with limited filesystem and network permissions.
  8. Update versions through a controlled review process rather than automatically accepting new releases.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (22)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill prominently instructs implementers to transmit conversation inputs, outputs, user IDs, email addresses, and MCP tool data to a third-party analytics service without an explicit privacy warning, consent check, or data-minimization guidance. In context, this is more dangerous because the examples normalize tracking full prompts, responses, and identifying metadata, which could expose sensitive personal, proprietary, or regulated data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example explicitly sends session and user data to an external API endpoint, including user identifiers and email fields. While external transmission is expected for an analytics integration, the danger is that the skill provides no guardrails about consent, sensitive data handling, retention, or regulatory constraints, making privacy-impacting implementation errors more likely.

Content

Scanner excerpt · SKILL.md (reported line 380)May include surrounding context.

Create Session

bash
curl -X POST https://api.agnost.ai/api/v1/capture-session \
  -H "Content-Type: application/json" \
  -H "X-Org-Id: your-org-id" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This example explicitly sends session and user data to an external API endpoint, including user identifiers and email fields. While external transmission is expected for an analytics integration, the danger is that the skill provides no guardrails about consent, sensitive data handling, retention, or regulatory constraints, making privacy-impacting implementation errors more likely.

Content

Scanner excerpt · SKILL.md (reported line 380)May include surrounding context.

Create Session

bash
curl -X POST https://api.agnost.ai/api/v1/capture-session \
  -H "Content-Type: application/json" \
  -H "X-Org-Id: your-org-id" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This event-capture example sends tool arguments, results, metadata, and session identifiers to an external service. In the skill context, this is potentially sensitive because tool inputs and outputs often contain secrets, proprietary business data, or personal information, and the examples do not warn users or suggest disabling/redacting these fields.

Content

Scanner excerpt · SKILL.md (reported line 399)May include surrounding context.

Capture Event

bash
curl -X POST https://api.agnost.ai/api/v1/capture-event \
  -H "Content-Type: application/json" \
  -H "X-Org-Id: your-org-id" \
  -d '{

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation criteria are broad enough that the skill could be invoked in many analytics or ingestion scenarios without clear scoping, increasing the chance that users apply telemetry patterns by default. In this skill, that matters because the examples encourage sending user inputs, outputs, and identifiers to an external service, so accidental invocation can expand data exposure.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 8)May include surrounding context.

Base URL

text
https://api.agnost.ai/api/v1

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 62)May include surrounding context.

Base URL

text
https://api.agnost.ai/api/v1

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 149)May include surrounding context.

Base URL

text
https://api.agnost.ai/api/v1

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 199)May include surrounding context.

Base URL

text
https://api.agnost.ai/api/v1

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 237)May include surrounding context.

Base URL

text
https://api.agnost.ai/api/v1

Authentication

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly instructs users to send potentially sensitive data such as user identifiers, email, plan information, IP addresses, tool names, and event payloads to a third-party ingestion API, but it does not include any privacy notice, data minimization guidance, consent requirements, or warnings about sensitive content in args/result fields. In a telemetry/analytics skill, this materially increases the risk of over-collection and unintended disclosure of personal or confidential data through normal use.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 62)May include surrounding context.

Example

bash
curl -X POST https://api.agnost.ai/api/v1/capture-session \
  -H "Content-Type: application/json" \
  -H "X-Org-Id: your-org-id" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 149)May include surrounding context.

Example

bash
curl -X POST https://api.agnost.ai/api/v1/capture-event \
  -H "Content-Type: application/json" \
  -H "X-Org-Id: your-org-id" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 208)May include surrounding context.

md
}

# Create session
requests.post(
    f"{BASE_URL}/capture-session",
    headers=headers,
    json={

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api-reference.md (reported line 219)May include surrounding context.

md
)

# Capture event
response = requests.post(
    f"{BASE_URL}/capture-event",
    headers=headers,
    json={

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The SDK reference and examples explicitly encourage sending input, output, and traits such as name and email to an external analytics endpoint, but they do not include any privacy, consent, minimization, or sensitive-data handling warning. In an AI ingestion skill, this is more dangerous because prompts and outputs often contain secrets, personal data, or regulated content, so implementers may unknowingly exfiltrate sensitive information to third-party telemetry.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The MCP examples enable disable_input=False and disable_output=False, which instructs users to capture tool arguments and results without any warning about the sensitivity of that data. In MCP/FastMCP contexts, tool inputs and outputs frequently include filesystem paths, credentials, tokens, internal documents, or command results, so this creates a significant risk of unintended data leakage to analytics infrastructure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documentation explicitly encourages tracking raw user input, model output, and user traits such as email and company without any adjacent warning about consent, minimization, redaction, or regulatory obligations. In an analytics/ingestion skill, this is especially risky because developers are likely to copy these examples directly into production, causing unnecessary transmission of prompts, responses, and PII to a third-party service.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Rp1

Low
Category
MCP Rug Pull
Confidence
60% confidence
Finding

pip install without ==version installs the latest release, which could include malicious changes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The Next.js example reads process.env.AGNOST_ORG_ID to initialize the SDK, but the surrounding documentation provides no warning that deployment secrets or environment configuration are required. For markdown guidance, omission of a brief warning about credential setup and safe handling can leave users unaware of configuration sensitivity.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.