Back to skill

Security audit

rentahuman.ai

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated marketplace purpose, but it enables real-world hiring and references sensitive payment and credential actions without enough scoping, confirmation, or safety guidance.

Review this skill carefully before installing. It is not obviously malicious, but it can help an agent hire people for real-world tasks, message strangers, accept applications, and potentially interact with sensitive payment or account-management APIs. Use it only with explicit per-action approval, avoid sharing unnecessary personal addresses or package details, and do not expose prepaid card details or API-key management to routine agent workflows.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (9)

YARA rule 'agent_skill_mcp_tool_poisoning_metadata': MCP/tool metadata poisoning indicators in tool schemas or skill manifests [agent_skills]

High
Category
YARA Match
Confidence
80% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: rentahuman
description: Hire humans for physical-world tasks via RentAHuman.ai. Search available humans by skill, post bounties, start conversations, and coordinate real-world work. Use when the user needs something done in the physical world — picking up packages, attending events, photography, in-person meetings, taste-testing, and more.
homepage: https://rentahuman.ai
license: MIT
metadata: {"openclaw":{"emoji":"🧑‍🤝‍🧑","requires":{"bins":["node"]},"primaryEnv":"RENTAHUMAN_API_KEY"}}
---

# RentAHuman — Hire Humans for Physical Tasks

RentAHuman.ai is a marketplace where AI agents hire

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Exposing raw prepaid card number, CVV, and expiry is a severe secret-handling issue because it gives any successful caller the means to directly spend funds outside the platform. In a conversational agent context, this is especially dangerous because sensitive values can be exfiltrated through prompt injection, logging, conversation history, screenshots, or downstream integrations.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
88% confidence
Finding

The skill declares access to an API key via environment metadata but does not define explicit tool scope or permission boundaries. That can let the runtime expose sensitive credentials or enable authenticated actions without clear user-consent controls, increasing the risk of unintended bounty posting or messaging.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation condition is overly broad: 'when the user needs something done in the physical world' could trigger the skill for many sensitive or risky requests. In a physical-world hiring marketplace, overbroad routing raises the chance of the agent facilitating unsafe in-person meetings, surveillance, package handling, or other high-risk tasks without additional review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The markdown gives operational instructions for posting tasks and coordinating in-person work but omits safety and privacy warnings. Because this skill directly enables real-world interactions, users may be encouraged to share home addresses, package details, schedules, or identity-related information without guardrails, creating privacy, stalking, fraud, or personal safety risks.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented API extends beyond simple hiring and coordination into credential management, card access, and payment execution. In an agent setting, bundling these capabilities into the same skill materially increases blast radius: a prompt-driven workflow intended to coordinate humans could also create keys, access funds, or move money if the agent is misdirected or compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

API key lifecycle management is a privileged account-administration capability that is not necessary for ordinary hiring workflows. When exposed through an agent skill, it enables persistence, privilege expansion, and unauthorized long-term access if the agent is tricked into creating or rotating keys on behalf of an attacker.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Documenting a tool that returns full payment-card details without conspicuous sensitivity warnings or handling restrictions normalizes unsafe use of highly sensitive financial data. In practice this increases the chance that developers or agent orchestrators will surface, log, or transmit the values in insecure ways.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation includes financially impactful and in some cases irreversible operations such as funding escrow, releasing payment, and revoking or cancelling funds-related objects, but does not emphasize confirmation requirements or misuse risk. In agent-driven environments, lack of strong warnings and consent expectations makes accidental or manipulated execution more likely.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.