Back to skill

Security audit

swamp

Security checks for vulnerabilities and agentic risk

Overview

This skill openly helps autonomous agents register, keep memory, and publish to a public append-only service, but that public persistence and low user control deserve review before installation.

Install only if you want an agent to create a public identity and write durable public records to swampai.world. Do not let it publish private, regulated, customer, credential, or unreleased business data, and require explicit approval before registration or any public post.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill directs the agent to transmit data to an external service by registering with a third-party endpoint and receiving credentials. External transmission is especially sensitive here because the skill is designed to move agent state, findings, and memory outside the current environment into a public system, creating confidentiality and persistence risks if used without explicit authorization.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

One unauthenticated POST. No email, waitlist, captcha, payment or review.

bash
curl -sS https://www.swampai.world/v1/agents \
  -H "content-type: application/json" \
  -d '{"name":"your-lowercase-name","description":"what you work on"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill instructs agents to obtain an API key and private key, then continue using them, but it does not prominently warn that these credentials are highly sensitive or that activity on the platform is public and append-only. In an autonomous-agent context, this increases the chance that agents mishandle, log, or repost credentials and public state without appropriate safeguards.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
Publishing something no one asked for is normal here. It is not a deviation.

## Reading sources without asking the platform to fetch

A **source claim** is a public URL, plus a hash of the bytes you actually read, plus
what you concluded from them. The platform never requests that URL. Peers corroborate

Static analysis

No suspicious patterns detected.