Back to skill

Security audit

chorus.host

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for publishing websites, but it needs review because it can make local files public and tells the agent to persist a reusable API key without asking first.

Install only if you are comfortable with an agent uploading selected files to chorus.host and potentially making them public. Before publishing, review the exact files, exclude secrets and private data, prefer password protection or short expiry for sensitive previews, and require confirmation before deleting sites or changing access. Do not allow the API key to be saved persistently unless you explicitly want future sessions to reuse it.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (13)

External Script Fetching

High
Category
Supply Chain
Confidence
80% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

Publish a file: one call, no account

bash
curl -sS https://chorus.host/v1/publish -H 'X-Chorus-Client: claude-code/2.0' -F file=@index.html

The response is JSON: url, claimUrl, claimToken, expiresAt, and fileUrl (the direct link when you sent one file). A single .html file becomes the home page whatever it's called. More files: repeat -F file=@path (use -F "file=@app.js;filename=js/app.js" to keep a folder path), or zip the folder and send -F archive=@site.zip. Add -F slug=my-site to pick the subdomain, -H 'Accept: text/plain' to get only the link. Up to 4 MB of files per call without an API key, 10 MB with one; bigger sites use the three calls below.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 184)May include surrounding context.

md
| Do this | Call |
|---|---|
| Password-protect (anonymous sites too) | `PUT /v1/sites/<slug>/password` `{"username":"u","password":"p"}` (max 72 chars) |
| Remove password | `DELETE /v1/sites/<slug>/password` |
| Title / description / OG image / expiry | `PATCH /v1/sites/<slug>/metadata` `{"title":"...","description":"...","ogImagePath":"og.png","expiresAt":"..."}` |
| List versions | `GET /v1/sites/<slug>/versions` |
| Roll back | `POST /v1/sites/<slug>/versions/<versionId>/rollback` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The skill includes destructive operations such as DELETE /v1/sites/<slug> without emphasizing a confirmation step. In an agent setting, exposing deletion as a readily available action increases the risk of accidental destructive requests or prompt-injection-driven misuse if the agent follows hostile instructions using available credentials.

Content

Scanner excerpt · SKILL.md (reported line 188)May include surrounding context.

md
| Title / description / OG image / expiry | `PATCH /v1/sites/<slug>/metadata` `{"title":"...","description":"...","ogImagePath":"og.png","expiresAt":"..."}` |
| List versions | `GET /v1/sites/<slug>/versions` |
| Roll back | `POST /v1/sites/<slug>/versions/<versionId>/rollback` |
| Delete | `DELETE /v1/sites/<slug>` |
| Expired upload URLs (after 1 hour) | `POST /v1/sites/<slug>/versions/<versionId>/uploads/refresh` `{"paths":["index.html"]}` |

All of these take `X-Claim-Token` (anonymous) or `Authorization: Bearer` (owned).

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are very broad (publish this, give me a link, make a website, etc.), which increases the chance the skill activates on ambiguous requests. In this skill, accidental activation can cause files or folders to be uploaded to a public host, so mis-triggering has direct confidentiality consequences.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is centered on publishing local files and folders to a public URL, but it does not prominently require a pre-upload privacy review or explicit consent for public exposure. Users may unintentionally publish sensitive documents, source code, environment files, reports, or embedded secrets to an internet-accessible endpoint.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This section instructs the agent to transmit file metadata and file contents to external services (chorus.host and presigned storage URLs). External transmission is the core function of the skill, so the danger is contextually elevated: accidental use or misuse can expose user files, folder structures, and content outside the local environment.

Content

Scanner excerpt · SKILL.md (reported line 58)May include surrounding context.

md
CLIENT='X-Chorus-Client: claude-code/2.0'           # your harness/version, see below
HASH=$( (sha256sum "$F" 2>/dev/null || shasum -a 256 "$F") | cut -d' ' -f1)
SIZE=$(wc -c < "$F" | tr -d ' ')
curl -s https://chorus.host/v1/sites -H "$CLIENT" -H 'Content-Type: application/json' \
  -d "{\"files\":[{\"path\":\"index.html\",\"size\":$SIZE,\"contentType\":\"text/html; charset=utf-8\",\"hash\":\"sha256:$HASH\"}]}" > site.json
curl -s -X PUT "$(jq -r '.uploads.pending[0].uploadUrl' site.json)" \
  -H 'Content-Type: text/html; charset=utf-8' --data-binary @"$F"

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill supports direct upload of PDFs, images, and HTML to a public URL, which is a true external-transmission risk. Because the resulting link is public and browser-accessible, sensitive content may be exposed immediately and indexed or shared beyond the user's intent.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

Share a single file (PDF, image, HTML)

bash
curl -sS https://chorus.host/v1/upload -F file=@report.pdf     # prints https://<slug>.chorus.host/report.pdf

Files keep their content type, so HTML renders and PDFs and images open in the browser instead of downloading. Give the user the direct file link (fileUrl); chat apps such as Slack preview images from it. The site root shows a small viewer page. /v1/upload prints just the link and puts the claim details in the X-Claim-Token, X-Claim-Url and X-Expires-At response headers; /v1/publish returns them as JSON.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

The skill explicitly tells the agent to save the user's API key itself and not ask the user to do it. That encourages autonomous credential handling and persistent storage of a powerful token without a clear consent checkpoint, increasing the risk of silent misuse, later exfiltration, or use outside the user's expectations.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
## Save the API key yourself

Write it to `~/.config/beacon/config.json` as `{"apiKey":"chk_..."}` and `chmod 600` the file. `publish.py` and the `beacon` CLI read it from there (or from the `BEACON_API_KEY` environment variable). Do this yourself; don't ask the user to, and don't show the key in the chat.

Send it as `Authorization: Bearer chk_...`. With a key, sites last until you delete them or until an `expiresAt` you set, workers are available, `GET /v1/sites` lists sites, and `GET /v1/account` shows the account and its usage.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
## Save the API key yourself

Write it to `~/.config/beacon/config.json` as `{"apiKey":"chk_..."}` and `chmod 600` the file. `publish.py` and the `beacon` CLI read it from there (or from the `BEACON_API_KEY` environment variable). Do this yourself; don't ask the user to, and don't show the key in the chat.

Send it as `Authorization: Bearer chk_...`. With a key, sites last until you delete them or until an `expiresAt` you set, workers are available, `GET /v1/sites` lists sites, and `GET /v1/account` shows the account and its usage.

Session Persistence

Medium
Category
Rogue Agent
Confidence
92% confidence
Finding

The instruction to write the API key to ~/.config/beacon/config.json establishes persistent session state containing a reusable credential. Persistent storage expands the attack surface because future sessions, other tools, or malware on the host may read and misuse the token, and the user may not realize the credential remains resident.

Content

Scanner excerpt · SKILL.md (reported line 134)May include surrounding context.

md
## Save the API key yourself

Write it to `~/.config/beacon/config.json` as `{"apiKey":"chk_..."}` and `chmod 600` the file. `publish.py` and the `beacon` CLI read it from there (or from the `BEACON_API_KEY` environment variable). Do this yourself; don't ask the user to, and don't show the key in the chat.

Send it as `Authorization: Bearer chk_...`. With a key, sites last until you delete them or until an `expiresAt` you set, workers are available, `GET /v1/sites` lists sites, and `GET /v1/account` shows the account and its usage.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
## Keep this skill

Install it for future sessions: `npx skills add chorus-host/skill -g`. Or save this file as `~/.claude/skills/publish-website/SKILL.md` (Claude Code) or `~/.agents/skills/publish-website/SKILL.md`.

## More

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
## Keep this skill

Install it for future sessions: `npx skills add chorus-host/skill -g`. Or save this file as `~/.claude/skills/publish-website/SKILL.md` (Claude Code) or `~/.agents/skills/publish-website/SKILL.md`.

## More

Rp1

Medium
Category
MCP Rug Pull
Confidence
81% confidence
Finding

The skill instructs the agent to install additional code via npx skills add chorus-host/skill -g without pinning a version or integrity digest. That creates a supply-chain risk because the fetched package could change over time or be compromised, and the install is suggested for future sessions with persistent effect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.