Back to skill

Security audit

IdentityMonitoringAgent

Security checks for vulnerabilities and agentic risk

Overview

This identity-monitoring skill is coherent but needs Review because it sends sensitive identifiers to external OSINT services and uses shell-style command templates with weak scoping.

Install only in an isolated environment and use it only for your own accounts or targets you are authorized to investigate. Expect emails, usernames, phone numbers, and search queries to be sent to external services or search providers. Pin and review dependencies before use, and avoid passing untrusted input through the documented shell-style command templates.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:60
Finding

Shell Command Injection Through Unescaped Tool Arguments

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 60-70
Vulnerability Type: Shell command injection through unsafe command templates
Risk Level: High

The documented tool calls interpolate user-controlled email addresses, usernames, and search queries directly into shell command strings:

markdown
### `scan_email`
Checks 120+ sites to see if an email is registered using forgotten password flows.
- **Inputs:** `email` (string)
- **Call:** `python3 monitor.py --tool scan_email --target {{email}}`

### `scan_username`
Hunts for a specific username across 400+ social networks and platforms.
- **Inputs:** `username` (string)
- **Call:** `python3 monitor.py --tool scan_username --target {{username}}`

### `search_leaks`
Uses advanced Google Dorks to find identifiers on leak sites, forums, and pastebins.
- **Inputs:** `query` (string)
- **Call:** `python3 monitor.py --tool search_leaks --query "{{query}}"`

Technical Analysis

The email and username placeholders are completely unquoted. If the skill runtime expands these templates and executes the resulting text through a shell, shell metacharacters in an attacker-controlled value are interpreted as command syntax rather than as part of a single argument.

Although the query placeholder is surrounded by double quotes, an attacker can include a double quote in the supplied value to terminate the quoted argument and then introduce shell operators. Quoting the template without escaping the interpolated data therefore does not establish a security boundary.

The Python subprocess calls in monitor.py use argument arrays and do not independently invoke a shell. The injection occurs one layer earlier if the documented skill call is rendered into a shell command.

Attack Path

  1. An attacker supplies a crafted value through a request handled by the skill. For example, an email or username could contain x; touch /tmp/skill-injection.

...[truncated 1044 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not represent tool invocation as a shell command assembled through textual interpolation.
  • Invoke the program through an argument array, preserving each user value as one argument. For example:
    python
    subprocess.run(
        ["python3", "monitor.py", "--tool", "scan_email", "--target", email],
        check=True,
        shell=False,
    )
    
  • Apply the same approach to username and query operations.
  • Explicitly prohibit shell execution mechanisms such as shell=True, sh -c, or equivalent wrappers for these calls.
  • Validate inputs before invocation. Enforce an email format and reasonable length for email input, a conservative platform-compatible character set for usernames, and maximum lengths for all fields.
  • If command-string generation is unavoidable, use a platform-appropriate argument-escaping function for every interpolated value. Escaping is a fallback and should not replace argument-array execution.
  • Run the skill in a restricted account or container with minimal filesystem access, no unnecessary credentials, and constrained outbound networking to reduce the impact of any future command-execution flaw.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:28
Finding

Unpinned Third-Party Dependencies Installed Without Integrity Verification

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 28
Vulnerability Type: Unpinned and integrity-unverified package installation
Risk Level: Medium

The setup instructions install mutable package versions directly from the configured Python package index:

bash
pip install holehe sherlock-project googlesearch-python

Technical Analysis

No exact versions or cryptographic hashes are specified for the three direct dependencies. Consequently, repeated installations can resolve to different package releases and different transitive dependency trees. Python packages may execute build backend or installation logic during installation, and their imported runtime code executes with the privileges of the agent.

If a dependency account, release pipeline, package index, or transitive dependency is compromised, the setup command can install attacker-controlled code even though the reviewed project files remain unchanged. The absence of a lock file and hash verification also prevents reliable reproduction of the audited dependency set.

Attack Path

  1. An attacker compromises a listed dependency, one of its transitive dependencies, or the package distribution channel.
  2. The attacker publishes a malicious version that satisfies the unconstrained installation request.
  3. An operator follows the setup instructions and executes the documented pip install command.
  4. pip resolves and downloads the malicious release because no reviewed version or hash is required.
  5. Malicious code executes during package build or installation, or later when monitor.py imports or invokes the installed component.

Impact Assessment

A compromised dependency can execute code with the privileges of the account performing installation or running the skill. Potential impact includes theft of environment variables and credentials, modification of local files or installed tools, unauthorized network access, and compromise of ...[truncated 119 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin every direct dependency to a reviewed exact version.
  • Generate a fully resolved lock file that also fixes all transitive dependency versions.
  • Require cryptographic hashes during installation, for example through a hash-locked requirements file and pip install --require-hashes.
  • Retrieve packages only from an approved package index over authenticated TLS and disable unintended extra indexes to reduce dependency-confusion exposure.
  • Review package provenance, maintainers, release history, and dependency trees before updating the lock file.
  • Perform dependency updates through a controlled process with vulnerability scanning and behavioral review.
  • Install packages inside a dedicated virtual environment or isolated container as an unprivileged user rather than into the system Python environment.
  • Prefer binary wheels from trusted sources where appropriate, and prevent unexpected source builds in production installation workflows.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill invokes shell commands and external binaries (python3, holehe, sherlock) but does not declare an explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability, making it easier for an agent runtime to grant broader execution capability than users expect, especially in a privacy-sensitive OSINT workflow.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill encourages scanning emails, usernames, phone numbers, and password-recovery-based enumeration without prominent privacy, consent, or legal-use warnings. In this context, users may deploy the skill for unauthorized account discovery or identity profiling, and the password-reset flow checks can generate privacy-invasive or potentially abusive reconnaissance against third parties.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The function submits a target email address to an external enumeration tool without any disclosure, consent, or warning that the identifier will be processed externally. This creates a privacy and compliance risk because users may not realize that sensitive PII is being transmitted and checked against third-party services.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · monitor.py (reported line 9)May include surrounding context.

python
def scan_email(email):
    try:
        result = subprocess.run(['holehe', email, '--only-used'], capture_output=True, text=True)
        raw_lines = result.stdout.split('\n')
        registered = [
            line.replace("[+]", "").strip()

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill delegates core functionality to external executables (holehe and sherlock), which expands the trust boundary to whatever binaries are installed on the host. In an agent setting, this is dangerous because the wrapper provides no verification, sandboxing, or provenance checks for those tools, so behavior may differ from the advertised web-monitoring function and could leak data or execute untrusted code paths.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The username profiling feature invokes an external reconnaissance tool with no visible notice that the supplied username will be searched across external services. In an identity-monitoring context this increases the risk of covert OSINT collection, privacy harm, and misuse for profiling third parties without informed consent.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · monitor.py (reported line 22)May include surrounding context.

python
def scan_username(username):
    try:
        result = subprocess.run(['sherlock', username, '--timeout', '1'], capture_output=True, text=True)
        found = [line.split(': ')[1] for line in result.stdout.split('\n') if 'http' in line]
        return json.dumps({"target": username, "profiles": found})
    except Exception as e:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The leak-search function automatically sends user-supplied queries to external search engines using sensitive dorks such as password and database leak terms, without telling the user that their query leaves the local environment. In this skill context, queries may contain emails, usernames, or other identifiers, so undisclosed transmission can expose sensitive investigative targets and create privacy or policy issues.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.