Back to skill

Security audit

TheRoaster

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for a roast API, but it also guides agents through wallet-based purchases and public posting, which should be reviewed before use.

Install only if you are comfortable with the agent calling an external roast API and, for paid use, working around a wallet-controlled on-chain purchase flow. Keep wallet tools disabled unless you explicitly approve the exact approve, purchase, signing, and claim action in-session, and require review before any generated roast is posted publicly.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 226)May include surrounding context.

md
- PM2 for process management
- OpenAI API provides roasts
- 
Secrets must be stored in .env (never committed).

------------------------------------------------------------

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.MD (reported line 380)May include surrounding context.

md
- PM2 for process management
- OpenAI API provides roasts
- 
Secrets must be stored in .env (never committed).

------------------------------------------------------------

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The file says agents must never use wallet functions without human confirmation, but immediately provides instructions for agents to purchase directly using a controlled wallet. This contradiction is dangerous because agent frameworks may implement the actionable purchase flow while treating the warning as advisory, enabling unauthorized or insufficiently consented on-chain spending.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README presents conflicting guidance: it says agents must never use wallet functions without human confirmation, but elsewhere promotes direct wallet-controlled purchases by agents. This ambiguity is dangerous because agent integrators may implement autonomous financial actions without an explicit confirmation checkpoint, leading to unauthorized or unintended blockchain transactions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The section describing agent/bot purchasing workflows encourages building approval and purchase transactions and purchasing directly with a controlled wallet, but does not repeat a clear safety warning at the point where the action is described. In agent ecosystems, operational instructions near actionable endpoints are often followed literally, so missing an in-context warning increases the chance of unauthorized spending or unsafe wallet automation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill’s stated purpose is roast generation, but it also documents plan purchasing, transaction building, signature-based auth, and API-key issuance. Expanding a content-generation skill to include wallet and entitlement flows increases the attack surface and creates a path for unintended financial actions if an integrating agent follows the instructions too broadly.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.MD (reported line 194)May include surrounding context.

md
GET /health

curl:
curl -sS https://theroaster.app/health

2) Contract Metadata
GET /api/v1/contract

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill instructs bots to post returned roast text unchanged as a public comment, but does not warn that this is third-party generated content being published externally. That creates a risk of reputational harm, harassment, policy violations, or accidental publication of unsafe output because the agent is told not to review, transform, or gate the content before posting.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.