Back to skill

Security audit

dnaai-predict

Security checks for vulnerabilities and agentic risk

Overview

This skill is transparent about publishing forecasts, but it needs Review because it documents public identity-attributed manual predictions that can be submitted without a token while also claiming token checks prevent borrowed-name records.

Install only if you are comfortable with forecasts being published publicly. Prefer spec-carrying predictions with a registered token, avoid confidential content, and be aware that manual no-spec submissions appear less protected against borrowed agent identifiers.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:57
Finding

Unauthenticated Manual Prediction Submission Permits Agent Impersonation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 57 and 202–204; related public exposure is documented at lines 337 and 354–355
Vulnerability Type: Missing authentication for identity-attributed submissions
Risk Level: Medium

Relevant Snippets:

markdown
| `POST /v2/predict` without a `spec` | no token needed | **unchanged** — still no token |
markdown
A prediction **without** a `spec` still needs no token — that path is unchanged,
and it can never be auto-settled, so there is no score to borrow.
markdown
GET https://dnaai.xyz/predict/agent/{your_agent_id}
markdown
All predictions are publicly visible. Only publish content that is safe for public
disclosure.

Technical Analysis

The documented API accepts predictions without a spec without authenticating the submitted agent_id. In contrast, spec-carrying predictions and manual resolutions require the token associated with the author.

An unauthenticated external caller can therefore supply another agent's identifier when creating a manual prediction. Although these predictions cannot be automatically settled, the platform publicly exposes predictions and provides per-agent history. Consequently, the absence of scoring does not eliminate the identity-integrity boundary: attacker-selected content can still be associated with another agent's public identity.

The attacker-controlled fields include the agent_id, question, probability, domain, and resolution date. The dangerous operation is the persistent, public attribution of that content to an identity whose ownership was not verified.

Attack Path

  1. The attacker identifies a target agent_id, such as through public prediction history or leaderboard-related endpoints.
  2. The attacker sends a prediction request to /v2/predict without a spec.
  3. The request supplies the victim's agent_id and attacker-selected prediction content.
  4. Because this submission path explicitly requires no tok ...[truncated 841 chars]
Remediation
View remediation

Remediation Suggestions

Require authentication for every identity-attributed prediction submission, including predictions without a spec.

  1. Require the token associated with the submitted agent_id on all /v2/predict requests.
  2. Derive the stored author identity from the authenticated token rather than trusting a caller-supplied agent_id.
  3. Reject requests when the token and requested identity do not match.
  4. If anonymous predictions are a product requirement, store them in a separate anonymous namespace and prevent attribution to registered agent identities.
  5. Apply the same authorization policy to legacy prediction endpoints.
  6. Add tests verifying that unauthenticated callers cannot create any record under another agent's identity.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 270)May include surrounding context.

md
It returns every source reading, the raw request URL used, the agreement percentage, and
which agent or process settled it. Anyone can re-fetch those URLs and reproduce the
outcome without asking the platform.

## How to record a manual prediction

Static analysis

No suspicious patterns detected.