T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:57- Finding
Unauthenticated Manual Prediction Submission Permits Agent Impersonation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 57 and 202–204; related public exposure is documented at lines 337 and 354–355
Vulnerability Type: Missing authentication for identity-attributed submissions
Risk Level: MediumRelevant Snippets:
markdown | `POST /v2/predict` without a `spec` | no token needed | **unchanged** — still no token |markdown A prediction **without** a `spec` still needs no token — that path is unchanged, and it can never be auto-settled, so there is no score to borrow.markdown GET https://dnaai.xyz/predict/agent/{your_agent_id}markdown All predictions are publicly visible. Only publish content that is safe for public disclosure.Technical Analysis
The documented API accepts predictions without a
specwithout authenticating the submittedagent_id. In contrast, spec-carrying predictions and manual resolutions require the token associated with the author.An unauthenticated external caller can therefore supply another agent's identifier when creating a manual prediction. Although these predictions cannot be automatically settled, the platform publicly exposes predictions and provides per-agent history. Consequently, the absence of scoring does not eliminate the identity-integrity boundary: attacker-selected content can still be associated with another agent's public identity.
The attacker-controlled fields include the
agent_id, question, probability, domain, and resolution date. The dangerous operation is the persistent, public attribution of that content to an identity whose ownership was not verified.Attack Path
- The attacker identifies a target
agent_id, such as through public prediction history or leaderboard-related endpoints. - The attacker sends a prediction request to
/v2/predictwithout aspec. - The request supplies the victim's
agent_idand attacker-selected prediction content. - Because this submission path explicitly requires no tok ...[truncated 841 chars]
- The attacker identifies a target
- Remediation
View remediation
Remediation Suggestions
Require authentication for every identity-attributed prediction submission, including predictions without a
spec.- Require the token associated with the submitted
agent_idon all/v2/predictrequests. - Derive the stored author identity from the authenticated token rather than trusting a caller-supplied
agent_id. - Reject requests when the token and requested identity do not match.
- If anonymous predictions are a product requirement, store them in a separate anonymous namespace and prevent attribution to registered agent identities.
- Apply the same authorization policy to legacy prediction endpoints.
- Add tests verifying that unauthenticated callers cannot create any record under another agent's identity.
- Require the token associated with the submitted
