Back to skill

Security audit

CARP

Security checks for vulnerabilities and agentic risk

Overview

The skill is mainly a CARP operations guide, but it asks users to deploy mutable npm code, use plaintext public endpoints, and set up persistent monitoring without enough boundaries.

Install only if you are comfortable operating a CARP CGI service and can harden it yourself: pin and lock dependencies, run it under a dedicated low-privilege account, avoid plaintext public endpoints where possible, keep private keys outside public paths, and make any cron monitoring an explicit opt-in with a clear disable path.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T06 · System Persistence

Error
Location
SKILL.md:233
Finding

Persistent Hourly Execution Through Cron

Content
View full analysis
` (fresh SAD, verify proof and compare pubkey), `/index.json` (menu/goods/fees). 4. Classify: UP (all probes ok), DEGRADED (reachable but something failed), DOWN (timenow unreachable). Sellers = role Seller or fee-bearing services. 5. Publish an HTML report to the doc root `index.html` (atomic write: tmp file + rename). The report doubles as catalog/flyer source material. 6. Run from cron hourly; log runs and keep `last-report.json` state. ``` ### Technical Analysis The Skill directs the operator or agent to install an hourly cron job. Cron survives the initiating Skill run and continues to perform network requests and filesystem writes across sessions without renewed user authorization. Health monitoring is related to the declared CARP functionality, but persistent scheduling is not necessary for ordinary on-demand queue processing or endpoint management. The instructions do not define a least-privileged account, bounded execution time, network allowlist, secure cron environment, retention policy, or removal procedure. The scheduled process also consumes directory information and publishes generated HTML. If directory data, peer metadata, or report content is malicious or improperly escaped by the eventual implementation, repeated unattended processing can amplify downstream risks. ### Attack ...[truncated 1108 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Error
Location
SKILL.md:48
Finding

Unpinned Third-Party Dependency Installation Without a Lockfile

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:152
Finding

Identity and Authentication Exchanges Over Plaintext HTTP

Content
View full analysis
", "", ]` - The DID must be passed as the plain did:key STRING, not the DID-document object — the object form is rejected with `did must equal sad.id`. - Lookup: `POST /cgi-bin/get` with `[ "" ]`; also `byDID`, `byHandle` (same array shape). There is no `byPubkey` endpoint — that's what `get` is. `verify` takes `[pubkey, did, sad]`. - `update`/`remove`/`revoke` implicitly authenticate by envelope `spkhex`. 3. Challenge/response handshake with El-Cabezon (Concierge, `http://70.66.243.75:8000`): - `GET /cgi-bin/challenge` → `{ result: { challenge: } }` - `adilos.makeResponse(chB64, privKeyBuffer)` → `rspB64` - `POST /cgi-bin/response` with `{ "rsp": rspB64, "chall": chB64 }` - 200 `{"ack":""}` = recognized. ``` ### Technical Analysis The Skill instructs users to send identity-registration and challenge-response traffic to hard-coded public IP addresses over plaintext HTTP. HTTP provides neither confidentiality nor authenticated server identity. The public key, DID, and signed descriptor may be intended for publication, and the private key is not directly transmitted. Nevertheless, registration metadata, challenges, responses, timing, and peer relationships are visible to network intermediaries. More importantly, the client cannot cryptographically verify that it is communicating with the intended Registrar or Concierge. The returned HTTP status and acknowledgement are treated as evidence of recognition even tho ...[truncated 1606 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

const ecjsonrpc = require('ecjsonrpc') process.stdout.write(JSON.stringify(ecjsonrpc.makeKey())) NODE chmod 600 AGENT_EC_KEYPAIR.txt

text

- `prv`: private EC key. Never share, send, commit, log, or expose.

Static analysis

No suspicious patterns detected.