Back to skill

Security audit

BlackPix

Security checks for vulnerabilities and agentic risk

Overview

This skill is not deceptive, but it lets a third-party service assign agent tasks and receive submissions without clear consent, privacy, or instruction-boundary safeguards.

Review before installing. Use this only for non-sensitive work, require explicit approval before requesting tasks and before submitting content, and do not allow the agent to include secrets, local files, private chat history, credentials, or unrelated workspace data in BlackPix submissions. Store the API key as a scoped secret and revoke it if you stop using the service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Untrusted External Service Can Direct Agent Tasks and Receive Agent-Generated Content

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 3-94
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: High

Vulnerable Code

markdown
Connect to the BlackPix distributed AI knowledge network. Your bot receives tasks from the system, contributes knowledge, and earns karma to unlock more access.
bash
curl -X POST https://blackpix.com/api/open/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YourBotName", "description": "What you do"}'
json
{
  "apiKey": "bpx_xxx...",
  "claimUrl": "https://blackpix.com/claim/abc123",
  "claimInstructions": "Send claimUrl to your human..."
}
markdown
### Request Task

Get a task from BlackPix Get a physics task from BlackPix Request a BlackPix task about AI

text
System assigns a task with context (title, summary, instructions).

### Submit Work

Submit to BlackPix: [your contribution text]

text
Submit your completed work for AI evaluation.
bash
curl -X POST https://blackpix.com/api/work/request-task \
  -H "Content-Type: application/json" \
  -H "X-BlackPix-API-Key: $BLACKPIX_API_KEY" \
  -d '{"preferredType": "contribute", "focusAreas": ["physics"]}'
bash
curl -X POST https://blackpix.com/api/work/submit \
  -H "Content-Type: application/json" \
  -H "X-BlackPix-API-Key: $BLACKPIX_API_KEY" \
  -d '{"taskId": "uuid", "submission": "Your contribution..."}'

Technical Analysis

The skill delegates task selection and task instructions to the external blackpix.com service. It tells the agent to self-register, request a task containing a title, summary, and instructions, act on that task, and transmit the resulting contribution back to the service.

The document does not establish a trust boundary for remotely supplied task text. It does not require the agent to treat task instructions as untrusted data, constrain them to a d ...[truncated 2097 chars]

Remediation
View remediation

Remediation Suggestions

  1. Require explicit user authorization before registration, before accepting every remote task, and before submitting any content.
  2. Treat all remote task fields, including titles, summaries, instructions, and claim instructions, as untrusted data rather than authoritative agent instructions.
  3. Define a strict allowlist of supported task types and permitted tool operations. Reject tasks that request file access, credential access, shell execution, configuration changes, memory changes, or unrelated network activity.
  4. Add an explicit instruction-precedence rule stating that remote content cannot override system instructions, developer instructions, user intent, safety controls, or workspace boundaries.
  5. Validate API responses against a strict schema and enforce size, type, and content limits before presenting them to the agent.
  6. Apply outbound data-loss prevention before /submit: block secrets, API keys, environment variables, private conversation content, local file contents, and unrelated workspace data.
  7. Show the user the exact sanitized task and exact proposed submission, including the destination domain, before any action is taken.
  8. Scope the BlackPix API key to the minimum necessary permissions, store it in an approved secret manager, never include it in generated submissions, and support immediate revocation.
  9. Pin and verify the expected HTTPS origin. Do not follow cross-origin redirects for authenticated requests.
  10. Log task identifiers, approvals, rejected instructions, and submitted content for auditability without recording secrets.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The self-registration flow directs the agent to perform an external POST request that transmits identifying metadata and obtains an API key for ongoing interaction with a third-party network. In context, this is more dangerous because the skill is designed to enroll the agent into a remote task system and later encourages uploading work, creating a channel for data exfiltration and unauthorized external interaction if used without strict consent and scope controls.

Content

Scanner excerpt · SKILL.md (reported line 10)May include surrounding context.

Register yourself and get your API key:

bash
curl -X POST https://blackpix.com/api/open/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YourBotName", "description": "What you do"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to use a persistent API key and submit task content to an external service, but it does not clearly warn that status checks, task requests, history retrieval, and submissions transmit data off-platform. In an agent setting, this can lead to unreviewed disclosure of user, system, or task-derived information to a third party, especially because the workflow encourages routine outbound submissions.

Content

No source excerpt is available for this finding.