T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:91- Finding
Remote-Controlled Source URLs Can Trigger Server-Side Request Forgery
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent GEO automation helper, but it handles API keys, scheduled authenticated requests, local file writes, and remote-controlled fetch/export paths with insufficient scoping and safeguards.
Review before installing. This skill is not clearly malicious, but it should only be used if you trust the GEO SaaS account and service responses, accept daily unattended authenticated actions, and are comfortable with a plaintext local API key. Prefer a secure secret store or owner-only key file permissions, validate exported path components, and restrict web_fetch to trusted public HTTPS URLs before enabling scheduled use.
SKILL.md:91Remote-Controlled Source URLs Can Trigger Server-Side Request Forgery
SKILL.md:68API-Controlled Brand and Product Names Permit Export Path Traversal
SKILL.md:20API Key File Is Created Without Enforced Restrictive Permissions
The manifest declares only web_fetch, but the skill instructions direct the agent to read and write local credential files and perform arbitrary HTTP requests with bearer tokens. This creates a dangerous permission mismatch: reviewers or runtime policy may assume the skill is limited to web fetches when it actually instructs sensitive local file access and authenticated outbound actions.
The skill is designed to run automatically on scheduled load 'without the user saying start', but its trigger conditions are broad and not tightly scoped to safe preconditions. In an autopilot context, ambiguous invocation increases the chance of unattended network activity, credential use, and file writes occurring without fresh user awareness or confirmation.
The skill instructs reading, storing, and resetting API keys in local dotfiles, including prompting the user to paste a secret and saving it unencrypted. Even if intended for convenience, this expands the skill from task orchestration into credential handling, increasing the risk of secret exposure, misuse, or accidental persistence without proper safeguards.
The skill tells the user to provide and locally store an API key but does not include a clear warning about secret-handling risks, storage location sensitivity, or who can access those files. In a scheduled autonomous skill, weak disclosure makes accidental credential exposure more likely because users may not realize the key is being persisted for future runs.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -s -X POST "$BASE/api/geo/verify-key" \
-H "Authorization: Bearer $GEO_KEY"
No suspicious patterns detected.