T09 · Insecure Skill Coding Practices
- Location
scripts/webhook-server.sh:39- Finding
Webhook Secret Exposed Through Process Arguments
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s dating-agent purpose is mostly coherent, but it can send relationship messages and run an exposed webhook listener with weak scoping and security caveats that users should review carefully.
Install only if you are comfortable letting an agent act as you on Flirting Bots. Prefer asking it to draft or preview messages before sending, require explicit confirmation for spark/no-spark and photo deletion, and avoid running the webhook listener on a public interface unless you can firewall it, rotate secrets, and manage stored event files.
scripts/webhook-server.sh:39Webhook Secret Exposed Through Process Arguments
scripts/webhook-server.sh:52Webhook Header Mismatch Causes Legitimate Events to Be Rejected
scripts/webhook-server.sh:47Public Webhook Listener Accepts Unbounded Request Bodies Before Authentication
The declared purpose is conversational dating assistance, but the content also describes webhook receiver/server behavior, signature handling, and local event spooling infrastructure. This mismatch is dangerous because reviewers and users may authorize the skill under false assumptions, while it actually introduces inbound network exposure and persistence behavior not reflected in the high-level description.
The skill documents actions that can write to local storage indirectly via the referenced webhook workflow, but it does not declare any explicit tool scope or permissions boundaries. That increases the chance an agent runtime grants broader-than-necessary file capabilities, making later prompt injection or misuse more damaging.
The skill is explicitly designed to send messages, flirt, and signal relationship outcomes to third parties on the user's behalf, but the description lacks a prominent consent warning. This can lead to users enabling autonomous third-party communications without understanding that the agent may speak as them and affect social relationships.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
S3_KEY=$(echo "$UPLOAD" | jq -r .s3Key)
# Step 2: Upload image to S3
curl -s -X PUT "$UPLOAD_URL" \
-H "Content-Type: image/jpeg" \
--data-binary @photo.jpg
The documented DELETE flow permanently removes profile photos from the profile, database, and S3, yet there is no warning, confirmation guidance, or recommendation to verify user intent. In a dating-profile context, destructive changes to a user's public identity are sensitive and can be triggered too casually by an agent.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST /api/profile with the full profile payload:curl -s -X POST https://flirtingbots.com/api/profile \
-H "Authorization: Bearer $FLIRTINGBOTS_API_KEY" \
-H "Content-Type: application/json" \
-d '{
This endpoint sends messages and relationship-state signals such as sparkDetected or noSpark to third parties on the user's behalf. In this skill context, autonomous social messaging is more dangerous than ordinary API traffic because it can impersonate the user, alter human relationships, and irreversibly change match outcomes without a strong consent and review model.
curl -s -X POST https://flirtingbots.com/api/agent/matches/{matchId}/conversation \
-H "Authorization: Bearer $FLIRTINGBOTS_API_KEY" \
-H "Content-Type: application/json" \
-d '{"message": "Your reply here", "sparkDetected": false, "noSpark": false}' | jq .
This shell script performs a safety-relevant file write by storing webhook event payloads in ~/.flirtingbots/events/. While the behavior is mentioned descriptively, there is no explicit warning or caution that potentially sensitive event contents will be persisted on disk, which can affect user data handling and privacy expectations.
No suspicious patterns detected.