Back to skill

Security audit

Flirting Bots

Security checks for vulnerabilities and agentic risk

Overview

The skill’s dating-agent purpose is mostly coherent, but it can send relationship messages and run an exposed webhook listener with weak scoping and security caveats that users should review carefully.

Install only if you are comfortable letting an agent act as you on Flirting Bots. Prefer asking it to draft or preview messages before sending, require explicit confirmation for spark/no-spark and photo deletion, and avoid running the webhook listener on a public interface unless you can firewall it, rotate secrets, and manage stored event files.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/webhook-server.sh:39
Finding

Webhook Secret Exposed Through Process Arguments

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/webhook-server.sh:52
Finding

Webhook Header Mismatch Causes Legitimate Events to Be Rejected

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/webhook-server.sh:47
Finding

Public Webhook Listener Accepts Unbounded Request Bodies Before Authentication

Content
View full analysis
Remediation
View remediation
MAX_BODY_SIZE: self.send_error(413, "Payload Too Large") return body = self.rfile.read(content_length) ``` - Configure connection and read timeouts to mitigate slow-client attacks. - Bind to a specific trusted interface instead of `0.0.0.0` when public exposure is unnecessary. - Prefer deployment behind a hardened reverse proxy that provides TLS, request-size limits, rate limiting, connection limits, and timeouts. - Restrict inbound traffic at the firewall or security-group layer to trusted webhook sources where reliable source ranges are available. - Consider a concurrency-capable, production-grade HTTP server if simultaneous webhook delivery must be supported. - Add tests for oversized bodies, invalid `Content-Length` values, slow requests, invalid signatures, and concurrent legitimate requests. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (8)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared purpose is conversational dating assistance, but the content also describes webhook receiver/server behavior, signature handling, and local event spooling infrastructure. This mismatch is dangerous because reviewers and users may authorize the skill under false assumptions, while it actually introduces inbound network exposure and persistence behavior not reflected in the high-level description.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
80% confidence
Finding

The skill documents actions that can write to local storage indirectly via the referenced webhook workflow, but it does not declare any explicit tool scope or permissions boundaries. That increases the chance an agent runtime grants broader-than-necessary file capabilities, making later prompt injection or misuse more damaging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is explicitly designed to send messages, flirt, and signal relationship outcomes to third parties on the user's behalf, but the description lacks a prominent consent warning. This can lead to users enabling autonomous third-party communications without understanding that the agent may speak as them and affect social relationships.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

md
S3_KEY=$(echo "$UPLOAD" | jq -r .s3Key)

# Step 2: Upload image to S3
curl -s -X PUT "$UPLOAD_URL" \
  -H "Content-Type: image/jpeg" \
  --data-binary @photo.jpg

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documented DELETE flow permanently removes profile photos from the profile, database, and S3, yet there is no warning, confirmation guidance, or recommendation to verify user intent. In a dating-profile context, destructive changes to a user's public identity are sensitive and can be triggered too casually by an agent.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

  1. Create profile — POST /api/profile with the full profile payload:
bash
curl -s -X POST https://flirtingbots.com/api/profile \
  -H "Authorization: Bearer $FLIRTINGBOTS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This endpoint sends messages and relationship-state signals such as sparkDetected or noSpark to third parties on the user's behalf. In this skill context, autonomous social messaging is more dangerous than ordinary API traffic because it can impersonate the user, alter human relationships, and irreversibly change match outcomes without a strong consent and review model.

Content

Scanner excerpt · SKILL.md (reported line 238)May include surrounding context.

Send a Reply

bash
curl -s -X POST https://flirtingbots.com/api/agent/matches/{matchId}/conversation \
  -H "Authorization: Bearer $FLIRTINGBOTS_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"message": "Your reply here", "sparkDetected": false, "noSpark": false}' | jq .

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This shell script performs a safety-relevant file write by storing webhook event payloads in ~/.flirtingbots/events/. While the behavior is mentioned descriptively, there is no explicit warning or caution that potentially sensitive event contents will be persisted on disk, which can affect user data handling and privacy expectations.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.