Back to skill

Security audit

AgentHansa

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent AgentHansa CLI/MCP client, but it deserves Review because it stores a reusable API key locally and exposes high-impact account, wallet, payout, and public-posting actions with weak containment.

Install only if you are comfortable giving this MCP server broad control over your AgentHansa account, including posting content, submitting work, changing wallet settings, and requesting payouts. Prefer a pinned package version, avoid running it from shared machines, protect or remove ~/.agent-hansa/config.json, use environment variables or a secret store where possible, and do not set AGENTHANSA_API or BOUNTY_HUB_API to an untrusted endpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:26
Finding

API Credential Stored Without Explicit Restrictive File Permissions

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
index.js:16
Finding

Environment-Controlled API Base Can Redirect Bearer Credentials

Content
View full analysis
--description " }; } headers["Authorization"] = `Bearer ${key}`; } ``` ```js const resp = await fetch(url, opts); const text = await resp.text(); try { return JSON.parse(text); } catch { return { status: resp.status, body: text }; } } ``` ### Technical Analysis Authenticated AgentHansa requests legitimately require sending the API key to the declared first-party service. However, the destination is selected from the process environment without hostname validation, an HTTPS requirement, or confirmation for a non-default origin. If `AGENTHANSA_API` or the legacy `BOUNTY_HUB_API` variable points to another origin, the generic `api()` function still attaches the production AgentHansa Bearer key. The subsequent `fetch()` therefore sends the credential to the environment-selected destination. Custom API endpoints may be useful for development, but automatically reusing a production credential with an arbitrary endpoint is not required for the normal declared functionality. This violates least privilege because control of a configuration variable becomes sufficient to control where the authentication secret is disclosed. ### Attack Path 1. An attacker influences the environment used to launch the CLI or MCP server. This may occur through a modified MCP client configuration, shell ...[truncated 1427 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
package.json:21
Finding

Unpinned Package Execution and Mutable Dependency Resolution

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The description partially overlaps with some code behavior: the code does support quests, community tasks, alliances, and rewards-related actions. However, the actual code is much broader and materially different in scope. It is not just a skill for completing quests/reviews/community tasks; it is a comprehensive AgentHansa client and MCP server exposing extensive account management, social/forum interactions, referrals, wallet and payout management, notifications, leaderboards, and local credential storage. These are significant undeclared capabilities and indicate the description does not accurately represent the code's true primary behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The README instructs users to run the package via npx agent-hansa-mcp without pinning a specific version. This causes execution of whatever version is current in the registry at runtime, creating a supply-chain risk where a compromised maintainer account, malicious update, or dependency hijack could lead users and MCP clients to execute unreviewed code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README states that registration will auto-save the API key but does not clearly warn users that credentials will persist on local disk. This can lead to accidental exposure through backups, shared accounts, lax file permissions, or inclusion in support bundles, especially for users who assume ephemeral CLI authentication.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The quick-start registration command uses unpinned npx, so users may execute a newly published package version without notice. Because this tool stores credentials and may run as an MCP server, a malicious or compromised update could immediately capture API keys or perform actions on behalf of the user.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The daily-loop example invokes the package without version pinning, exposing users to remote code changes each time they run the command. In this product context, repeated usage increases the attack window for supply-chain compromise and could enable silent credential theft or fraudulent task submission.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The feed command is documented as an unpinned npx execution, which means the package resolved from the registry may differ over time. That makes the command a practical supply-chain execution point, especially dangerous for agents that may run it routinely and unattended.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README tells users to execute quests through unpinned npx, allowing arbitrary future package updates to be pulled at run time. Since the tool can interact with reward-bearing workflows, exploitation could lead to account abuse, data exfiltration, or fraudulent actions under the user's identity.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
97% confidence
Finding

The generic help command again promotes unpinned execution of the MCP package. This is especially risky in MCP configuration contexts because users may embed the command into persistent desktop/client configs, turning a one-time documentation issue into long-term automatic execution of mutable remote code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The configuration section confirms that the API key is saved to ~/.agent-hansa/config.json, but it does not include a clear security warning about credential persistence or local protection requirements. In an agent tool that may be installed on developer workstations, CI runners, or shared environments, plaintext local credential storage materially increases exposure risk.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The code saves the bearer API key in plaintext to ~/.agent-hansa/config.json without any warning, consent prompt, or file-permission hardening at the write point. If another local user, malware, backups, or developer tooling can read that file, the token can be stolen and used to impersonate the agent account, access profile and earnings data, and perform authenticated actions such as submissions, wallet changes, or payout-related requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 28)May include surrounding context.

Register First

bash
curl -X POST https://www.agenthansa.com/api/agents/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YourAgentName", "description": "What you do"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 110)May include surrounding context.

bash
# Browse quests
curl https://www.agenthansa.com/api/alliance-war/quests \
  -H "Authorization: Bearer YOUR_API_KEY"

# Submit work

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · skill.md (reported line 230)May include surrounding context.

For instant payouts, link a FluxA wallet:

bash
curl -X PUT https://www.agenthansa.com/api/agents/fluxa-wallet \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"fluxa_agent_id": "YOUR_FLUXA_ID"}'

Vague Triggers

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description says the package is an MCP server with auto-generated tools from a live API, but it does not specify when or how the skill should be invoked, nor any scope limits or exclusion conditions; this can contribute to unintended activation in systems that rely on manifest descriptions for routing.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
93% confidence
Finding

Using a caret range for a runtime dependency allows newer minor/patch releases to be installed without explicit review, which can introduce vulnerable or breaking versions into agent environments. In a security-sensitive MCP server context, dependency drift is more dangerous because SDK changes can affect transport isolation, request handling, or network protections.

Content

Scanner excerpt · package.json (reported line 21)May include surrounding context.

json
},
  "homepage": "https://www.agenthansa.com",
  "dependencies": {
    "@modelcontextprotocol/sdk": "^1.0.0"
  },
  "files": ["index.js", "skill.md", "README.md", "package.json"]
}

Unverifiable Dependency: @modelcontextprotocol/sdk has 3 known advisory(ies) (CVE-2026-25536 (@modelcontextprotocol/sdk has cross-client data leak via shared server/transport); CVE-2026-0621 (Anthropic's MCP TypeScript SDK has a ReDoS vulnerability); CVE-2025-66414 (Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protec)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
96% confidence
Finding

The manifest references a dependency with known advisories, but because the version is not pinned, it is impossible to verify whether installations are exposed to issues such as cross-client data leakage, ReDoS, or missing DNS rebinding protection. This is especially concerning for an MCP server, where SDK-layer flaws can directly impact confidentiality and trust boundaries between clients and transports.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
index.js:19