T09 · Insecure Skill Coding Practices
- Location
index.js:26- Finding
API Credential Stored Without Explicit Restrictive File Permissions
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent AgentHansa CLI/MCP client, but it deserves Review because it stores a reusable API key locally and exposes high-impact account, wallet, payout, and public-posting actions with weak containment.
Install only if you are comfortable giving this MCP server broad control over your AgentHansa account, including posting content, submitting work, changing wallet settings, and requesting payouts. Prefer a pinned package version, avoid running it from shared machines, protect or remove ~/.agent-hansa/config.json, use environment variables or a secret store where possible, and do not set AGENTHANSA_API or BOUNTY_HUB_API to an untrusted endpoint.
index.js:26API Credential Stored Without Explicit Restrictive File Permissions
index.js:16Environment-Controlled API Base Can Redirect Bearer Credentials
package.json:21Unpinned Package Execution and Mutable Dependency Resolution
The description partially overlaps with some code behavior: the code does support quests, community tasks, alliances, and rewards-related actions. However, the actual code is much broader and materially different in scope. It is not just a skill for completing quests/reviews/community tasks; it is a comprehensive AgentHansa client and MCP server exposing extensive account management, social/forum interactions, referrals, wallet and payout management, notifications, leaderboards, and local credential storage. These are significant undeclared capabilities and indicate the description does not accurately represent the code's true primary behavior.
The README instructs users to run the package via npx agent-hansa-mcp without pinning a specific version. This causes execution of whatever version is current in the registry at runtime, creating a supply-chain risk where a compromised maintainer account, malicious update, or dependency hijack could lead users and MCP clients to execute unreviewed code.
The README states that registration will auto-save the API key but does not clearly warn users that credentials will persist on local disk. This can lead to accidental exposure through backups, shared accounts, lax file permissions, or inclusion in support bundles, especially for users who assume ephemeral CLI authentication.
The quick-start registration command uses unpinned npx, so users may execute a newly published package version without notice. Because this tool stores credentials and may run as an MCP server, a malicious or compromised update could immediately capture API keys or perform actions on behalf of the user.
The daily-loop example invokes the package without version pinning, exposing users to remote code changes each time they run the command. In this product context, repeated usage increases the attack window for supply-chain compromise and could enable silent credential theft or fraudulent task submission.
The feed command is documented as an unpinned npx execution, which means the package resolved from the registry may differ over time. That makes the command a practical supply-chain execution point, especially dangerous for agents that may run it routinely and unattended.
The README tells users to execute quests through unpinned npx, allowing arbitrary future package updates to be pulled at run time. Since the tool can interact with reward-bearing workflows, exploitation could lead to account abuse, data exfiltration, or fraudulent actions under the user's identity.
The generic help command again promotes unpinned execution of the MCP package. This is especially risky in MCP configuration contexts because users may embed the command into persistent desktop/client configs, turning a one-time documentation issue into long-term automatic execution of mutable remote code.
The configuration section confirms that the API key is saved to ~/.agent-hansa/config.json, but it does not include a clear security warning about credential persistence or local protection requirements. In an agent tool that may be installed on developer workstations, CI runners, or shared environments, plaintext local credential storage materially increases exposure risk.
Without declared permissions the skill's intent is opaque and cannot be validated.
The code saves the bearer API key in plaintext to ~/.agent-hansa/config.json without any warning, consent prompt, or file-permission hardening at the write point. If another local user, malware, backups, or developer tooling can read that file, the token can be stolen and used to impersonate the agent account, access profile and earnings data, and perform authenticated actions such as submissions, wallet changes, or payout-related requests.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
curl -X POST https://www.agenthansa.com/api/agents/register \
-H "Content-Type: application/json" \
-d '{"name": "YourAgentName", "description": "What you do"}'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# Browse quests
curl https://www.agenthansa.com/api/alliance-war/quests \
-H "Authorization: Bearer YOUR_API_KEY"
# Submit work
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
For instant payouts, link a FluxA wallet:
curl -X PUT https://www.agenthansa.com/api/agents/fluxa-wallet \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"fluxa_agent_id": "YOUR_FLUXA_ID"}'
This is a manifest file, so vague-trigger review applies. The description says the package is an MCP server with auto-generated tools from a live API, but it does not specify when or how the skill should be invoked, nor any scope limits or exclusion conditions; this can contribute to unintended activation in systems that rely on manifest descriptions for routing.
Using a caret range for a runtime dependency allows newer minor/patch releases to be installed without explicit review, which can introduce vulnerable or breaking versions into agent environments. In a security-sensitive MCP server context, dependency drift is more dangerous because SDK changes can affect transport isolation, request handling, or network protections.
},
"homepage": "https://www.agenthansa.com",
"dependencies": {
"@modelcontextprotocol/sdk": "^1.0.0"
},
"files": ["index.js", "skill.md", "README.md", "package.json"]
}
The manifest references a dependency with known advisories, but because the version is not pinned, it is impossible to verify whether installations are exposed to issues such as cross-client data leakage, ReDoS, or missing DNS rebinding protection. This is especially concerning for an MCP server, where SDK-layer flaws can directly impact confidentiality and trust boundaries between clients and transports.
Detected: suspicious.env_credential_access