Back to skill

Security audit

Skill Hub Gateway

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent gateway integration, but it handles credentials, account actions, telemetry, and local file uploads with under-scoped controls that warrant Review before use.

Install only if you trust BinaryWorks and your agent runtime will restrict invocations to the intended gateway domains. Disable or constrain telemetry if possible, do not pass untrusted base_url or SKILL_TELEMETRY_BASE_URL values, avoid raw file_path inputs for sensitive files, and treat the face/person-recognition capabilities and portal account actions as sensitive.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/runtime-auth.mjs:6
Finding

Caller-Controlled Base URL Can Expose API Credentials Over Arbitrary or Plaintext Network Destinations

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/telemetry.mjs:12
Finding

Opt-Out Telemetry Can Send API Keys and Stable Identifiers to an Unvalidated Destination

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/attachment-normalize.mjs:145
Finding

Unrestricted file_path Processing Can Read and Upload Files Outside the Workspace

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (38)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

md
- Local current version source: this installed `SKILL.md` frontmatter `version`.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 102)May include surrounding context.

md
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 215)May include surrounding context.

md
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 235)May include surrounding context.

md
- `portal-action.mjs` defaults `include_files=true` for `portal.skill.presentation` unless explicitly disabled.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 125)May include surrounding context.

md
- `scripts/execute.mjs` (CLI args: `[api_key] [capability] [input_payload] [base_url] [agent_uid] [owner_uid_hint]`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
- `scripts/execute.mjs` (CLI args: `[api_key] [capability] [input_payload] [base_url] [agent_uid] [owner_uid_hint]`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 126)May include surrounding context.

md
- `scripts/poll.mjs` (CLI args: `[api_key] <run_id> [base_url] [agent_uid] [owner_uid_hint]`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 234)May include surrounding context.

md
- `scripts/poll.mjs` (CLI args: `[api_key] <run_id> [base_url] [agent_uid] [owner_uid_hint]`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 127)May include surrounding context.

md
- `scripts/feedback.mjs` (CLI args: `[api_key] [payload_json] [base_url] [agent_uid] [owner_uid_hint]`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

md
- `scripts/feedback.mjs` (CLI args: `[api_key] [payload_json] [base_url] [agent_uid] [owner_uid_hint]`)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
- `scripts/runtime-auth.mjs` (shared auto-bootstrap helper)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
- `scripts/portal-auth.mjs` (api-key -> user session bridge)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 224)May include surrounding context.

md
- `scripts/portal-auth.mjs` (api-key -> user session bridge)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 132)May include surrounding context.

md
- `scripts/attachment-normalize.mjs` (attachment URL/path normalization + upload)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
- `scripts/attachment-normalize.mjs` (attachment URL/path normalization + upload)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The capabilities catalog exposes a very broad set of services that materially exceeds the skill's stated purpose as a gateway for async execute/poll, portal user closure, and telemetry feedback. This unnecessary expansion increases the attack surface and enables misuse of the skill as a generic AI/vision broker, including access to sensitive image, audio, and document processing workflows unrelated to the declared function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The listed capabilities include facial attribute, action, quality, emotion, physical, and social classification features that are unrelated to the gateway purpose and process sensitive biometric inferences. In context, this makes the skill more dangerous because users and reviewers could reasonably expect only workflow-routing behavior, not covert access to emotion or attribute analysis.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The file exposes face recognition and person-identification capabilities such as political-figure, designated-person, and exhibit recognition without any justification tied to the gateway's declared workflows. These capabilities are highly sensitive because they can enable surveillance, identification, and downstream privacy harms if a broadly described gateway skill is used as cover for biometric processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This code sends sensitive API keys to telemetry via emitTelemetry on both the explicit-auth and bootstrap-success paths. Telemetry systems commonly have broader access, longer retention, and weaker secret-handling guarantees than primary auth stores, so exporting live credentials can lead to credential disclosure, account compromise, and downstream abuse if logs, dashboards, or processors are accessed by unauthorized parties.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill documents networked scripts, environment-controlled behavior, authentication bootstrap, file upload, and telemetry, but it does not declare any explicit tool scope or allowed-tools boundary. That omission weakens least-privilege controls and makes it easier for an agent runtime to grant broader env/network access than users or operators expect, increasing the blast radius if the skill or its dependencies are abused.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill describes best-effort telemetry and feedback submission, enabled by default, but does not present a clear user-facing disclosure of what data may be transmitted, when transmission occurs, or how to disable it. Because the same skill handles auth, execution, polling, feedback, and metadata fields like agent_uid and owner_uid_hint, this can lead to silent outbound data exposure and unexpected sharing of operational or user-derived information.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill documents automatic upload of local files referenced by file_path to a remote site, but does not prominently warn that local filesystem content may be transmitted externally. Because this gateway normalizes attachments and can auto-upload as part of normal execution, users may unintentionally send sensitive local data to a remote service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation states that telemetry and feedback are sent off-host and include runtime metadata such as agent_uid and owner_uid_hint, but it does not present a clear user-facing warning or explicit consent requirement. In a skill that acts as a gateway and performs networked operations by default, silent metadata exfiltration can expose operational identifiers and usage context to a remote service without the operator fully realizing it.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/telemetry.mjs:13

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/portal-auth.mjs:69

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
scripts/runtime-auth.mjs:157