Back to skill

Security audit

Level5 - Your Agent Can Pay For Itself

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent for a paid LLM proxy, but it puts account and billing tokens directly in URLs that users and tools are told to save and reuse.

Install only if you are comfortable routing model prompts and responses through Level5 and treating the dashboard/proxy URL as a sensitive credential. Avoid using it for secrets or regulated data unless Level5 is approved for that data, and do not paste token-bearing URLs into logs, tickets, screenshots, or shared chats.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:54
Finding

Bearer API Token Exposed in URL Paths and Dashboard Links

Content
View full analysis
Remediation
View remediation
`. - Ensure query strings, fragments, and resource paths never contain bearer credentials. 2. **Use secure dashboard authentication** - Replace permanent token-bearing dashboard links with a normal login flow, an opaque secure session cookie, or a short-lived single-use bootstrap link. - Configure cookies with `Secure`, `HttpOnly`, and an appropriate `SameSite` policy. - Expire bootstrap links immediately after account setup. 3. **Minimize credential display** - Do not print or return complete tokens unless strictly necessary. - Show only a short fingerprint or masked value, such as the final four characters. - Update agent instructions so credentials are not reproduced in conversations, logs, screenshots, or support requests. 4. **Add credential lifecycle controls** - Provide token rotation and immediate revocation. - Allow separate scoped credentials for dashboard access, read-only billing queries, and paid proxy invocation. - Prefer short-lived tokens with narrowly defined permissions. 5. **Harden logging and telemetry** - Redact existing token-shaped path segments from application, proxy, CDN, analytics, tracing, and error logs. - Prevent SDK diagnostics from recording authorization material. - Review historical logs for exposed tokens and rotate any affected credentials. 6. **Protect sensitive prompt traffic** - Continue requiring explicit user consent before proxy activation. - Present clear privacy, retention, and subprocessors disclosures before prompts are sent through Level5. - Warn users not to send secrets or regulated data unless the service is approved for that data class. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (15)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill prominently describes Level5 as a billing proxy but does not provide an upfront, explicit privacy warning that user prompts, completions, and possibly sensitive model traffic will be routed through a third-party service. Because this proxy sits in the path of all LLM requests, users may unknowingly send confidential data to an external provider, creating privacy, compliance, and data-handling risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The presence of a hardcoded external endpoint in executable example code reflects real outbound communication to a third-party service. In this skill's context, that endpoint is central to registration and billing, so use of it can expose metadata, create accounts, and obtain tokens tied to a user's billing workflow.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
Only call this after the user has explicitly confirmed they want to proceed.
    No files are written. The dashboard URL is displayed for the user to save.
    """
    reg = requests.post("https://api.level5.cloud/v1/register", timeout=10).json()
    api_token = reg["api_token"]
    dashboard_url = f"https://level5.cloud/dashboard/{api_token}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The presence of a hardcoded external endpoint in executable example code reflects real outbound communication to a third-party service. In this skill's context, that endpoint is central to registration and billing, so use of it can expose metadata, create accounts, and obtain tokens tied to a user's billing workflow.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
Only call this after the user has explicitly confirmed they want to proceed.
    No files are written. The dashboard URL is displayed for the user to save.
    """
    reg = requests.post("https://api.level5.cloud/v1/register", timeout=10).json()
    api_token = reg["api_token"]
    dashboard_url = f"https://level5.cloud/dashboard/{api_token}"

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

Step 1: Register

bash
curl -X POST https://api.level5.cloud/v1/register

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

Step 1: Register

bash
curl -X POST https://api.level5.cloud/v1/register

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

Step 1: Register

bash
curl -X POST https://api.level5.cloud/v1/register

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

Step 1: Register

bash
curl -X POST https://api.level5.cloud/v1/register

Response:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

GET /health

bash
curl https://api.level5.cloud/health

Response (healthy): HTTP 200

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This documented endpoint places the API token directly in the URL path when checking balance. Tokens in URLs are prone to leakage through logs, browser history, referrers, monitoring systems, and reverse proxies, which can expose account access and billing information.

Content

Scanner excerpt · SKILL.md (reported line 293)May include surrounding context.

GET /proxy/{api_token}/balance

bash
curl https://api.level5.cloud/proxy/{YOUR_API_TOKEN}/balance

Response: HTTP 200

External Transmission

Medium
Category
Data Exfiltration
Confidence
92% confidence
Finding

This transactions endpoint also embeds the API token in the URL path, risking credential disclosure via logs and telemetry. Because transaction history can reveal spending patterns and usage metadata, exposure of the token could lead to account misuse and privacy loss.

Content

Scanner excerpt · SKILL.md (reported line 312)May include surrounding context.

GET /proxy/{api_token}/transactions

bash
curl "https://api.level5.cloud/proxy/{YOUR_API_TOKEN}/transactions?page=1&limit=50"

Response: HTTP 200

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This proxy endpoint routes actual model prompts and responses through a third-party service and includes the API token in the URL path. That combination increases risk substantially: confidential LLM traffic is transmitted externally, and the credential can leak via infrastructure logs while the proxy gains visibility into user content.

Content

Scanner excerpt · SKILL.md (reported line 357)May include surrounding context.

Anthropic-compatible. Supports streaming (stream: true) and non-streaming.

bash
curl https://api.level5.cloud/proxy/{YOUR_API_TOKEN}/v1/messages \
  -H "Content-Type: application/json" \
  -d '{
    "model": "claude-sonnet-4-6",

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This endpoint proxies OpenAI-format completions through Level5, meaning user prompts and model outputs transit an external billing service. Because the token is part of the URL, there is additional credential leakage risk, and the proxy architecture creates material privacy and compliance concerns if users are not clearly informed.

Content

Scanner excerpt · SKILL.md (reported line 379)May include surrounding context.

OpenAI-compatible. Supports streaming and non-streaming.

bash
curl https://api.level5.cloud/proxy/{YOUR_API_TOKEN}/v1/chat/completions \
  -H "Content-Type: application/json" \
  -d '{
    "model": "gpt-4o",

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This SDK example configures an Anthropic client to send all requests through the Level5 proxy using a token-bearing base URL. In practice, that reroutes model traffic to a third party and risks secret leakage through URL logging, making it more dangerous than a simple informational API call.

Content

Scanner excerpt · SKILL.md (reported line 430)May include surrounding context.

md
import anthropic

client = anthropic.Anthropic(
    base_url="https://api.level5.cloud/proxy/{YOUR_API_TOKEN}",
    api_key="level5",
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This OpenAI SDK example similarly configures a client to proxy all chat completions through Level5 via a URL containing the API token. That exposes both privacy risk from third-party traffic inspection and credential leakage risk from token-in-URL design.

Content

Scanner excerpt · SKILL.md (reported line 448)May include surrounding context.

md
from openai import OpenAI

client = OpenAI(
    base_url="https://api.level5.cloud/proxy/{YOUR_API_TOKEN}/v1",
    api_key="level5",
)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

This example builds the proxy base URL dynamically from the returned api_token, reinforcing a pattern where a sensitive credential is embedded in URLs and then used for all model traffic. If logged or copied, that URL can function as an access token while also channeling potentially sensitive AI interactions through a third-party service.

Content

Scanner excerpt · SKILL.md (reported line 469)May include surrounding context.

import anthropic client = anthropic.Anthropic( base_url=f"https://api.level5.cloud/proxy/{api_token}", api_key="level5", )

text

Static analysis

No suspicious patterns detected.