Back to skill

Security audit

Send Usms Uspeedo

Security checks for vulnerabilities and agentic risk

Overview

This skill transparently sends SMS through uspeedo using user-provided API keys; the main caution is to verify consent, recipients, and costs before sending.

Install only if you intend to let the agent send SMS through your uspeedo account. Keep the access key secret out of chat, logs, and shell history; review the recipient list, message body, SMS type, and expected cost before each send, especially for batch or marketing messages, and only message recipients where you have proper consent and legal authorization.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 34)May include surrounding context.

md
Before sending, check environment variables. When not configured, guide the user as follows:

**1. When `USPEEDO_ACCESSKEY_ID` or `USPEEDO_ACCESSKEY_SECRET` is not set, or there is no .env / no environment variables**

Tell the user to follow these steps directly. **After giving this guidance, stop—do not perform sending or any further steps**:

Credential Access

High
Category
Privilege Escalation
Confidence
72% confidence
Finding

The workflow explicitly tells the agent to read access key credentials from the environment and use them to construct an Authorization header. Although this is operationally necessary, it is still a sensitive credential-use pattern that becomes dangerous if agent tooling, logs, traces, or error messages expose the secrets during execution.

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
## Workflow

1. **Pre-check**: If `USPEEDO_ACCESSKEY_ID` or `USPEEDO_ACCESSKEY_SECRET` is not set, or there is no .env / no environment variables, follow “Pre-checks and User Guidance” item 1 and stop. If the user is sending a type that has no template ID configured (e.g. verification but `USPEEDO_TEMPLATE_ID_VERIFICATION` not set), follow item 2.
2. Confirm SMS type (verification / notification / marketing) and choose the corresponding template ID env var.
3. Read `USPEEDO_ACCESSKEY_ID`, `USPEEDO_ACCESSKEY_SECRET`, the chosen template ID, and optional `USPEEDO_SENDER_ID` from env. Set header `Authorization: Basic base64(ACCESSKEY_ID:ACCESSKEY_SECRET)` and POST to `https://api.uspeedo.com/api/v1/usms/SendBatchUSMSMessage`.
4. Build `TemplateParams` (for full-variable template, the full SMS content). Format phone in international form (with country/region code) if needed.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill supports batch and marketing SMS but does not warn about operational, legal, and reputational consequences of bulk or promotional messaging. Without clear guidance, a user could misuse the skill for spam or non-compliant outreach, leading to account suspension, carrier blocking, or regulatory issues.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill supports batch and marketing SMS but does not warn about operational, legal, and reputational consequences of bulk or promotional messaging. Without clear guidance, a user could misuse the skill for spam or non-compliant outreach, leading to account suspension, carrier blocking, or regulatory issues.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

This instruction explicitly sends message content and recipient phone numbers to an external API endpoint. External transmission is expected for an SMS skill, but it remains security-relevant because it exposes user-supplied data to a third party and uses credentials that could be mishandled if surrounding controls are weak.

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
## Request

- **URL**: `POST https://api.uspeedo.com/api/v1/usms/SendBatchUSMSMessage`
- **Content-Type**: `application/json`
- **Auth**: Header `Authorization: Basic base64(ACCESSKEY_ID:ACCESSKEY_SECRET)`. Base64-encode `USPEEDO_ACCESSKEY_ID:USPEEDO_ACCESSKEY_SECRET` and set the header to `Basic <encoded_result>`.

External Transmission

Medium
Category
Data Exfiltration
Confidence
82% confidence
Finding

The curl example demonstrates transmitting SMS payloads and authentication material to an external service, which can normalize direct command-line handling of secrets. While the endpoint usage is core to the skill, shell examples increase accidental exposure risk through shell history, process inspection, or copied commands with real credentials.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

curl:

bash
curl -X POST "https://api.uspeedo.com/api/v1/usms/SendBatchUSMSMessage" \
  -H "Content-Type: application/json" \
  -H "Authorization: Basic $(echo -n 'YOUR_ACCESSKEY_ID:YOUR_ACCESSKEY_SECRET' | base64)" \
  -d '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
84% confidence
Finding

The workflow instructs the agent to read credentials and send content to a third-party API, which is functionally necessary but still a genuine data exfiltration path from the local environment to an external provider. In context, the danger is not hidden malice but insufficient disclosure and control around what data leaves the system.

Content

Scanner excerpt · SKILL.md (reported line 111)May include surrounding context.

md
1. **Pre-check**: If `USPEEDO_ACCESSKEY_ID` or `USPEEDO_ACCESSKEY_SECRET` is not set, or there is no .env / no environment variables, follow “Pre-checks and User Guidance” item 1 and stop. If the user is sending a type that has no template ID configured (e.g. verification but `USPEEDO_TEMPLATE_ID_VERIFICATION` not set), follow item 2.
2. Confirm SMS type (verification / notification / marketing) and choose the corresponding template ID env var.
3. Read `USPEEDO_ACCESSKEY_ID`, `USPEEDO_ACCESSKEY_SECRET`, the chosen template ID, and optional `USPEEDO_SENDER_ID` from env. Set header `Authorization: Basic base64(ACCESSKEY_ID:ACCESSKEY_SECRET)` and POST to `https://api.uspeedo.com/api/v1/usms/SendBatchUSMSMessage`.
4. Build `TemplateParams` (for full-variable template, the full SMS content). Format phone in international form (with country/region code) if needed.
5. Send the POST, parse `RetCode` and `Message`, and report success or failure. On error codes, see “Common errors” below.

Static analysis

No suspicious patterns detected.