Back to skill

Security audit

Taka

Security checks for vulnerabilities and agentic risk

Overview

This looks like a real Taka creative-management wrapper, but it should go through Review because it relies on an unpinned external CLI that handles login tokens and can modify or delete business creative content.

Install only if you trust the Taka npm package and the configured API endpoint. Prefer a pinned reviewed taka-cli version, avoid npx for login, verify TAKA_SERVER_URL before authenticating, use a limited Taka account where possible, and treat delete/update commands as potentially destructive until the CLI's confirmation and recovery behavior is clear.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:9
Finding

Unpinned Third-Party CLI Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:9-14; also present in HOW_TO_RUN.md:3-16, README.md:8-13, and QUICK_START.md:3-7
Vulnerability Type: Unpinned npm dependency and mutable supply-chain execution
Risk Level: Medium

Vulnerable code:

bash
## Install Taka CLI

```bash
npm install -g taka-cli

npm release: https://www.npmjs.com/package/taka-cli

text

`HOW_TO_RUN.md:3-16` additionally recommends direct unpinned execution:

```bash
## Option 1: Install from npm (Recommended)

```bash
npm install -g taka-cli

After installation, the taka command is available globally.

Option 2: npx (No Install)

bash
npx taka-cli --help
npx taka-cli login
npx taka-cli generate-image --prompt "sunset"

Technical Analysis

The project instructs users and AI agents to globally install or directly execute the latest available taka-cli npm release. It does not specify an exact audited version, integrity hash, lockfile, or other reproducible dependency constraint.

The actual CLI implementation is absent from the audited project. Therefore, the code that processes OTP input, stores authentication tokens, and communicates with remote services can change after this Skill package has been reviewed. The npx workflow is particularly sensitive because it can download and execute the currently resolved package without a persistent, previously inspected installation.

This does not establish that the current npm package is malicious. It creates a supply-chain trust boundary under which a compromised maintainer account, malicious replacement release, dependency compromise, or unexpected future package update could introduce arbitrary local code.

Attack Path

  1. An attacker compromises the npm package, a maintainer account, or a transitive dependency and publishes a malicious version under the existing package name.
  2. A user or agent follows the documented `npm insta ...[truncated 1147 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the CLI to a specific reviewed version, for example taka-cli@1.2.3, rather than resolving the latest release.
  2. Replace unpinned npx taka-cli commands with version-pinned invocation and disable automatic package resolution where practical.
  3. Prefer a project-local installation governed by a committed lockfile instead of global installation.
  4. Record and verify package integrity hashes and npm provenance attestations in the release process.
  5. Audit the CLI package and its transitive dependencies, especially installation scripts, authentication handling, token storage, and outbound network behavior.
  6. Run the CLI under a restricted user or sandbox with access only to files required for the creative task.
  7. Add an update-review process so a newly published CLI version is not automatically trusted merely because the Skill documentation remains unchanged.

T09 · Insecure Skill Coding Practices

Warning
Location
HOW_TO_RUN.md:48
Finding

Environment-Controlled Authentication Endpoint Can Redirect Sensitive Requests

Content
View full analysis

Vulnerability Details

File Location: HOW_TO_RUN.md:48-59; also documented in SKILL.md:71-77 and README.md:27-31
Vulnerability Type: Insufficiently constrained remote authentication endpoint
Risk Level: Medium

Vulnerable code:

bash
## Custom Server URL

By default, Taka CLI connects to `https://api.taka.ai/v1`.

To use a different server (staging, development, self-hosted):

```bash
# Set for current session
export TAKA_SERVER_URL=https://staging.api.taka.ai/v1

# Then login (URL is saved with credentials)
taka login
text

Related configuration in `SKILL.md:71-77`:

```markdown
**Environment Variables:**

| Variable | Required | Default | Description |
|----------|----------|---------|-------------|
| `TAKA_SERVER_URL` | No | `https://api.taka.ai/v1` | Custom API endpoint (for staging/dev) |

Credentials are saved to `~/.config/taka/config.json` with restricted permissions (owner-only read/write).

Technical Analysis

The documented authentication flow permits the API origin to be selected through the inherited TAKA_SERVER_URL environment variable. The instructions also state that the selected URL is saved with credentials. No documented control requires the production hostname, restricts custom endpoints to an allowlist, requires an explicit trust confirmation, or prevents existing session material from being used after an origin change.

HTTPS is used in the supplied example, but the documentation does not state that the CLI rejects plaintext URLs or validates custom hosts against trusted domains. Because the CLI source is not included, enforcement of TLS, origin-specific token separation, and certificate validation could not be verified.

In an automated agent, CI environment, shared shell, or wrapper process where environment variables can be influenced externally, this creates a risk that login and subsequent content requests will be directed to an unintended serv ...[truncated 1741 chars]

Remediation
View remediation

Remediation Suggestions

  1. Enforce HTTPS for every configured endpoint and reject plaintext or malformed URLs.
  2. Use an explicit allowlist of trusted production and staging hostnames.
  3. Require clear interactive confirmation before authenticating against any non-production origin, displaying the complete normalized URL.
  4. Do not silently inherit endpoint overrides for authentication in production or automated agent workflows.
  5. Bind credentials to the exact scheme, hostname, and port that issued them; never send existing tokens after the origin changes.
  6. Store production and development credentials in separate files or isolated profiles.
  7. Validate TLS certificates using the platform trust store and consider certificate pinning for high-assurance production use.
  8. Log the effective endpoint before login and each security-sensitive operation without logging OTP values or tokens.
  9. Update the documentation to warn that custom endpoints receive authentication and creative-content data.
  10. Publish or independently audit the CLI implementation to verify URL validation, TLS enforcement, token-origin binding, and secure credential storage.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (12)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · HOW_TO_RUN.md (reported line 66)May include surrounding context.

md
Taka CLI uses JWT access/refresh tokens. Tokens auto-refresh silently when expired.

- **Access token**: Short-lived, used for API requests
- **Refresh token**: Long-lived, used to get new access tokens
- Both are stored in `~/.config/taka/config.json` (mode 0o600, owner-only)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · HOW_TO_RUN.md (reported line 67)May include surrounding context.

md
Taka CLI uses JWT access/refresh tokens. Tokens auto-refresh silently when expired.

- **Access token**: Short-lived, used for API requests
- **Refresh token**: Long-lived, used to get new access tokens
- Both are stored in `~/.config/taka/config.json` (mode 0o600, owner-only)

You should rarely need to re-login. If auto-refresh fails:

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · HOW_TO_RUN.md (reported line 50)May include surrounding context.

md
## Custom Server URL

By default, Taka CLI connects to `https://api.taka.ai/v1`.

To use a different server (staging, development, self-hosted):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 113)May include surrounding context.

md
## Custom Server URL

By default, Taka CLI connects to `https://api.taka.ai/v1`.

To use a different server (staging, development, self-hosted):

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
## Custom Server URL

By default, Taka CLI connects to `https://api.taka.ai/v1`.

To use a different server (staging, development, self-hosted):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The markdown lists taka delete-creative --id <id> as an available command, but provides no warning that it deletes user content or whether the action is irreversible. For markdown files, destructive behavior that could affect user data should be accompanied by a clear warning about impact or recovery expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents taka delete-creative --id <creative-id> as a supported command but provides no warning that it removes user content, whether deletion is irreversible, or whether the CLI prompts for confirmation. For markdown files, destructive behaviors that may affect user data should be disclosed to the user.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

This shell script invokes taka commands to create a creative and build an email campaign, which likely send user-provided campaign content and metadata to a remote service. While the script has brief step comments, it provides no user-facing disclosure, confirmation, or warning that campaign data will be transmitted off-host.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

The taka generate-email-image command appears to perform a network operation using the supplied prompt and creative identifier, but the script gives no visible warning that this data may leave the local environment. There is also no confirmation prompt or user-facing log explaining the privacy implications of the generation step.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.