Back to skill

Security audit

Price Api

Security checks for vulnerabilities and agentic risk

Overview

This skill is a construction price helper that uses a disclosed FRED API call and user-provided cost data, with no hidden persistence or deceptive behavior found.

Before installing, be aware that the skill may make network requests to FRED and may include a FRED API key in request parameters. Use a limited API key, avoid logging full URLs, and validate or back up cost datasets before applying generated price updates to business records.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:76
Finding

API Credential Exposed Through URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 76-84
Vulnerability Type: API credential exposure through URL query parameters
Risk Level: Medium

python
params = {
    'series_id': series_id,
    'observation_start': start_date,
    'observation_end': end_date,
    'file_type': 'json'
}

if self.fred_api_key:
    params['api_key'] = self.fred_api_key

try:
    response = requests.get(self.FRED_BASE, params=params)

Technical Analysis

The optional FRED API key is added to the params dictionary passed to requests.get. The Requests library serializes these parameters into the request URL. Although the request uses HTTPS and is sent to the declared official FRED API endpoint, URL query strings can be recorded by HTTP client diagnostics, reverse proxies, monitoring systems, server access logs, browser-like debugging tools, and exception telemetry.

This behavior is directly related to the Skill's declared price-fetching functionality and is not evidence of covert exfiltration. However, transmitting credentials in URLs expands their potential exposure compared with authorization headers. If the FRED API requires query-string authentication, the residual risk should be documented and URL logging must be controlled.

Attack Path

  1. A user supplies a valid FRED API key when initializing OpenPriceAPI.
  2. The Skill places the credential in the api_key query parameter.
  3. requests.get serializes the key into the complete request URL.
  4. A proxy, server, diagnostic facility, or telemetry system records the URL.
  5. An attacker or unauthorized operator with access to those logs recovers the API key.
  6. The exposed key is used to make unauthorized FRED API requests under the user's account or quota.

Impact Assessment

Successful exploitation could disclose the supplied FRED API credential. The resulting access is limited to the permissions and quota associated with that ...[truncated 304 chars]

Remediation
View remediation

Remediation Suggestions

  1. Prefer an API-supported authorization header rather than a query parameter, if the FRED API supports such an authentication method.
  2. If the API mandates query-string authentication, explicitly document that the credential is transmitted to FRED in the URL.
  3. Disable verbose HTTP tracing in production and ensure application, proxy, monitoring, and exception logs redact the api_key parameter.
  4. Never include the final request URL or request parameters in user-visible errors.
  5. Retrieve the key from a protected secret store or environment variable rather than embedding it in source code or notebooks.
  6. Use a dedicated key with the minimum available privileges and quota, rotate it periodically, and revoke it immediately if log exposure is suspected.
  7. Where practical, isolate the FRED request behind a narrowly scoped client that enforces the expected hostname and credential-redaction policy.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:84
Finding

External HTTP Request Lacks a Timeout

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 84
Vulnerability Type: Unbounded external network request
Risk Level: Low

python
try:
    response = requests.get(self.FRED_BASE, params=params)
    if response.status_code != 200:
        return []

    data = response.json()
    observations = data.get('observations', [])

Technical Analysis

The call to requests.get does not specify a connection or response timeout. Requests does not impose a default timeout, so the operation may wait indefinitely when the remote service, DNS resolver, intermediary proxy, or network connection becomes unresponsive.

The network operation is necessary for the declared material-price retrieval functionality, and its destination is a fixed HTTPS endpoint rather than user-controlled input. Nevertheless, the lack of bounded waiting creates an availability weakness in agents or services that invoke this method.

Attack Path

  1. A user or automated workflow invokes get_fred_prices.
  2. The runtime attempts to connect to the configured FRED endpoint.
  3. The endpoint, DNS service, proxy, or network path accepts the connection but fails to complete the response.
  4. Because no timeout is configured, the worker remains blocked.
  5. Repeated concurrent invocations can consume available workers or execution slots and degrade service availability.

Impact Assessment

Exploitation can stall an individual Skill execution and, in a shared or concurrent deployment, contribute to worker exhaustion or denial of service. It does not grant filesystem access, credential access, code execution, elevated privileges, or persistence. The impact is limited primarily to availability and resource consumption within the process or service running the Skill.

Remediation
View remediation

Remediation Suggestions

  1. Set separate connection and read timeouts:
    python
    response = requests.get(
        self.FRED_BASE,
        params=params,
        timeout=(5, 30),
    )
    response.raise_for_status()
    
  2. Catch requests.exceptions.Timeout and requests.exceptions.RequestException explicitly rather than relying only on a broad exception handler.
  3. Add a limited retry policy with exponential backoff and jitter for transient failures.
  4. Cap the total retry duration so retries cannot recreate an unbounded wait.
  5. Reuse a configured requests.Session if the Skill performs frequent requests, with timeout and retry policies enforced centrally.
  6. Return a clear structured error or safely fall back to the documented estimator when live price data is unavailable.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

md
"""Client for open material price APIs."""

    # Commodity price sources
    FRED_BASE = "https://api.stlouisfed.org/fred/series/observations"

    # FRED Series IDs for construction commodities
    FRED_SERIES = {

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
87% confidence
Finding

This markdown file includes a use case explicitly labeled 'Update Cost Database' and shows calling update_cost_database, which modifies pricing fields and timestamps in the provided dataset. The surrounding documentation does not warn users that applying these updates can alter business cost records and should be reviewed before use.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
94% confidence
Finding

The instructions state the skill will fetch construction material prices from open APIs, but they do not warn the user that external network requests may occur or that project-related inputs could be sent to third-party services. This creates a transparency and privacy risk because users may provide sensitive cost or project context without realizing data could be transmitted outside the local environment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.