Back to skill

Security audit

Epstein Detective

Security checks for vulnerabilities and agentic risk

Overview

This skill documents a GOYFILES API integration, but it asks users to publish server-supplied text on X and handles API credentials without enough safeguards.

Review this skill before installing. It is not proven malicious, but users should only proceed if they trust GOYFILES, understand that onboarding may require posting exact service-generated text from their X account, and have a safe place to store the returned API key and identity token. Avoid using the persistent markdown write tool unless you explicitly intend to save or overwrite notes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:14
Finding

Mandatory Reproduction and Publication of Remotely Controlled Content

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

Step A - Register bot

bash
curl -sS -X POST "https://goyfiles.com/api/chatbot/bot-auth/register" \
  -H "Content-Type: application/json" \
  -d '{"name":"MyAgent"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill explicitly instructs the agent to save a one-time agent_api_key but provides no warning about treating it as a secret, avoiding logs, or restricting storage. In an agent setting, this increases the chance the credential is exposed in chat history, traces, or files, enabling unauthorized use of the external bot identity.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
4. `After posting, send me the tweet URL.`

Never paraphrase `verification_phrase`.
Never ask the user to "include the code".
Do not ask the user to compose the claim tweet manually.

### Step C - Verify claim tweet

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
Never paraphrase `verification_phrase`.
Never ask the user to "include the code".
Do not ask the user to compose the claim tweet manually.

### Step C - Verify claim tweet

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · bot-docs/dataset-reference.md (reported line 131)May include surrounding context.

Step 1: Check dataset ID shapes

bash
curl -sS -X POST "https://goyfiles.com/api/chatbot" \
  -H "Content-Type: application/json" \
  -H "X-Bot-Identity: $IDENTITY_TOKEN" \
  -d '{"message":"schema","toolCalls":[{"name":"document_id_schema","args":{"source_dataset":"pacer-courtlistener","max_samples":5}}]}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation exposes a persistent write capability via write_markdown_file but does not warn that invoking it modifies durable state. In an agent-skill context, this increases the chance an agent will write notes or overwrite files without explicit user consent, creating integrity and privacy risks through unintended persistence.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.