Back to skill

Security audit

Free Mobile SMS

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says, but it sends SMS content and API credentials to Free Mobile using a riskier URL-query method and lacks explicit send-confirmation guidance.

Review before installing. Use this only for a Free Mobile account where you are comfortable giving the skill access to the SMS notification API key, require explicit confirmation before each send, avoid sending secrets in SMS messages, and prefer changing the implementation to POST before using it with real credentials.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/FreeMobile_sms.py:24
Finding

Sensitive API Credentials Transmitted in URL Query Parameters

Content
View full analysis

Vulnerability Details

File Location: scripts/FreeMobile_sms.py, lines 24–41
Vulnerability Type: Sensitive information exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

python
url = "https://smsapi.free-mobile.fr/sendmsg"

# Limite de longueur SMS
if len(message) > 160:
    print(f"Avertissement: message tronqué à 160 caractères", file=sys.stderr)
    message = message[:160]

params = {
    'user': user,
    'pass': api_key,
    'msg': message
}

try:
    response = requests.get(url, params=params, timeout=timeout)

Technical Analysis

The requests.get() call serializes user, pass, and msg into the request URL. Consequently, the Free Mobile subscriber identifier, API key, and SMS content become part of the URL query string.

HTTPS encrypts the URL while it is transmitted between the client and the HTTPS endpoint, but it does not prevent the complete URL from being retained by local HTTP debugging, application telemetry, exception-reporting systems, forward proxies, or server-side access logs. The bundled API reference explicitly states that the endpoint supports POST requests, so transmitting these sensitive values in the URL is unnecessary.

Exploitation requires access to infrastructure or diagnostics that capture complete request URLs. This finding does not establish that such logging currently exists, but the chosen request method unnecessarily expands the locations in which credentials may be exposed.

Attack Path

  1. A user invokes the Skill with valid FREEMOBILE_SMS_USER and FREEMOBILE_SMS_API_KEY environment variables.
  2. The script inserts those credentials and the message into query parameters.
  3. requests.get() constructs a URL containing user, pass, and msg.
  4. A logging, monitoring, debugging, proxy, or server component records the complete request URL.
  5. An attacker with access to those records extracts the subsc ...[truncated 638 chars]
Remediation
View remediation

Remediation Suggestions

Use the API's supported POST method so credentials and message content are not embedded in the URL:

python
response = requests.post(
    url,
    data={
        "user": user,
        "pass": api_key,
        "msg": message,
    },
    timeout=timeout,
)

In addition:

  1. Configure application, HTTP client, proxy, and observability tooling to redact user, pass, and msg.
  2. Never print or include the API key in exception messages or diagnostic output.
  3. Rotate the Free Mobile API key if a URL containing it may already have been logged.
  4. Restrict access to historical proxy, telemetry, and server logs and apply appropriate retention controls.
  5. Add a regression test confirming that credentials do not appear in the requested URL.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The script performs outbound network communication to the Free Mobile SMS API, but the finding indicates this network capability is not declared in permissions. Undeclared egress is dangerous because it allows a skill to transmit user-supplied content and secrets off-host without transparent authorization; here it sends SMS content and API credentials to a remote service. In a messaging skill this behavior is expected functionally, but it is still high-risk if not explicitly permissioned because it enables external data transfer.

Content

No source excerpt is available for this finding.

Lp1

High
Category
MCP Least Privilege
Confidence
98% confidence
Finding

The script performs outbound network communication to the Free Mobile SMS API, but the finding indicates this network capability is not declared in permissions. Undeclared egress is dangerous because it allows a skill to transmit user-supplied content and secrets off-host without transparent authorization; here it sends SMS content and API credentials to a remote service. In a messaging skill this behavior is expected functionally, but it is still high-risk if not explicitly permissioned because it enables external data transfer.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The activation guidance is extremely broad: 'use this skill when you want to send an SMS to your human' can match many ordinary conversational requests and may cause an agent to select a networked, side-effecting action too eagerly. Because the skill sends outbound messages to a real subscriber number, accidental activation could disclose sensitive content or trigger unwanted external actions without sufficiently explicit user intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The configuration section lists credentials but does not clearly warn that message content and authentication data will be used in a network request to Free Mobile. In a skill that performs external communication, missing disclosure increases the risk that users or upstream agents unknowingly send sensitive information off-system or mishandle credentials.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This reference file presents all user-facing instructions exclusively in French, and there is no indication that the skill offers a language or locale choice. Under the policy rule for natural-language violations, forcing a specific language without user opt-in can be a violation unless the locale constraint is clearly documented and justified.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This code file contains natural-language content such as the module docstring, CLI help text, and runtime messages entirely in French. Under the policy rule, forcing a specific language without offering a user choice or documenting a justified locale restriction is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.