Back to skill

Security audit

PanchangaAPI — Vedic Astrology

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent astrology API integration, but it encourages automatic paid requests and exposes reusable API keys in payment URLs.

Install only if you are comfortable sending astrology inputs such as birth date, time, and location to api.moon-bot.cc. Do not let an agent auto-pay or create payment links unless you have explicitly approved the amount and account, and avoid putting reusable API keys in URLs or Telegram links.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:365
Finding

Reusable API Key Exposed in Checkout URLs and Telegram Deep Links

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 365-396
Vulnerability Type: Credential exposure through URL paths and third-party deep links
Risk Level: High

Vulnerable Code

markdown
| **NOWPayments crypto** | `/checkout/{api_key}/{credits}` — 350+ coins (BTC, ETH, USDT, SOL, ...). Packages: 100/$3, 500/$15, 1000/$30, 5000/$150. | Any cryptocurrency |
markdown
https://t.me/vastr_bot?start=pay_{api_key}_{stars}
markdown
GET https://api.moon-bot.cc/checkout/{api_key}/{credits}

Technical Analysis

The Skill instructs agents to place a reusable API key directly into URL paths and Telegram deep-link parameters. This conflicts with the safer authentication pattern documented elsewhere in the same file, where the key is transmitted in the X-API-Key request header.

URLs are commonly retained or processed by:

  • Browser history and synchronized browsing data
  • Web server, reverse-proxy, CDN, and API gateway access logs
  • Monitoring, analytics, and error-reporting systems
  • Messaging platforms and automatic link-preview services
  • Network security products and endpoint telemetry
  • Screenshots, copied messages, support records, and chat exports

The Telegram payment flow additionally sends the API key to t.me and exposes it in a user-visible message. Because the documentation states that the same API key is used in the X-API-Key header for authenticated API requests, disclosure may allow replay outside the intended payment transaction.

Credential transmission is necessary for authenticated API access, but embedding a reusable credential in a URL is not the minimum privilege required. A short-lived, single-purpose payment token would provide the required account association without disclosing the primary API credential.

Attack Path

  1. An agent obtains or registers a valid PANCHANGA_API_KEY.
  2. Following the Skill instructions, the agent substitutes t ...[truncated 1450 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the API key from all URL paths, query parameters, Telegram deep links, and user-visible messages.
  2. Authenticate checkout creation through an HTTPS request carrying the key in an Authorization or X-API-Key header.
  3. Have the server return a cryptographically random payment-session token that is:
    • Single-purpose and usable only for payment
    • Bound to the intended account, payment amount, and credit quantity
    • Short-lived and automatically expired
    • Single-use and invalidated after successful payment
    • Insufficient to call ordinary authenticated API endpoints
  4. Put only this restricted payment-session token in Telegram or checkout URLs.
  5. Redact credentials and payment tokens from application, proxy, CDN, analytics, and monitoring logs.
  6. Disable automatic link previews for sensitive payment links where supported.
  7. Rotate API keys previously placed in these URLs and provide users with a documented revocation mechanism.
  8. Monitor for replay, anomalous credit consumption, and use of API keys from unexpected clients or locations.
  9. Update all examples to use a flow such as:
http
POST /checkout
X-API-Key: pnc_REDACTED
Content-Type: application/json

{"credits": 1000}

The response should contain a restricted checkout URL that does not reveal the reusable API key.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (15)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
All calculations use Lahiri ayanamsha and sidereal zodiac.
homepage: "https://api.moon-bot.cc"
author: moon-bot
privacy: "https://api.moon-bot.cc/terms"
contact: "api@moon-bot.cc"
tags:
  - astrology

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 35)May include surrounding context.

md
All calculations use Lahiri ayanamsha and sidereal zodiac.
homepage: "https://api.moon-bot.cc"
author: moon-bot
privacy: "https://api.moon-bot.cc/terms"
contact: "api@moon-bot.cc"
tags:
  - astrology

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 39)May include surrounding context.

md
All calculations use Lahiri ayanamsha and sidereal zodiac.
homepage: "https://api.moon-bot.cc"
author: moon-bot
privacy: "https://api.moon-bot.cc/terms"
contact: "api@moon-bot.cc"
tags:
  - astrology

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This is an operational instruction to perform an external registration request, not just metadata. It can trigger third-party account creation and later collection of identifiers, so it is a real outbound data-flow risk in an agent setting.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

If you have PANCHANGA_API_KEY, use it. If not, register first:

bash
curl -s -X POST https://api.moon-bot.cc/register \
  -H "Content-Type: application/json" -d '{}'

This returns {"api_key": "pnc_..."}. Use it in all requests as X-API-Key header.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

This is an operational instruction to perform an external registration request, not just metadata. It can trigger third-party account creation and later collection of identifiers, so it is a real outbound data-flow risk in an agent setting.

Content

Scanner excerpt · SKILL.md (reported line 59)May include surrounding context.

If you have PANCHANGA_API_KEY, use it. If not, register first:

bash
curl -s -X POST https://api.moon-bot.cc/register \
  -H "Content-Type: application/json" -d '{}'

This returns {"api_key": "pnc_..."}. Use it in all requests as X-API-Key header.

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This request sends a datetime and exact coordinates to the external service. Because this skill centers on highly personal astrology use cases, the surrounding context increases sensitivity: the same fields may correspond to current or birth location and time, which are personal data and should not be silently exported.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

Making Requests

bash
curl -s -X POST https://api.moon-bot.cc/panchanga \
  -H "X-API-Key: YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"datetime": "2026-03-15T12:00:00+05:30", "latitude": 28.6139, "longitude": 77.2090}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill encourages sending highly sensitive personal data such as birth datetime and location to a third-party astrology API, but it does not provide a clear, prominent privacy warning or require explicit user consent before transmission. In this context, those fields can reveal intimate profile information and are sufficient for building personal dossiers, so silent transmission is a real privacy risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

This registration example explicitly sends an email address to the third-party API. That is a direct transmission of personal contact information, and the skill does not foreground privacy implications or retention practices before instructing the agent to do it.

Content

Scanner excerpt · SKILL.md (reported line 242)May include surrounding context.

Step 1: Register

bash
POST https://api.moon-bot.cc/register
Content-Type: application/json

{"email": "user@example.com"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
78% confidence
Finding

Polling the external registration status endpoint is a real outbound interaction, but by itself it transmits less sensitive information than birth data or email; the main concern is continued reliance on a third-party registration/account flow. The risk is lower here because the call primarily uses an account identifier rather than rich personal data.

Content

Scanner excerpt · SKILL.md (reported line 255)May include surrounding context.

User receives an email with a verification button. After clicking it:

bash
GET https://api.moon-bot.cc/register/status/acc_...

Response: {"status": "verified", "api_key": "pnc_..."}

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This example operationalizes sharing user time/location data with the provider. In the skill's context, that data is used for horoscope outputs and may correspond to birth details, increasing privacy sensitivity and making the external transmission materially risky.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

Step 3: Use

bash
curl -X POST https://api.moon-bot.cc/panchanga \
  -H "X-API-Key: pnc_..." \
  -H "Content-Type: application/json" \
  -d '{"datetime": "2024-01-15T06:00:00+05:30", "latitude": 28.6139, "longitude": 77.2090}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This example operationalizes sharing user time/location data with the provider. In the skill's context, that data is used for horoscope outputs and may correspond to birth details, increasing privacy sensitivity and making the external transmission materially risky.

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

Step 3: Use

bash
curl -X POST https://api.moon-bot.cc/panchanga \
  -H "X-API-Key: pnc_..." \
  -H "Content-Type: application/json" \
  -d '{"datetime": "2024-01-15T06:00:00+05:30", "latitude": 28.6139, "longitude": 77.2090}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This repeated example continues to normalize sending exact location and time to the external API. Repetition across the skill raises the likelihood that an agent will transmit sensitive values by default without pausing for user approval.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

bash
# Get today's Panchanga for Delhi
curl -X POST https://api.moon-bot.cc/panchanga \
  -H "X-API-Key: pnc_YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"datetime": "2024-01-15T06:00:00+05:30", "latitude": 28.6139, "longitude": 77.2090}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

This repeated example continues to normalize sending exact location and time to the external API. Repetition across the skill raises the likelihood that an agent will transmit sensitive values by default without pausing for user approval.

Content

Scanner excerpt · SKILL.md (reported line 334)May include surrounding context.

bash
# Get today's Panchanga for Delhi
curl -X POST https://api.moon-bot.cc/panchanga \
  -H "X-API-Key: pnc_YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"datetime": "2024-01-15T06:00:00+05:30", "latitude": 28.6139, "longitude": 77.2090}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

The birth chart example sends a full birth datetime and precise coordinates to the third-party service, which is especially sensitive in this domain because it is core personal data used to derive intimate astrological profiling. This is more dangerous than generic API traffic because the skill explicitly markets deep personal analysis from that data.

Content

Scanner excerpt · SKILL.md (reported line 340)May include surrounding context.

md
-d '{"datetime": "2024-01-15T06:00:00+05:30", "latitude": 28.6139, "longitude": 77.2090}'

# Get a complete birth chart
curl -X POST https://api.moon-bot.cc/kundali \
  -H "X-API-Key: pnc_YOUR_KEY" \
  -H "Content-Type: application/json" \
  -d '{"datetime": "1990-05-15T10:30:00+05:30", "latitude": 28.6139, "longitude": 77.2090}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
74% confidence
Finding

This checkout URL exposes the API key in the request path, which may be logged by browsers, proxies, analytics, and server access logs. While this is more of an insecure API design/documentation issue than data exfiltration from the agent, embedding secrets in URLs is a real credential-handling weakness.

Content

Scanner excerpt · SKILL.md (reported line 396)May include surrounding context.

Create a checkout invoice for any amount of credits:

text
GET https://api.moon-bot.cc/checkout/{api_key}/{credits}

Example: GET /checkout/pnc_abc123/1000 creates a $10 invoice for 1000 credits.

Static analysis

No suspicious patterns detected.