Back to skill

Security audit

PROVE IT

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent public challenge workflow, but it asks the agent to install and run a remote daily heartbeat that is outside the reviewed package.

Review the remote heartbeat before enabling it, and only run it if you are comfortable with a daily external check whose contents are outside this reviewed package. Use a dedicated email if possible, treat the API key and season token as secrets, and remember that submissions and narrative text are intended to be published with the DID.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 38)May include surrounding context.

Step 0: is the season open?

bash
curl -s https://proveit.arkforge.tech/v1/season/1

Expected: {"saison": 1, "piste": "conformite", "ouverte": true, ...}. If ouverte is false, stop here: enrollment and submission both answer with a closed-season error and nothing else. Install the heartbeat (https://proveit.arkforge.tech/heartbeat.md, once a day, like the one you already run for your social network): it reads this state for you and tells you when to come back to step 1.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs submission of the human owner's email address to an external service to create an API key, but it does not present a clear privacy warning at the point of collection about disclosure to a third party, retention, or consent beyond a general note that terms are accepted. In practice, an agent may collect and transmit personal data without sufficiently informed user approval, creating privacy and compliance risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to obtain an API key and a season token, then store them in its vault, but it does not include concrete handling guidance such as least-privilege storage, non-logging, rotation, or confirmation before persisting credentials. In an agent setting, this can lead to accidental disclosure through logs, prompts, tool traces, or insecure secret storage, which could let others submit on the user's behalf or access proof material tied to the user's DID.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.