Back to skill

Security audit

ZapYeti

Security checks for vulnerabilities and agentic risk

Overview

This ZapYeti skill is mostly transparent, but it gives an agent broad financial-account API access without clear limits or confirmations.

Install only if you trust the publisher and are comfortable giving an agent API-key access to sensitive ZapYeti financial data. Use a narrowly scoped ZapYeti API key if available, avoid admin-capable keys, require explicit confirmation before exports, deletes, account changes, API-key changes, SimpleFin sync, or social posting, and rotate the key if command-line process logging may expose it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/zy_api.sh:24
Finding

API Key Exposed Through the curl Process Command Line

Content
View full analysis

Vulnerability Details

File Location: scripts/zy_api.sh, lines 24-35
Vulnerability Type: Credential exposure through process arguments
Risk Level: Medium

Vulnerable Code

bash
CURL_ARGS=(
  -s -w "\n%{http_code}"
  -X "$METHOD"
  -H "X-API-Key: ${ZAPYETI_API_KEY}"
  -H "Content-Type: application/json"
)

if [ -n "$BODY" ]; then
  CURL_ARGS+=(-d "$BODY")
fi

RESPONSE=$(curl "${CURL_ARGS[@]}" "${BASE_URL}${PATH_ARG}")

Technical Analysis

The script expands ZAPYETI_API_KEY into the argument supplied to curl through the -H option. Consequently, the resulting curl process receives an argument equivalent to:

text
X-API-Key: sensitive-key-value

On systems where process arguments are visible through process-monitoring utilities or process metadata interfaces such as /proc, another local user or monitoring component may capture the key while curl is running. Although the exposure window is limited to the lifetime of the curl process, repeated API calls increase the opportunity for observation. Long-running requests can further extend that window.

Exploitability depends on the operating system's process-visibility controls and the attacker's ability to observe other processes. This issue does not by itself grant local code execution or elevated operating-system privileges.

Attack Path

  1. A victim configures a valid ZAPYETI_API_KEY and invokes scripts/zy_api.sh.
  2. The script interpolates the key into curl's X-API-Key command-line argument.
  3. A local attacker or process-monitoring service observes curl's arguments while the request is active.
  4. The attacker extracts the API key from the visible header argument.
  5. The attacker submits requests directly to https://api.zapyeti.com using the stolen key.
  6. The attacker can access or modify resources permitted by that key until it is revoked or expires.

Impact Assessment

Successful exploitation ...[truncated 654 chars]

Remediation
View remediation

Remediation Suggestions

Avoid placing sensitive header values directly in curl's command-line arguments.

Prefer a protected, short-lived curl configuration file supplied through standard input, so the secret does not appear in process arguments:

bash
RESPONSE=$(
  {
    printf 'header = "X-API-Key: %s"\n' "$ZAPYETI_API_KEY"
    printf 'header = "Content-Type: application/json"\n'
  } | curl --config - \
      -sS \
      -w $'\n%{http_code}' \
      -X "$METHOD" \
      ${BODY:+--data "$BODY"} \
      "${BASE_URL}${PATH_ARG}"
)

Because conditional array handling is safer than shell parameter expansion for the body, the implementation should ideally retain an argument array for non-secret options and pass only the secret configuration through standard input. Additional hardening should include:

  • Ensure the secret is never printed in normal output, debug traces, or error logs.
  • Explicitly disable shell tracing around credential handling if callers might enable set -x.
  • Apply restrictive process-visibility controls, such as an appropriately configured /proc mount, as defense in depth.
  • Use narrowly scoped API keys with the minimum required permissions.
  • Support key expiration and rotation.
  • Revoke and replace any key suspected of having been exposed.
  • Review monitoring and telemetry systems to ensure they do not retain command-line arguments containing credentials.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (15)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
92% confidence
Finding

A delete-by-id debt endpoint is susceptible to parameter abuse in an agent context because the model may supply or be tricked into supplying an unintended identifier, causing irreversible deletion of the wrong debt record. Since debt tracking is user-facing and stateful, accidental or malicious invocation can directly corrupt financial records and user trust.

Content

Scanner excerpt · references/api.md (reported line 26)May include surrounding context.

md
- POST /api/debts/ (create)
- GET /api/debts/{id}
- PUT /api/debts/{id} (update)
- DELETE /api/debts/{id}
- POST /api/debts/bulk
- POST /api/debts/{id}/link-simplefin
- PATCH /api/debts/{id}/balance

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

Deleting payments by arbitrary ID creates a direct integrity risk because payment history is financially significant and users may rely on it for balances and payoff progress. In an agent workflow, identifier confusion or prompt injection could cause unauthorized or incorrect deletion of transaction records.

Content

Scanner excerpt · references/api.md (reported line 37)May include surrounding context.

md
- GET /api/payments/summary
- GET /api/payments/history
- GET /api/payments/{id}
- DELETE /api/payments/{id}

## Users
- GET /api/users/me

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
97% confidence
Finding

Account deletion is a highly destructive action that can remove access to financial data, integrations, and history, making arbitrary parameter or prompt-driven invocation extremely dangerous. In the context of a debt-management skill, this is far more sensitive than routine data retrieval and could lead to irrecoverable user harm.

Content

Scanner excerpt · references/api.md (reported line 52)May include surrounding context.

md
- PUT /api/settings/profile
- GET /api/settings/export
- GET /api/settings/export/csv
- DELETE /api/settings/account

## SimpleFin
- GET /api/simplefin/status

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

API key deletion by ID can disrupt integrations, revoke legitimate automation, or be abused to lock out users or services. In an agent setting, arbitrary identifier handling and overbroad authority make this endpoint especially risky when it is unrelated to the skill's advertised purpose.

Content

Scanner excerpt · references/api.md (reported line 81)May include surrounding context.

md
## API Keys
- GET /api/apikeys
- POST /api/apikeys
- DELETE /api/apikeys/{id}

## Admin
- GET /api/admin/dashboard

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Admin endpoints are especially dangerous because they imply privileged operations such as global sync, dashboard access, and user-targeted administrative actions that are unrelated to an end-user debt assistant. If reachable by the skill or implied as in-scope, they create a severe risk of privilege escalation, cross-tenant access, and platform-wide impact.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill exposes shell execution capability through documented script usage but does not declare any explicit tool scope or permission boundaries. This creates a mismatch between what the skill can do and what reviewers or enforcement systems can verify, increasing the risk of unintended command execution or overly broad agent behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The description says to use the skill when the user asks about 'ZapYeti data, debt tracking, payoff progress, payment history, or debt plan management,' which is a wide natural-language scope without explicit trigger constraints or exclusions. This can cause unintended invocation for general debt-management conversations rather than clear ZapYeti-specific requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill explicitly supports data export endpoints but does not warn that these operations may retrieve sensitive financial data. In a financial context, missing disclosure and safeguards around export features increases the chance of accidental exfiltration of personal or account data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The documentation points users to a broader API surface including social features and admin endpoints that exceed the stated debt-management purpose of the skill. That scope expansion can lead an agent to access or expose privileged or unrelated functionality, especially if the API key has wider permissions than expected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented API surface materially exceeds the skill's declared purpose of debt tracking and payoff management, including user lifecycle, social, API key, and admin capabilities. In an agent context, exposing broad undocumented authority increases the chance of prompt-driven misuse, over-privileged actions, and data access beyond user expectations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Account registration, password reset, email verification, and session-management endpoints go beyond a simple data-access skill and create opportunities for identity, session, and account-state manipulation. In an agent setting, these flows are sensitive because they can be triggered through ambiguous prompts or used to interfere with account access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The reference lists destructive and sensitive endpoints such as delete, sync, account, API key, and admin operations without cautionary notes, approval requirements, or safety guidance. In agent ecosystems, lack of contextual warnings can normalize dangerous operations and increase the likelihood of unsafe invocation from routine user prompts.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Social/community endpoints are outside the declared scope and introduce additional write actions, profile data handling, feeds, reactions, and group interactions not required for debt tracking. This broadens the attack surface and raises privacy and reputational risks if an agent is induced to post, join, or expose social content unexpectedly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

API key management is highly sensitive and not justified by the stated debt-management use case. Exposing key creation or deletion through a general-purpose skill can enable credential proliferation, persistence, revocation of legitimate access, or compromise of downstream integrations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

This shell script sends requests and optional JSON bodies to an external API via curl, which may transmit user or system data off-host. While the file name and examples imply API usage, the script does not include any explicit warning, confirmation, or user-facing notice about network transmission or the sensitivity of the provided body data.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.