Back to skill

Security audit

Agent Metaverse

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed virtual trading skill, but it needs review because an agent can immediately change a virtual exchange account and send its API key to a configurable server without strong safeguards.

Review before installing. Use this only for a virtual exchange account you are willing to let an agent modify, keep AGENT_METAVERSE_BASE_URL on localhost or a trusted HTTPS endpoint, treat registration output as a secret, and impose your own trade size, leverage, and approval limits before running autonomous strategies.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/skill.py:9
Finding

API Key Can Be Transmitted over Plaintext HTTP

Content
View full analysis
httpx.Client: headers = {} if API_KEY: headers["X-API-Key"] = API_KEY return httpx.Client(base_url=BASE_URL, headers=headers, timeout=30.0) ``` ### Technical Analysis The exchange base URL is read from the user-controlled `AGENT_METAVERSE_BASE_URL` environment variable without validating its scheme or destination. The HTTP client then automatically adds the `X-API-Key` header to authenticated requests. Although the default `http://localhost:8000` endpoint is reasonable for local development, the client also accepts a remote URL using plaintext HTTP. When that configuration is used, the API key and all request and response data are transmitted without TLS protection. A network adversary capable of observing traffic between the client and server could recover the key. A maliciously configured endpoint would also receive the credential directly. The documentation explicitly permits changing the base URL but does not warn users that authenticated commands should only use HTTPS for remote hosts. ### Attack Path 1. A user, deployment script, or compromised environment sets `AGENT_METAVERSE_BASE_URL` to a remote plaintext URL such as `http://exchange.example`. 2. The user sets `AGENT_METAVERSE_API_KEY` and invokes an authenticated command such as `balance`, `buy`, or `open-long`. 3. `_client()` attaches the API key to the `X-API-Key` request header. 4. The request travels over unencrypted HTTP. 5. A network observer, transparent proxy, or malicious endpoint captures the API key. 6. The attacker reuses the captured key against the exchange API to access the as ...[truncated 684 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/skill.py:34
Finding

Registration Duplicates the API Key into Standard Error Output

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (8)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 263)May include surrounding context.

text

DELETE /api/spot/orders/{order_id} Auth: Required Response: {"status": "cancelled"}

text

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill exposes multiple state-changing trading operations such as buy, sell, futures open/close, swaps, and order cancellation that execute immediately once invoked, with no confirmation prompt, dry-run mode, or user acknowledgement. In an agent setting, this creates a real risk of unintended or prompt-induced transactions, especially because the commands directly affect account balances and leveraged positions.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill advertises executable commands that use environment variables and network access, but it does not declare any explicit tool scope such as permissions or allowed-tools. That creates a governance gap: an agent may be allowed to invoke code and outbound requests more broadly than a reviewer or user expects, increasing the chance of unintended API use or secret handling.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill describes commands that place orders, open leveraged positions, cancel orders, and close positions, but it does not prominently warn that these are state-changing actions affecting the user's portfolio. In an agent setting, missing transactional warnings can cause unsafe autonomous execution, especially because futures and swaps can quickly alter balances and risk exposure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The documentation includes privileged market-maker endpoints such as token minting and liquidity addition even though the stated skill purpose is ordinary trading. Exposing these elevated capabilities in the same skill increases the chance that an agent or integrator will discover and attempt sensitive functions that can manipulate simulated markets or bypass expected role boundaries.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The client automatically attaches the AGENT_METAVERSE_API_KEY as an X-API-Key header to whatever BASE_URL is configured, and the default transport is plain HTTP to localhost with no user-facing disclosure of where credentials are sent. If the base URL is changed to a non-local or intercepted endpoint, the key may be exposed to an unintended service or over an unencrypted channel.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
97% confidence
Finding

The dependency is specified as httpx>=0.28.0 without an upper bound or exact pin, which makes builds non-reproducible and allows future releases to be installed implicitly. That increases supply-chain risk and can unexpectedly introduce vulnerable or breaking versions into the skill at install time.

Content

Scanner excerpt · scripts/requirements.txt (reported line 1)May include surrounding context.

text
httpx>=0.28.0

Unverifiable Dependency: httpx has 2 known advisory(ies) (CVE-2021-41945 (Improper Input Validation in httpx); CVE-2021-41945 (Encode OSS httpx <=1.0.0.beta0 is affected by improper input validation in `http)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
89% confidence
Finding

Because httpx is not pinned, it is impossible to verify from this manifest alone which version will actually be installed, including whether an affected release with known advisories could be selected in some environments. This uncertainty is a supply-chain hygiene issue: while >=0.28.0 likely excludes the cited older vulnerable versions, the manifest still prevents reliable attestation of dependency safety and reproducibility.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.