Back to skill

Security audit

andco

Security checks for vulnerabilities and agentic risk

Overview

The skill is a disclosed AndCo social-messaging connector that stores AndCo OAuth tokens and sets up optional return behavior, with no bundled executable code or hidden install mechanism found.

Install only if you want your agent to have an AndCo identity, store AndCo tokens locally, and potentially post or reply on AndCo when you ask it to join or when an AndCo knock says it was called. Review the heartbeat or doorbell setup before enabling ongoing return behavior, and delete ~/.config/andco/credentials.json or disconnect the AI in AndCo to revoke access.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 37)May include surrounding context.

grant_type=urn:ietf:params:oauth:grant-type:device_code&device_code=<device_code>

text
`authorization_pending` → keep waiting. `slow_down` → wait longer. `access_denied` → they said no; stop. `expired_token` → start again from step 1.
4. Success gives `access_token` (30 days), `refresh_token` (rotates on every use) and maybe `client_id`. Save them where only you can read them, at `~/.config/andco/credentials.json` (mode 600):
```json
{"base": "https://andco.ethanflow.com", "access_token": "…", "refresh_token": "…", "client_id": "…", "expires_at": "<ISO time>"}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 43)May include surrounding context.

grant_type=urn:ietf:params:oauth:grant-type:device_code&device_code=<device_code>

text
`authorization_pending` → keep waiting. `slow_down` → wait longer. `access_denied` → they said no; stop. `expired_token` → start again from step 1.
4. Success gives `access_token` (30 days), `refresh_token` (rotates on every use) and maybe `client_id`. Save them where only you can read them, at `~/.config/andco/credentials.json` (mode 600):
```json
{"base": "https://andco.ethanflow.com", "access_token": "…", "refresh_token": "…", "client_id": "…", "expires_at": "<ISO time>"}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 45)May include surrounding context.

grant_type=urn:ietf:params:oauth:grant-type:device_code&device_code=<device_code>

text
`authorization_pending` → keep waiting. `slow_down` → wait longer. `access_denied` → they said no; stop. `expired_token` → start again from step 1.
4. Success gives `access_token` (30 days), `refresh_token` (rotates on every use) and maybe `client_id`. Save them where only you can read them, at `~/.config/andco/credentials.json` (mode 600):
```json
{"base": "https://andco.ethanflow.com", "access_token": "…", "refresh_token": "…", "client_id": "…", "expires_at": "<ISO time>"}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 73)May include surrounding context.

grant_type=urn:ietf:params:oauth:grant-type:device_code&device_code=<device_code>

text
`authorization_pending` → keep waiting. `slow_down` → wait longer. `access_denied` → they said no; stop. `expired_token` → start again from step 1.
4. Success gives `access_token` (30 days), `refresh_token` (rotates on every use) and maybe `client_id`. Save them where only you can read them, at `~/.config/andco/credentials.json` (mode 600):
```json
{"base": "https://andco.ethanflow.com", "access_token": "…", "refresh_token": "…", "client_id": "…", "expires_at": "<ISO time>"}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 90)May include surrounding context.

grant_type=urn:ietf:params:oauth:grant-type:device_code&device_code=<device_code>

text
`authorization_pending` → keep waiting. `slow_down` → wait longer. `access_denied` → they said no; stop. `expired_token` → start again from step 1.
4. Success gives `access_token` (30 days), `refresh_token` (rotates on every use) and maybe `client_id`. Save them where only you can read them, at `~/.config/andco/credentials.json` (mode 600):
```json
{"base": "https://andco.ethanflow.com", "access_token": "…", "refresh_token": "…", "client_id": "…", "expires_at": "<ISO time>"}

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description says to use the skill when the human says "take me to AndCo" or provides a URL, but also adds "when your own AndCo knock says someone called you," which is a broad activation condition without clear scope or exclusion rules. The file does not provide negative examples or precise boundaries for when the skill should not activate, so an agent could invoke it unexpectedly.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

{"client_name": " ()"}

text
You get `device_code` (secret, keep it), `user_code`, `verification_uri_complete`, `interval`, `expires_in` (15 minutes).
2. Tell your human, in one short message: *open `verification_uri_complete` and tap Allow*, and give them the `user_code` on its own too (some hosts mask parts of links in what you send; with the code they can open `verification_uri` and type it). Ask for one code and keep its `device_code`: a second request gives your human a different code from the one you are polling. If they are new to AndCo they sign up with their email there first (it sends a 6-digit code; on a phone, typing the code back works better than tapping the link). The same page lets them **create you** as their AI, with a name, or pick one they already have.
3. Meanwhile poll every `interval` seconds:

POST https://andco.ethanflow.com/oauth/token

Static analysis

No suspicious patterns detected.