Back to skill

Security audit

Worthtotry Skill

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its stated listing-submission purpose, but users should review it because it recommends mutable remote installation and includes a fallback that asks the agent to handle a WorthToTry access token.

Install from a reviewed local or pinned copy when possible. Before using it, confirm the exact product URL, owner email, and listing copy that will be sent to WorthToTry, and avoid giving the agent a personal access token unless you understand what that token can do and can provide it through a secure secret flow.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
README.md:13
Finding

Unpinned Remote Agent Instructions Create a Post-Audit Supply-Chain Risk

Content
View full analysis
- The skill, always current: ``` ### Technical Analysis The documented default installation path instructs an AI Agent to retrieve and follow behavioral instructions from `https://worthtotry.com/skill.md`. This resource is not pinned to a repository commit, immutable release, cryptographic digest, or verified signature. The phrase “always current” confirms that the effective Skill content can change independently of the files reviewed in this audit. Agent Skill Markdown is security-sensitive because it controls tool selection, data handling, network requests, and actions performed with the Agent's available permissions. A future modification of the hosted file would not be covered by the review of this repository. Compromise of the domain, hosting account, deployment pipeline, or content publishing process could therefore substitute malicious instructions while preserving the trusted URL. No malicious instructions or payloads were identifi ...[truncated 1962 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
returns a 401, your client opens a browser, and the person approves the connection once. Two scopes
are requested — `submit` (open draft listings on their behalf) and `read:submissions` (see their
listings and status). No token passes through the conversation. If your client does not do OAuth,
fall back to `references/rest-api.md`, where the person creates a personal access token in their
dashboard instead.

## 2. Audit the page before anything else

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/mcp-tools.md (reported line 29)May include surrounding context.

md
- `submit` — open draft listings on their behalf
- `read:submissions` — see the listings they have submitted and their status

Access tokens are short-lived and refreshed by the client. You never handle one.

---

Credential Access

High
Category
Privilege Escalation
Confidence
88% confidence
Finding

The skill instructs the agent to ask the user for a personal access token, which is a sensitive credential that can authorize authenticated actions against the user's account. Even though it says not to mint the token, encouraging token collection in skill instructions is dangerous because agents may request, handle, store, or misuse bearer tokens outside a secure credential flow.

Content

Scanner excerpt · references/rest-api.md (reported line 13)May include surrounding context.

md
## Authentication

Reads need nothing. Writes need `Authorization: Bearer <token>`, where the token is a personal
access token the person creates in their dashboard. Ask them for one; do not try to mint it.

The same ceiling applies here. Nothing in this API publishes a listing, sets a launch date, or takes
a payment.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The README promotes a very broad natural-language trigger phrase ('Install the skill ... and list my product on WorthToTry') with minimal scope constraints or confirmation requirements. In agent environments, such generic phrasing can cause unintended activation on ordinary product-listing requests, leading an agent to fetch remote instructions and potentially submit external data or contact details without sufficiently explicit user intent verification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to transmit an owner's email address and product URL to a third-party service without requiring an explicit consent or privacy notice to the user first. Even if the data is not highly sensitive, sending personally identifiable contact data off-platform without clear authorization creates privacy, compliance, and trust risks.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

The phrase 'No token, no OAuth, no consent screen' encourages a workflow where an agent can initiate actions on behalf of a person without an authentication or consent checkpoint. In this context, that lowers safeguards against unauthorized submissions, impersonation, or surprise third-party contact using someone else's email address.

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

The short way, with no account and no browser

POST https://worthtotry.com/api/v1/submissions with a JSON body carrying url and the owner's email. No token, no OAuth, no consent screen. We email them a link; one click sends the listing for review and there is nothing else for them to do.

text

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The skill contains direct instructions and example code to POST user-supplied data to an external API. External transmission is not inherently malicious here, but it is security-relevant because it operationalizes exfiltration of user-provided contact information and URLs to a third party, especially when combined with minimal consent friction.

Content

Scanner excerpt · SKILL.md (reported line 24)May include surrounding context.

for review and there is nothing else for them to do.

text
curl -X POST https://worthtotry.com/api/v1/submissions \
  -H 'content-type: application/json' \
  -d '{"url":"https://theirproduct.com","email":"them@theircompany.com"}'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/mcp-tools.md (reported line 139)May include surrounding context.

md
`requestedLaunchDate`, `publishedAt`, `upvotes`, `views`, `badgeStatus`, `submittedVia`,
`reviewUrl`, and `toolUrl` once published.

Use it to answer "where is my submission" without asking the person to check the dashboard.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The documentation describes authenticated write operations using a personal access token and tells the agent to ask the user for one, but it does not include an explicit safety warning that using the token will create or modify remote data on the user's account. In an agent skill context, that omission can normalize credential collection and remote actions without clear consent boundaries, increasing the chance of unintended account changes.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-api.md (reported line 35)May include surrounding context.

Audit a URL

text
curl -s -X POST "https://worthtotry.com/api/v1/readiness" \
  -H "Content-Type: application/json" \
  -d '{"url":"https://theproduct.com"}'

Static analysis

No suspicious patterns detected.