Back to skill

Security audit

Agent Ads Earn

Security checks for vulnerabilities and agentic risk

Overview

This skill should be reviewed carefully because it monetizes monitoring XMTP group chats and sends message-derived identifiers and content to external services before the referred person opts in.

Install only if you can ensure explicit notice and consent for monitored groups and participants, enforce a strict allowlist of group IDs, minimize or redact trigger messages and stable identifiers, and confirm that Basemate requires real authentication beyond publisherId for referrals and earnings access.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:381
Finding

Private XMTP Group Messages and Member Identifiers Are Disclosed Without Member-Level Consent

Content
View full analysis
{ if (message.senderInboxId === client.inboxId) return; // skip own messages if (!message.content || typeof message.content !== "string") return; // 3. Detect intent const match = await detectIntent(message.content, activeInterests.map(i => i.category)); if (!match.detected || match.confidence < 0.7) return; // 4. Submit referral const res = await fetch(`${BASEMATE_API}/api/earn/refer`, { method: "POST", headers: { "Content-Type": "application/json" }, body: JSON.stringify({ publisherId: PUBLISHER_ID, humanInboxId: message.senderInboxId, matchedInterests: match.interests, sourceGroupId: message.conversationId, triggerMessage: message.content.slice(0, 500), confidence: match.confidence, }), }); ``` The operational instruction at `SKILL.md:246` additionally states: ```markdown - Monitor all group messages in your registered groups ``` ### Technical Analysis The reference implementation listens to all messages exposed by `streamAllMessages`. It then transmits the sender's XMTP inbox ID, source conversation ID, inferred interests, confidence score, and up to 500 characters of the original message to the Basemate API. The only consent described by the skill is the recipient's later choice to accept or reject an invitation. That consent occurs after the original message and associated identifiers have already been processed and disclosed. Authorization from a group owner to add Basemate does not demonstrate informed consent from every group member to behavioral profiling or third-party disclosure. The sample callback also does not explicitly verify that the conversation is one of the publisher's registered groups. ...[truncated 1382 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
SKILL.md:194
Finding

Raw Group-Chat Messages Are Sent to an Additional AI Provider

Content
View full analysis
{ const response = await openai.chat.completions.create({ model: "gpt-4o-mini", messages: [ { role: "system", content: `You are an intent detection engine. Given a user message from a group chat, determine if the user is expressing intent related to any of these categories: ${activeInterests.join(", ")}. Return JSON: { "detected": boolean, "interests": string[], "confidence": number (0-1) } Only flag genuine intent — questions, requests, expressed needs. NOT casual mentions or jokes.`, }, { role: "user", content: message }, ], response_format: { type: "json_object" }, temperature: 0, }); ``` ### Technical Analysis The recommended intent detector submits the complete message string to OpenAI. The skill does not require member consent for this additional recipient and does not redact names, wallet addresses, credentials, health information, financial details, or other sensitive material before transmission. Consequently, processing is not confined to the XMTP group or the Basemate referral platform. A member's message may be transferred to an AI service before the member has been notified of a referral or offered a consent action. ### Attack Path 1. A group member posts a message in a conversation monitored by the integrating agent. 2. The listener passes the entire message to `detectIntent`. 3. `detectIntent` places the unredacted message in the user role of an OpenAI API request. 4. OpenAI receives and processes the ...[truncated 812 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
mcp-server.json:35
Finding

Publisher ID Is Used as the Sole Documented Credential for Sensitive API Operations

Content
View full analysis
0.7)" } }, "required": ["publisherId", "humanInboxId", "matchedInterests", "sourceGroupId"] }, "endpoint": "POST /api/earn/refer" }, { "name": "check_earnings", "description": "Check your earnings dashboard — total earnings, pending payouts, referral stats, and conversion rates.", "inputSchema": { "type": "object", "properties": { "publisherId": { "type": "string", "description": "Your publisher ID" } }, "required": ["publisherId"] }, "endpoint": "GET /api/earn/dashboard" } ``` The declared authentication configuration states: ```json "authentication": { "type": "erc-8004", "description": "Publisher registration requires ERC-8004 identity on Base. Subsequent calls use publisher ID.", "registry": "0x8004A169FB4a3325136EB29fA0ceB6D2e539a432" ...[truncated 2061 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

These instructions normalize broad surveillance of human group-chat traffic and monetized forwarding of inferred intent to a third party. Even if the later DM is consent-based, the sensitive step has already occurred: private communications are analyzed and referral metadata is generated for profit, which can expose user interests, identities, and group participation patterns.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The referral payload explicitly includes raw trigger messages plus inbox IDs, wallet addresses, source group IDs, and inferred interests, which together create a rich semantic profile of a user's private activity. This is dangerous because it enables third-party reconstruction of who said what, where, and about which topic, increasing risks of privacy harm, profiling, and secondary misuse or breach impact.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The full example operationalizes continuous ingestion of all group messages and automatic transmission of message excerpts and sender identifiers to an external API, making the privacy-invasive behavior turnkey. Because it is presented as a ready-to-run integration, it substantially increases the likelihood of widespread deployment of a semantic data-exfiltration pattern without adequate safeguards.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The manifest explicitly says the service detects intent in group chats and submits referrals containing inbox IDs, wallet addresses, source group IDs, matched interests, and trigger messages, but it provides no prominent privacy warning or consent model. In this context, the skill facilitates transmission of sensitive communication metadata and potentially personal data from group conversations to a third party, which is dangerous because users may be monitored or profiled without clear notice or permission.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill directs agents to monitor all messages in registered groups for commercial intent, but it does not clearly foreground this as continuous surveillance of participant communications. In practice, this can mislead deployers and group members about the scope of collection and create covert monitoring in spaces where participants may not expect their chats to be analyzed for monetized referrals.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs publishers to send human inbox IDs, wallet addresses, matched interests, source group IDs, confidence scores, and trigger-message content to an external service, but it does not prominently warn operators that this shares third-party chat-derived data off-platform. That omission creates a meaningful privacy and compliance risk because integrators may deploy the workflow without obtaining informed consent from monitored users or evaluating whether such disclosure is permitted.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill list uses broad action-oriented descriptions such as registering publishers, fetching subscriber interests, and submitting human referrals without defining authorization boundaries, approval steps, or narrow trigger conditions. In an agent ecosystem, this can cause overbroad invocation or unsafe automation around financial and identity-linked actions, increasing the chance of privacy violations, spammy referrals, or unintended submissions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest explicitly indicates collection and transmission of group IDs, payout wallet information, subscriber interests, and human referral data, but provides no privacy notice, consent model, retention policy, or disclosure of downstream sharing. Because this skill operates on messaging-group and referral-marketplace data tied to wallet identities and earnings, missing data-handling warnings can expose users and referred individuals to unwanted profiling, deanonymization, and unauthorized data sharing.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The tool descriptions authorize broad monitoring of XMTP group chats and intent matching without clear limits on what content may be inspected, what signals are in scope, or what exclusions apply. That ambiguity can lead integrators or downstream agents to over-collect messages and identifiers, creating privacy, consent, and misuse risks even if the backend behaves as intended.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says the service will 'detect intent in XMTP groups and refer matched humans' without defining clear trigger conditions, consent boundaries, scope limits, or exclusion criteria. In a messaging and monetization context, broad activation language can enable over-collection of conversational data, unsolicited profiling, or automatic referral behavior that users and integrators may not expect.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.