Back to skill

Security audit

AMAI ID

Security checks for vulnerabilities and agentic risk

Overview

This identity skill is coherent and not malicious, but its examples handle long-lived private signing keys too unsafely for automatic approval.

Review before installing or using. The API registration flow itself is purpose-aligned, but do not follow the private-key examples as written: avoid printing private keys, use encrypted or OS-managed secret storage, enforce owner-only permissions, and keep sensitive personal/customer/action details out of any permanent reputation record.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:55
Finding

Unencrypted Private-Key Disclosure Through Console Output and Plaintext File Storage

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 55–64, 386–389, and 432–433
Vulnerability Type: Plaintext exposure of sensitive cryptographic key material
Risk Level: High

Vulnerable Code

python
private_pem = private_key.private_bytes(
    encoding=serialization.Encoding.PEM,
    format=serialization.PrivateFormat.PKCS8,
    encryption_algorithm=serialization.NoEncryption()
).decode()

print("Public Key (share this):")
print(public_pem)
print("\nPrivate Key (KEEP SECRET):")
print(private_pem)
python
private_pem = private_key.private_bytes(
    encoding=serialization.Encoding.PEM,
    format=serialization.PrivateFormat.PKCS8,
    encryption_algorithm=serialization.NoEncryption()
).decode()
python
(KEYS_DIR / f"{AGENT_NAME}.pub").write_text(public_pem)
(KEYS_DIR / f"{AGENT_NAME}.key").write_text(private_pem)

Technical Analysis

The examples serialize the Ed25519 private key as an unencrypted PKCS#8 PEM document. The quick-start example then prints the complete private key to standard output. Standard output may be retained in terminal transcripts, CI/CD logs, agent conversation records, monitoring systems, or other log aggregation facilities.

The complete registration example also writes the unencrypted key with Path.write_text() without explicitly enforcing owner-only permissions. The resulting access permissions depend on the process umask and surrounding filesystem configuration. On a permissively configured or shared system, other local accounts or processes may be able to read the key.

These exposures are unnecessary for the declared registration workflow. The remote service only requires the public key and a signature proving possession of the private key. The private key does not need to be printed or transmitted. Although Base64 encoding and network submission appear elsewhere in the file, the encoded value is an Ed25519 signature, and th ...[truncated 1588 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all statements that print or log private-key material. Only display the public key and a non-sensitive fingerprint.

  2. Prefer an operating-system keychain, hardware-backed keystore, HSM, or managed secret store for persistent private keys.

  3. If PEM storage is necessary, use encrypted PKCS#8 serialization with a strong passphrase obtained from a protected secret source:

    python
    private_pem = private_key.private_bytes(
        encoding=serialization.Encoding.PEM,
        format=serialization.PrivateFormat.PKCS8,
        encryption_algorithm=serialization.BestAvailableEncryption(passphrase)
    )
    
  4. Create local key files atomically with owner-only permissions such as mode 0600; do not rely solely on the ambient umask. Verify file ownership and permissions after creation.

  5. Prevent accidental overwrite, symbolic-link traversal, and storage in shared or synchronized directories.

  6. Document secure backup, revocation, rotation, and recovery procedures for compromised identity keys.

  7. Ensure logs, exception handlers, debugging tools, and agent transcripts never include private-key bytes or passphrases.

  8. Clearly state that only the public key and signed proof may be transmitted to https://id.amai.net; the private key must remain local and protected.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The documentation promotes an immutable, append-only reputation chain without prominently warning that actions may become permanently attributable and difficult or impossible to redact later. In an identity skill, this can lead users to expose sensitive behavioral metadata, operational history, or regulated information in a way that creates lasting privacy, compliance, and doxxing risks.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The examples export and persist the Ed25519 private key in plaintext using NoEncryption() and later write it directly to disk, which materially increases the chance of credential compromise if the host, logs, backups, or local filesystem are exposed. Because this skill is specifically about long-lived identity and signing authority, private key theft would let an attacker impersonate the agent, sign actions, and potentially irreversibly poison its reputation trail.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
signature_b64 = base64.b64encode(signature).decode()

# Register
response = requests.post("https://id.amai.net/register", json={
    "name": name,
    "public_key": public_pem,
    "key_type": "ed25519",

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

md
signature_b64 = base64.b64encode(signature).decode()

# Register
response = requests.post("https://id.amai.net/register", json={
    "name": name,
    "public_key": public_pem,
    "key_type": "ed25519",

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 419)May include surrounding context.

md
if description:
        payload["description"] = description

    response = requests.post(f"{AMAI_SERVICE}/register", json=payload)
    return response.json()

def main():

Static analysis

No suspicious patterns detected.