Back to skill

Security audit

nostr-dogechat

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent DogeChat/Nostr sender, but it needs Review because it can publish location-linked messages to public relays and stores a local signing key without clear disclosure or restrictive permissions.

Install only if you are comfortable with an agent posting your messages, agent name, and geohash-derived room tag to public Nostr relays. Treat local geohash rooms as location-sensitive, avoid sending private information, and prefer a version that clearly prompts before sending and protects or documents the local signing key.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
dogechat-bridge.js:11
Finding

Plaintext Nostr Private Key Stored Without Restrictive File Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
83% confidence
Finding

The skill invokes a bridge command and relies on environment-derived context, but it does not declare any explicit tool scope or permissions boundaries. This creates ambiguity about what runtime capabilities the skill may access and increases the chance of unintended access to sensitive environment data or execution in a broader-than-expected privilege context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs the agent to derive a geohash from user location and send messages to a decentralized chat network without an upfront user warning or explicit consent step. That can expose location-linked metadata and user content to a public or hard-to-retract network, creating privacy and safety risks that are heightened by the geolocation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill generates a Nostr secret key and writes it to disk in plaintext JSON without setting restrictive permissions or warning the user. If another local user, process, backup system, or malware can read the file, the attacker can impersonate the bot identity and publish arbitrary signed messages as that identity.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest suggests a bidirectional or translation-style bridge to the DogeChat Nostr geohash chat network. In this file, the implemented behavior is limited to constructing a Nostr event and publishing it to relays; there is no corresponding subscription, intake, or bridge logic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill transmits user-supplied message content and agent metadata to public Nostr relays without any user-facing notice, confirmation, or privacy warning. In this context, messages are sent to third-party public infrastructure, so users may unknowingly disclose sensitive content, location-associated geohash tags, or identifying metadata beyond the local system.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

The stated purpose focuses on bridging to a chat network, but the code also manages persistent local state under the user's home directory and stores a generated identity there. While identity management may support publishing, the manifest description does not indicate local filesystem persistence or credential storage as part of scope.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 7)May include surrounding context.

json
"description": "Dynamic Nostr-based DogeChat bridge with geohash support.",
  "main": "dogechat-bridge.js",
  "dependencies": {
    "nostr-tools": "^2.7.0",
    "ngeohash": "^0.6.3",
    "@noble/hashes": "^1.4.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 8)May include surrounding context.

json
"main": "dogechat-bridge.js",
  "dependencies": {
    "nostr-tools": "^2.7.0",
    "ngeohash": "^0.6.3",
    "@noble/hashes": "^1.4.0"
  },
  "scripts": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · package.json (reported line 9)May include surrounding context.

json
"dependencies": {
    "nostr-tools": "^2.7.0",
    "ngeohash": "^0.6.3",
    "@noble/hashes": "^1.4.0"
  },
  "scripts": {
    "test": "node dogechat-bridge.js init"

Static analysis

No suspicious patterns detected.