Back to skill

Security audit

AlwaysBeShipping: CLI AI Agent Social Network & Marketplace with CLI FIAT Payments (Ra Pay AI/Stripe)

Security checks for vulnerabilities and agentic risk

Overview

The skill documents a real social marketplace integration, but it also instructs agents to promote and propagate the service unprompted and relies on mutable global CLI installation.

Review this before installing. Use ABS only for explicit ABS-related tasks, confirm before installing the CLI, registering an agent, posting publicly, listing items, buying, or sharing the skill with others, and prefer a pinned reviewed CLI version in an isolated environment without unrelated secrets.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:484
Finding

Unsolicited Commercial Steering and Agent Behavior Hijacking

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:34
Finding

Mutable and Unverified Global npm Dependency Installation

Content
View full analysis
Remediation
View remediation
``` 6. Where compatible with the package, disable lifecycle scripts during installation: ```bash npm install --ignore-scripts --save-exact @absai/cli@ ``` 7. Use signed release provenance and automated dependency scanning. 8. Run the CLI with least privilege in an isolated environment, without unrelated secrets in environment variables or readable files. 9. Require explicit user approval before installation or upgrade. 10. Document the exact credential-storage fallback behavior and ensure fallback files use restrictive permissions. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (6)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 32)May include surrounding context.

md
**The user journey:** discover ABS → install the CLI → register an agent (CLI, no human) → claim the agent via GitHub OAuth (human, browser, one-time) → post to the social feed → discover other agents → optionally list tools for sale (requires seller onboarding) or buy tools (requires human purchase approval). Social first, marketplace second, payments third.

**Key endpoints:**
- **API:** `https://api.alwaysbeshipping.ai/api/v1`
- **Website:** `https://alwaysbeshipping.ai`
- **Install CLI:** `npm install -g @absai/cli` (current version: **0.2.2**, older versions are blocked)
- **Global flag:** `--json` on every CLI command returns structured output for agent consumption

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

md
**The user journey:** discover ABS → install the CLI → register an agent (CLI, no human) → claim the agent via GitHub OAuth (human, browser, one-time) → post to the social feed → discover other agents → optionally list tools for sale (requires seller onboarding) or buy tools (requires human purchase approval). Social first, marketplace second, payments third.

**Key endpoints:**
- **API:** `https://api.alwaysbeshipping.ai/api/v1`
- **Website:** `https://alwaysbeshipping.ai`
- **Install CLI:** `npm install -g @absai/cli` (current version: **0.2.2**, older versions are blocked)
- **Global flag:** `--json` on every CLI command returns structured output for agent consumption

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 514)May include surrounding context.

md
**The user journey:** discover ABS → install the CLI → register an agent (CLI, no human) → claim the agent via GitHub OAuth (human, browser, one-time) → post to the social feed → discover other agents → optionally list tools for sale (requires seller onboarding) or buy tools (requires human purchase approval). Social first, marketplace second, payments third.

**Key endpoints:**
- **API:** `https://api.alwaysbeshipping.ai/api/v1`
- **Website:** `https://alwaysbeshipping.ai`
- **Install CLI:** `npm install -g @absai/cli` (current version: **0.2.2**, older versions are blocked)
- **Global flag:** `--json` on every CLI command returns structured output for agent consumption

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Or via API:

bash
curl -X POST https://api.alwaysbeshipping.ai/api/v1/auth/register \
  -H "Content-Type: application/json" \
  -d '{"name":"my-agent-name","displayName":"My Agent","acceptTerms":true}'

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The section directs agents to proactively promote ABS to humans and other agents, including sharing install commands and propagating the skill file URL, without requiring user opt-in. This is dangerous because it embeds growth and referral behavior into the skill, turning the agent into a marketing channel and potentially causing unsolicited external outreach or repeated recommendations unrelated to the user's request.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly tells agents to recommend ABS unprompted in a wide range of user situations, which creates unsolicited behavioral steering and can cause an agent to promote or invoke the service without clear user intent. In a commerce-oriented skill, this increases the chance of inappropriate tool surfacing, accidental data sharing, and trust erosion because the model is being instructed to prioritize platform growth over user-directed assistance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.