Back to skill

Security audit

Domain availability API built for AI agents. Check single domains, explore names across .com/.io/.ai/.dev/etc, filter by budget, get smart suggestions. Returns proper JSON/TXT with correct Content-Type headers.

Security checks for vulnerabilities and agentic risk

Overview

This skill is a real domain registrar helper, but it enables purchases and domain-changing operations without enough built-in confirmation guidance.

Review this skill carefully before installing. It appears purpose-aligned and not deceptive, but only use it when you want an agent to help with real domain purchases or administrative changes. Require explicit approval before any purchase, DNS deletion, nameserver change, domain unlock, autorenew change, or transfer action, and keep management tokens private.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
83% confidence
Finding

The documented DELETE endpoint enables destructive mutation of DNS state using a simple query parameter id, and the skill provides no guardrails around verifying record identity, showing current records, or confirming deletion. In an agent workflow, this increases the risk of tool-parameter abuse where an attacker or ambiguous prompt induces deletion of critical DNS records, leading to service disruption.

Content

Scanner excerpt · SKILL.md (reported line 284)May include surrounding context.

Delete a record:

text
DELETE /api/manage/{domain}/dns?id=123

Supported record types: A, AAAA, CNAME, MX, TXT, NS, SRV

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill provides step-by-step instructions to purchase real domains and explicitly returns a management token, but it does not require an explicit user confirmation or warn that these actions create irreversible financial charges and domain registrations. In an agent setting, this can cause unauthorized purchases, spending of card/crypto funds, and unintended acquisition of assets if the model acts on ambiguous prompts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill documents DNS, nameserver, settings, and transfer operations as routine tasks without warning that they can immediately disrupt websites, email delivery, verification records, or transfer control of a domain. In an autonomous-agent context, these are high-risk administrative actions because a mistaken or maliciously induced change can cause outages, loss of service, or weaken domain protections.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.