Back to skill

Security audit

Carbosilex Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent marketplace API skill, but it gives agents broad authenticated power to post, message, submit work, and use a bearer API key with weak destination controls.

Install only if you trust CarboSilex137 and are prepared for the agent to act on your marketplace account. Keep CARBOSILEX_API_KEY protected, avoid api_key.txt unless file access is tightly controlled, do not override CARBOSILEX_API_URL except to a trusted endpoint, and require human review before sending proposals, deliveries, job posts, or messages.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/carbosilex_client.py:114
Finding

API Key Disclosure Through an Unrestricted API Destination

Content
View full analysis
dict[str, str]: """Build request headers with optional authentication.""" headers = { "Content-Type": "application/json", "Accept": "application/json", } if self.api_key: headers["X-API-Key"] = self.api_key return headers ``` For example, the key-bearing header is used when listing public jobs: ```python with httpx.Client(timeout=30) as client: resp = client.get(self._url("/jobs/"), params=params, headers=self._headers) ``` ### Technical Analysis The client accepts an arbitrary `base_url` from either the `CARBOSILEX_API_URL` environment variable or the `CarbosilexClient` constructor. It does not validate the normalized hostname, URL scheme, port, embedded user information, or whether the destination belongs to CarboSilex137. At the same time, `_headers` adds the `CARBOSILEX_API_KEY` to every request whenever a key is available. This includes operations documented as public, such as job listing, job details, the job feed, and the platform health check. These operations do not require authentication and therefore should not receive the credential. This design means that configuration influence over `CARBOSILEX_API_URL` can become a creden ...[truncated 2355 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (29)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 404)May include surrounding context.

bash
# Generate an API key from an authenticated user session
curl -X POST https://api.carbosilex137.com/api/v1/users/me/api-keys \
  -H "Authorization: Bearer <user-session-jwt>" \
  -H "Content-Type: application/json" \
  -d '{"label": "my-agent"}'

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · README.md (reported line 414)May include surrounding context.

python scripts/carbosilex_client.py my-work

text

The client automatically sends the `X-API-Key: <key>` header on every request.

### Endpoints by access level

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill exposes network and environment-variable capabilities but does not declare any explicit tool scope or permission boundaries. That omission makes it easier for an agent runtime or user to invoke authenticated external actions without clear least-privilege constraints or review expectations.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Proposal submission and delivery submission create persistent records on an external marketplace and may expose project details, repository links, schedules, or other sensitive business information. Without an explicit warning, an agent may autonomously publish data or take business actions that are difficult to retract and could bind the user operationally or contractually.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill includes authenticated messaging features that can send outbound content to external recipients, but it does not clearly warn users that agent-generated text may be transmitted to marketplace participants. In an agent setting, this can lead to unintended disclosures, unauthorized commitments, spam, or reputational harm if messaging is triggered automatically.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest advertises actions that can transmit user-generated content and trigger financially meaningful operations, including proposals, deliveries, messaging, and escrow management, but provides no user-facing disclosure about external transmission, irreversible blockchain effects, or the need for explicit confirmation. In an agent context, this omission increases the risk that a user or calling system invokes sensitive actions without understanding that data will leave the local environment or may affect funds and contractual state.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 5)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 51)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 73)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 87)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 296)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 321)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 370)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 404)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 433)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

md
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · claw.yaml (reported line 33)May include surrounding context.

yaml
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · claw.yaml (reported line 69)May include surrounding context.

yaml
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/carbosilex_client.py (reported line 12)May include surrounding context.

python
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/carbosilex_client.py (reported line 128)May include surrounding context.

python
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/carbosilex_client.py (reported line 149)May include surrounding context.

python
python carbosilex_client.py <command> [options]

Environment Variables:
    CARBOSILEX_API_URL: Base URL for the CarboSilex API (default: https://api.carbosilex137.com/api/v1)
    CARBOSILEX_API_KEY: API key (sent as X-API-Key) for authenticated endpoints

Examples:

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest says the skill enables browsing jobs, submitting proposals, managing escrows, and tracking deliveries. However, the code also creates new jobs, reads notifications, and manages direct conversations/messages, which are materially different marketplace functions not mentioned in the stated scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code exposes state-changing operations such as marking all notifications as read via a POST request, but provides no confirmation prompt or explicit warning before performing the action. While the command names describe the behavior, the file does not include a user-facing caution for these irreversible or hard-to-undo actions in the CLI flow itself.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

This is a markdown file, so SQP-2 applies to missing user-facing warnings about behaviors affecting privacy or user data. The section describes reading notifications, listing conversations, viewing messages, and sending replies via authenticated API calls, but it does not explicitly warn that message content and account activity are sent to the CarboSilex137 service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README shows how to generate an API key and immediately use the returned raw key, but it does not clearly warn that this value is a bearer credential that must be protected like a password. In agent environments, such examples are often copied into shell history, logs, notebooks, or chat transcripts, which can lead to credential theft and unauthorized API access.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.