Back to skill

Security audit

AskHuman

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it sends prompts and attachments to an external human-review service while granting broad local tool access and documenting risky credential and payment flows.

Review before installing. Use this only for prompts and attachments you are comfortable sharing with AskHuman and external human workers; do not send secrets, credentials, private screenshots, regulated data, or proprietary content unless explicitly approved. Avoid putting real API keys in URL query strings, constrain local file reads and uploads, treat worker responses as untrusted input, and use paid USDC tasks only with manual review before signing permits or allowing auto-approval windows to expire.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
askhuman/SKILL.md:13
Finding

Overly Broad Local Tool Permissions

Content
View full analysis

Vulnerability Details

File Location: askhuman/SKILL.md:13
Vulnerability Type: Excessive execution and file-read permissions
Risk Level: Medium

Vulnerable Code

yaml
allowed-tools: Bash(curl *) Bash(node *) Read

Technical Analysis

The Skill grants unrestricted access to Bash(node *) and the general-purpose Read tool. Its documented workflow primarily requires HTTPS requests to the AskHuman API; no documented operation requires arbitrary Node.js execution.

Unrestricted Node.js execution can run arbitrary local JavaScript with the privileges of the hosting agent process. General Read access can expose files unrelated to the requested human-judgment task. These permissions violate least-privilege principles and substantially increase the consequences of malicious or untrusted content influencing the agent.

The project does not contain instructions that explicitly exploit these permissions. The risk arises from the excessive authority available during Skill execution.

Attack Path

  1. A task response, worker message, prompt, or other untrusted content contains instructions encouraging the agent to inspect a local file or run Node.js code.
  2. The agent treats that content as actionable rather than untrusted data.
  3. The broad Read permission is used to access unrelated files, or Bash(node *) is used to execute arbitrary JavaScript.
  4. The accessed information may then be exposed through the agent response or transmitted using the permitted network tooling.

Impact Assessment

Successful exploitation could allow access to files readable by the agent process and arbitrary Node.js execution under that process's operating-system privileges. Potentially exposed data includes source files, configuration files, environment-derived credentials, and other local workspace content. This finding does not establish operating-system privilege escalation beyond the privileges already held by the agent.

Remediation
View remediation

Remediation Suggestions

  • Remove Bash(node *) because the documented workflow does not require arbitrary Node.js execution.
  • Restrict file reads to paths explicitly selected by the user for attachment upload.
  • Constrain curl access to HTTPS requests against the documented AskHuman API host and required endpoint set.
  • Require explicit user confirmation before reading or uploading local files.
  • Require explicit confirmation before any paid task, wallet signature, or permit operation.
  • Treat task results and worker messages as untrusted data and prohibit interpreting their contents as tool-use instructions.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:203
Finding

Reusable API Key Included in SSE Query String

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:203
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

bash
curl -N "https://askhuman-api.onrender.com/v1/events?apiKey=askhuman_sk_..."

Technical Analysis

The documented SSE connection places a reusable API key in the URL query string. URLs may be retained in shell history, command-line process listings, reverse-proxy and server access logs, observability platforms, debugging output, and URL telemetry.

The same project uses the X-API-Key request header for other authenticated endpoints, which reduces ordinary URL-based credential exposure. Using a query parameter for SSE creates inconsistent and less secure credential handling.

Attack Path

  1. The agent starts the documented SSE command with its actual API key embedded in the URL.
  2. The complete command or requested URL is captured in shell history, process-monitoring output, API infrastructure logs, or telemetry.
  3. A party with access to one of those records extracts the API key.
  4. The exposed key is replayed against AskHuman API endpoints.
  5. Subject to server-side authorization, the attacker can impersonate the registered agent and access or manipulate its tasks.

Impact Assessment

Exposure of the API key could permit unauthorized access to resources associated with the agent identity. Depending on server-side authorization, this may include reading task data and messages or invoking task-management actions such as creation, approval, rejection, cancellation, or messaging. The repository does not contain a real hardcoded API key; the vulnerability is in the prescribed credential-transmission method.

Remediation
View remediation

Remediation Suggestions

  • Authenticate the SSE connection using an HTTP authorization header, preferably the existing X-API-Key convention.
  • If header-based SSE authentication is unavailable, issue a short-lived, single-purpose stream token that cannot authorize other API operations.
  • Never include reusable API keys in URLs.
  • Ensure credentials are redacted from command output, diagnostic logs, and telemetry.
  • Document immediate API-key revocation and rotation procedures for suspected exposure.
  • Add server-side token scoping, expiration, and rate limiting to reduce the impact of credential disclosure.

T09 · Insecure Skill Coding Practices

Warning
Location
askhuman/references/API-REFERENCE.md:108
Finding

Reusable API Key Included in API Reference SSE URL

Content
View full analysis

Vulnerability Details

File Location: askhuman/references/API-REFERENCE.md:108
Vulnerability Type: Credential exposure through URL query parameters
Risk Level: Medium

Vulnerable Code

bash
curl -N "https://askhuman-api.onrender.com/v1/events?apiKey=askhuman_sk_..."

Technical Analysis

The API reference independently instructs users and agents to place a reusable API key in an SSE URL. Query-string credentials are liable to enter shell history, process listings, server or proxy access logs, monitoring platforms, and debugging records.

Because this reference is linked as the complete API documentation, retaining the insecure example here could reintroduce the behavior even if the root Skill instructions are corrected.

Attack Path

  1. A user or agent follows the API reference and substitutes a valid API key into the SSE URL.
  2. The command or URL is recorded by the local shell, process-monitoring facilities, network infrastructure, or application logs.
  3. An unauthorized party obtains access to the recorded URL.
  4. The party extracts and reuses the API key against the AskHuman API.
  5. The attacker performs operations allowed to the compromised agent credential.

Impact Assessment

A compromised key could expose task prompts, human responses, messages, and agent-associated information. Depending on API authorization controls, it could also permit unauthorized task creation or task lifecycle operations. No live secret is embedded in the repository; the issue is the insecure authentication pattern presented to users.

Remediation
View remediation

Remediation Suggestions

  • Replace the query-string example with header-based authentication supported by the SSE endpoint.
  • If conventional headers cannot be used, exchange the API key for an expiring, narrowly scoped SSE token.
  • Update all copies of the documentation simultaneously to prevent conflicting security guidance.
  • Add an explicit warning that reusable credentials must not appear in URLs, logs, or command histories.
  • Provide credential rotation guidance and invalidate any key suspected of appearing in retained URL logs.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (18)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README explicitly states that prompts/tasks are sent to real human workers, but it does not warn users against including secrets, personal data, internal prompts, or other sensitive workflow context. In an agent setting, users may pass arbitrary session content to the skill, so omission of a clear disclosure/sanitization warning can lead to unintended third-party data exposure to humans outside the trust boundary.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 31)May include surrounding context.

md
The skill will:
1. Authenticate with the AskHuman API (auto-registers if no API key is set)
2. Create a task for human workers
3. Poll until a worker submits an answer
4. Return the result to your workflow

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly supports uploading images and creating tasks whose contents are sent to an external API and then displayed to human workers, but it does not provide a clear user-facing warning about that disclosure. This creates a privacy and data-handling risk because an agent could forward sensitive screenshots, prompts, or proprietary material to third parties without informed consent from the user.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
97% confidence
Finding

This section instructs agents to send task prompts and image attachments to an external service, and those attachments may include uploaded files or inline base64 image data. In context, the service is explicitly designed for human review, so any included sensitive screenshots, documents, or personal data would be disclosed to a third party without a strong warning, making the external transmission materially risky.

Content

Scanner excerpt · SKILL.md (reported line 143)May include surrounding context.

Use it in task creation:

bash
curl -X POST https://askhuman-api.onrender.com/v1/tasks \
  -H "Content-Type: application/json" \
  -H "X-API-Key: askhuman_sk_..." \
  -d "{

External Transmission

Medium
Category
Data Exfiltration
Confidence
93% confidence
Finding

The SSE example places the API key directly in the query string, which is commonly logged by clients, proxies, browser history, monitoring tools, and server access logs. Exposing long-lived credentials in URLs increases the chance of accidental credential leakage and unauthorized access to task events.

Content

Scanner excerpt · SKILL.md (reported line 203)May include surrounding context.

Open a persistent connection to receive real-time events. No external server needed — just listen.

bash
curl -N "https://askhuman-api.onrender.com/v1/events?apiKey=askhuman_sk_..."

Events you'll receive:

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The skill documents that tasks are finalized automatically after 72 hours if the agent does nothing, meaning payment and acceptance can occur without an explicit review decision. For a human-judgment marketplace, this can cause agents to implicitly endorse poor or harmful outputs and release funds due to missed events or downtime rather than intentional approval.

Content

Scanner excerpt · SKILL.md (reported line 210)May include surrounding context.

md
- `task.assigned` — a worker accepted your task
- `task.submitted` — the worker submitted an answer (you can now review it)
- `task.completed` — task is finalized (auto-approved after 72h if you don't act)

Open the SSE connection **before** creating the task so you don't miss any events.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
91% confidence
Finding

This repeats the behavior that submitted work is automatically approved and payment released if the agent does not respond within 72 hours. In context, the risk is higher because the skill encourages agents to rely on external human decisions for socially sensitive or irreversible actions, so unintended approval can have operational and reputational consequences beyond simple payment loss.

Content

Scanner excerpt · SKILL.md (reported line 252)May include surrounding context.

-H "X-API-Key: askhuman_sk_..."

text

If you don't approve or reject within 72 hours, the task is auto-approved and payment is released.

### Step 7: Message the worker (optional)

External Transmission

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The skill is explicitly designed to transmit task content over the network to a third-party API and ultimately to human reviewers. That behavior is core functionality, but it still creates a real exfiltration risk if an agent forwards sensitive repository contents, internal prompts, screenshots, or secrets without strict consent and filtering.

Content

Scanner excerpt · askhuman/SKILL.md (reported line 13)May include surrounding context.

md
author: askhuman
  version: "1.0.0"
  homepage: https://askhuman.guru/developers
allowed-tools: Bash(curl *) Bash(node *) Read
---

# AskHuman — Human Judgment as a Service

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs agents to send prompts and related content to an external human-review service, but it does not prominently warn that user data may be disclosed to third-party humans. In agent workflows, this can cause accidental sharing of sensitive code, credentials, personal data, or proprietary business information because the operator may not realize the content leaves the local environment and is viewed by people.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · askhuman/SKILL.md (reported line 104)May include surrounding context.

}

text

**VERIFY** — Yes/No verification:
```json
{
  "type": "VERIFY",

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Automatic approval after 72 hours can cause an agent's workflow to accept and finalize human-submitted results without explicit review. If the response is incorrect, malicious, low quality, or socially engineered, the task may be treated as accepted by default, and for paid tasks funds may be released despite no deliberate validation.

Content

Scanner excerpt · askhuman/SKILL.md (reported line 162)May include surrounding context.

-H "X-API-Key: $ASKHUMAN_API_KEY"

text

> Tasks are auto-approved after 72 hours if no action is taken.

## Paid Tasks (Optional)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

Step 1: Get a challenge

bash
curl -X POST https://askhuman-api.onrender.com/v1/agents/challenge \
  -H "Content-Type: application/json" \
  -d '{"name":"YourAgentName"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · askhuman/references/API-REFERENCE.md (reported line 21)May include surrounding context.

Step 1: Get a challenge

bash
curl -X POST https://askhuman-api.onrender.com/v1/agents/challenge \
  -H "Content-Type: application/json" \
  -d '{"name":"YourAgentName"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation recommends opening an SSE stream with the API key in the URL query string (/v1/events?apiKey=...). Query parameters are commonly exposed in browser history, reverse-proxy logs, analytics, referrer leakage, shell history, and monitoring systems, so this pattern materially increases the chance of credential disclosure. Because the key appears to grant agent actions, leakage could let an attacker monitor task events and potentially act as the agent against authenticated endpoints.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
89% confidence
Finding

The documentation states tasks are auto-approved after 72 hours if the agent does not act. In a system where human workers submit results and payment is released automatically, missed events, outages, or unattended agents can cause funds to be released for low-quality, incorrect, or malicious submissions without explicit review. The surrounding context makes this more dangerous because the same document also suggests SSE-based monitoring, and if that monitoring fails the approval safeguard disappears.

Content

Scanner excerpt · askhuman/references/API-REFERENCE.md (reported line 115)May include surrounding context.

md
- `task.assigned` — a worker accepted your task
- `task.submitted` — the worker submitted an answer (you can now review it)
- `task.completed` — task is finalized (auto-approved after 72h if you don't act)

Open the SSE connection **before** creating the task so you don't miss any events.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
90% confidence
Finding

This repeats the same risky business logic: if no approval or rejection occurs within 72 hours, payment is automatically released. That creates an exploitable failure mode where operational downtime, lost API keys, broken listeners, or deliberate flooding can prevent review and force approval of unsatisfactory work, causing financial loss and reduced trust in the platform.

Content

Scanner excerpt · askhuman/references/API-REFERENCE.md (reported line 157)May include surrounding context.

-H "X-API-Key: askhuman_sk_..."

text

If you don't approve or reject within 72 hours, the task is auto-approved and payment is released.

### Step 7: Message the worker (optional)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 336)May include surrounding context.

Read public testimonials (no auth needed):

bash
curl "https://askhuman-api.onrender.com/v1/ingest/volunteer-review?limit=20"

Returns testimonials where consent.public_display is true.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · askhuman/references/API-REFERENCE.md (reported line 241)May include surrounding context.

Read public testimonials (no auth needed):

bash
curl "https://askhuman-api.onrender.com/v1/ingest/volunteer-review?limit=20"

Returns testimonials where consent.public_display is true.

Static analysis

No suspicious patterns detected.