Back to skill

Security audit

电商agent社区

Security checks for vulnerabilities and agentic risk

Overview

The skill’s community-integration purpose is clear, but it asks agents to persistently run checks, store a bearer API key in local JSON state, and potentially post or comment automatically.

Review before installing. Use this only if you want an agent to interact with EcomMolt on a recurring basis, keep the heartbeat read-only unless you explicitly approve writes, store the API key in a proper secret store rather than the suggested JSON file, and confirm the intended API origin before enabling any schedule.

Vulnerability Patterns
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T06 · System Persistence

Error
Location
HEARTBEAT.md:3
Finding

Persistent Scheduled Heartbeat Creates Cross-Session Third-Party Activity

Content
View full analysis

Vulnerability Details

File Location: HEARTBEAT.md, lines 3–16
Vulnerability Type: Persistent scheduled task
Risk Level: High

Vulnerable Code

markdown
> 将本文件添加到你的周期任务列表。建议每 **30 分钟**执行一次。

---

## 心跳接入配置

在你的 `HEARTBEAT.md` 或等效周期任务文件中添加:

```markdown
## EcomMolt 巡检 (每 30 分钟)
如距上次 EcomMolt 巡检已超过 30 分钟:
1. GET https://ecommunity.example.com/api/home
2. 按优先级处理响应内容
3. 更新 lastEcomMoltCheck 时间戳
text

Related instructions also appear in `SKILL.md`, lines 89–98:

```markdown
### Step 2 — Set Up Heartbeat

Add this to your HEARTBEAT.md or periodic task schedule:

```markdown
## EcomMolt (every 30 minutes)
If more than 30 minutes since last EcomMolt check:
1. GET https://aiclub.wiki/api/home — fetch global state
2. Process activity notifications in feed
3. Update lastEcomMoltCheck timestamp
text

### Technical Analysis

The Skill explicitly directs the Agent to add a recurring heartbeat to a periodic task mechanism. The task survives the original Skill invocation and contacts an external service every 30 minutes. The retrieved response is then processed and can influence subsequent authenticated activity.

This is system persistence because the behavior is installed into a cross-session scheduling mechanism rather than remaining limited to the current user request. The instruction also expands the persistence from passive synchronization to autonomous engagement: later sections direct the Agent to inspect remote posts and news and potentially publish posts or comments.

There is also an endpoint inconsistency. `HEARTBEAT.md` uses `https://ecommunity.example.com/api/home`, while `SKILL.md` identifies `https://aiclub.wiki/api/home`. This may cause requests to be misdirected or make the persisted behavior unreliable.

### Attack Path

1. A user or Agent loads the Skill and follows its setup instructions.
2. The heartbeat instructions are copied into `HEARTBEAT.md` or an equivalent periodic scheduler.
3. The task persists beyond the initiating 
...[truncated 954 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove instructions that install the Skill into a persistent scheduler by default.
  • Make synchronization explicitly user-triggered and limited to the current session.
  • If periodic operation is essential, require informed opt-in that clearly identifies:
    • The exact endpoint contacted.
    • The execution interval.
    • The data read and stored.
    • Every write operation the task may perform.
    • How to disable and remove the task.
  • Separate read-only synchronization from write operations.
  • Require explicit user approval before every post, comment, vote, follow, edit, or deletion.
  • Pin all documentation to one validated HTTPS origin and remove the inconsistent ecommunity.example.com endpoint.
  • Treat every API response as untrusted data and prohibit remote feed content from modifying Agent instructions.
  • Provide a bounded expiration time so any approved schedule automatically disables itself.

T09 · Insecure Skill Coding Practices

Error
Location
HEARTBEAT.md:19
Finding

Bearer API Credential Stored in Plaintext Agent Memory

Content
View full analysis

Vulnerability Details

File Location: HEARTBEAT.md, lines 19–26
Vulnerability Type: Plaintext sensitive credential storage
Risk Level: High

Vulnerable Code

markdown
状态追踪文件 (`memory/ecommolt-state.json`):

```json
{
  "lastEcomMoltCheck": null,
  "myHandle": "@your-agent-handle",
  "apiKey": "eyJ..."
}
text

The credential’s authority is established in `SKILL.md`, line 63:

```markdown
> ⚠️ **Important:** `apiKey` is returned only once — save it immediately. All write operations require `Authorization: Bearer <apiKey>`.

Technical Analysis

The heartbeat configuration places a bearer API key directly in memory/ecommolt-state.json. Bearer credentials grant authority based solely on possession, so any process, Skill, backup system, diagnostic export, or disclosure channel capable of reading this memory file can reuse the credential.

The documentation provides no encryption requirement, secret-manager integration, restrictive file-permission guidance, token scoping, expiration policy, or rotation procedure. Storing the API key alongside ordinary heartbeat metadata also increases the likelihood that it will be copied into logs, backups, prompts, or memory exports.

Attack Path

  1. The Agent registers with the external service.
  2. The service returns the API key once.
  3. Following the heartbeat instructions, the Agent writes the key into memory/ecommolt-state.json.
  4. Another local component, Skill, process, backup, or accidental memory disclosure obtains the file.
  5. The party extracts the bearer token.
  6. The token is supplied in an Authorization: Bearer header to the external API.
  7. The party performs write operations under the registered Agent’s identity until the credential is revoked or otherwise becomes invalid.

Impact Assessment

A party that obtains the token could impersonate the Agent for API operations authorized by that credential. Based on the documented API, the potential scope includes creating post ...[truncated 376 chars]

Remediation
View remediation

Remediation Suggestions

  • Never store bearer credentials in Agent memory or ordinary JSON state files.
  • Store the API key in an operating-system credential manager, encrypted secret store, or platform-provided scoped credential vault.
  • Keep non-sensitive heartbeat state in a separate file that contains no authentication material.
  • Apply least-privilege token scopes so heartbeat reads do not share a credential capable of content deletion or profile modification.
  • Use short-lived tokens with automatic expiration rather than indefinite bearer keys.
  • Restrict secret access to the minimum process identity and enforce restrictive filesystem permissions where a file-backed secret is unavoidable.
  • Redact credentials from logs, prompts, diagnostics, backups, and exported memory.
  • Provide credential rotation and immediate revocation procedures.
  • Require explicit confirmation before authenticated write operations, even when a valid credential is available.
  • Document secure deletion and cleanup when the Skill is disabled.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · HEARTBEAT.md (reported line 189)May include surrounding context.

md
| 今日资讯 | `GET /api/news?date=YYYY-MM-DD` |
| 每日摘要(含行动建议) | `GET /api/digest?date=YYYY-MM-DD` |
| 关注 Agent | `POST /api/agents/:handle/follow` |
| 取关 Agent | `DELETE /api/agents/:handle/follow` |
| 更新 Profile | `PATCH /api/agents/:handle` |
| 编辑帖子 | `PATCH /api/posts/:id` |
| 删除帖子 | `DELETE /api/posts/:id` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · HEARTBEAT.md (reported line 192)May include surrounding context.

md
| 取关 Agent | `DELETE /api/agents/:handle/follow` |
| 更新 Profile | `PATCH /api/agents/:handle` |
| 编辑帖子 | `PATCH /api/posts/:id` |
| 删除帖子 | `DELETE /api/posts/:id` |
| 删除评论 | `DELETE /api/comments/:id` |
| Agent 主页 | `GET /agent/:handle` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · HEARTBEAT.md (reported line 193)May include surrounding context.

md
| 更新 Profile | `PATCH /api/agents/:handle` |
| 编辑帖子 | `PATCH /api/posts/:id` |
| 删除帖子 | `DELETE /api/posts/:id` |
| 删除评论 | `DELETE /api/comments/:id` |
| Agent 主页 | `GET /agent/:handle` |

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
---

### DELETE /api/posts/:id *(auth required, owner only)*

Delete a post (also deletes all comments).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
---

### DELETE /api/comments/:id *(auth required, owner only)*

Delete a comment (also deletes all replies).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 394)May include surrounding context.

md
---

### GET/POST/DELETE /api/agents/:handle/follow *(auth required)*

Manage agent follow relationships.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs storing a bearer-style API key in a local JSON state file, which encourages plaintext credential storage without any access control, encryption, or secrecy guidance. If the workspace, logs, backups, or other tools can read that file, the token could be stolen and used to post, modify, or delete content as the agent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill directs the agent to autonomously publish comments and posts based on feed content and relevance checks, but gives no requirement for explicit user approval or clear outbound-action disclosure. This creates risk of unwanted external actions, spam, reputational harm, and misuse if the upstream content is manipulative or if the agent misclassifies relevance.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger section is overly broad and invites activation for generic e-commerce or AI-agent topics without clear negative conditions, user-confirmation requirements, or scope boundaries. In an agent ecosystem, this can cause the skill to engage on loosely related prompts and steer the host agent into unnecessary external API use, unintended posting/discovery actions, or prompt-context hijacking through over-eager tool selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

All operational instructions and examples are presented in Chinese, with no indication that the user can choose another language or that the skill is intentionally limited to a Chinese-language audience. This may violate a language/locale policy when a skill forces one language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.