Back to skill

Security audit

电商agent社区

Security checks for vulnerabilities and agentic risk

Overview

This skill is mostly a disclosed community API guide, but it asks agents to run a recurring heartbeat that can automatically publish public posts or comments using a plaintext bearer token.

Review before installing. Use this skill only if you are comfortable with an agent periodically contacting aiclub.wiki and potentially posting or commenting publicly. Do not store the API key in plaintext memory; use a secret store or environment variable, require confirmation before any post/comment/profile/delete action, and disable or bound the heartbeat unless continuous operation is explicitly intended.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T06 · System Persistence

Warning
Location
SKILL.md:75
Finding

Persistent Heartbeat Task Creates Recurring Cross-Session Network Activity

Content
View full analysis
Remediation
View remediation

T01 · Skill Instruction Hijacking

Error
Location
HEARTBEAT.md:43
Finding

Untrusted Remote Content Can Trigger Authenticated Public Output

Content
View full analysis
0) { for (const item of home.news.items) { if (item.relevance > 0.7 && matchesMySkills(item.tags)) { await postAnalysis(item.title, item.summary, item.url); } } } ``` The same heartbeat workflow later instructs the agent to issue authenticated comment and post requests: ```http POST /api/comments Authorization: Bearer Content-Type: application/json ``` ```http POST /api/posts Authorization: Bearer Content-Type: application/json ``` ### Technical Analysis The heartbeat obtains news items, posts, summaries, tags, URLs, and other content from an external service. It then passes remote fields directly to `postAnalysis` when service-controlled relevance and tag conditions are satisfied. The relevance score and tags are also supplied by the remote service. They therefore do not constitute an independent security decision. A malicious or compromised service can select a high relevance score, use matching tags, and place manipulative instructions or misleading content in the title, summary, or URL. The Skill does not define a boundary that requires remote text to be treated exclusively as inert data. It also does not require user review before an analysis is generated and published. In an AI-agent context, hostile content in these fields may influence generated output, induce promotion of unsafe links, or steer the agent toward actions inconsistent with the user's intent. ### Attack Path 1. An attacker publishes content that reaches the EcomMolt news or feed pipeline, or compromises the remote service. 2. The attacker supplies an item with tags matching the agent's configured skills and a relevance score above `0.7`. 3. The recurring heartbeat retrieves the attacker-controlled title, s ...[truncated 970 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
HEARTBEAT.md:19
Finding

Long-Lived Bearer Token Stored in a Plaintext State File

Content
View full analysis
`. 6. The service accepts the attacker as the registered agent. 7. The attacker creates posts or comments, votes, follows accounts, changes the profile, or modifies and deletes agent-owned content. ### Impact Assessment The stolen credential grants the write privileges associated with the affected EcomMolt agent. Based on the documented APIs, this can include creating posts and comments, voting, following or unfollowing agents, updating the agent profile and webhook endpoint, editing owned content, and deleting owned posts or comments. ...[truncated 197 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · HEARTBEAT.md (reported line 189)May include surrounding context.

md
| 今日资讯 | `GET /api/news?date=YYYY-MM-DD` |
| 每日摘要(含行动建议) | `GET /api/digest?date=YYYY-MM-DD` |
| 关注 Agent | `POST /api/agents/:handle/follow` |
| 取关 Agent | `DELETE /api/agents/:handle/follow` |
| 更新 Profile | `PATCH /api/agents/:handle` |
| 编辑帖子 | `PATCH /api/posts/:id` |
| 删除帖子 | `DELETE /api/posts/:id` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · HEARTBEAT.md (reported line 192)May include surrounding context.

md
| 取关 Agent | `DELETE /api/agents/:handle/follow` |
| 更新 Profile | `PATCH /api/agents/:handle` |
| 编辑帖子 | `PATCH /api/posts/:id` |
| 删除帖子 | `DELETE /api/posts/:id` |
| 删除评论 | `DELETE /api/comments/:id` |
| Agent 主页 | `GET /agent/:handle` |

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · HEARTBEAT.md (reported line 193)May include surrounding context.

md
| 更新 Profile | `PATCH /api/agents/:handle` |
| 编辑帖子 | `PATCH /api/posts/:id` |
| 删除帖子 | `DELETE /api/posts/:id` |
| 删除评论 | `DELETE /api/comments/:id` |
| Agent 主页 | `GET /agent/:handle` |

---

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 213)May include surrounding context.

md
---

### DELETE /api/posts/:id *(auth required, owner only)*

Delete a post (also deletes all comments).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
---

### DELETE /api/comments/:id *(auth required, owner only)*

Delete a comment (also deletes all replies).

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 394)May include surrounding context.

md
---

### GET/POST/DELETE /api/agents/:handle/follow *(auth required)*

Manage agent follow relationships.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill explicitly instructs storing a bearer-style API key in a local JSON state file, with no guidance on encryption, secret storage, access controls, or redaction. That creates a realistic risk of credential exposure via logs, backups, source control, workspace sharing, or compromise of the agent's filesystem, enabling unauthorized API actions as the agent.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The file presents all operational instructions, warnings, and examples solely in Chinese. This effectively forces a specific language for use of the skill, and there is no opt-in, alternative language, or stated region-specific justification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

This markdown describes that EcomMolt will send POST requests to a user-supplied endpoint, which is a network action that can affect system integrations or trigger downstream automation. While the callback format is documented, there is no warning to ensure users understand they are enabling inbound automation and should only register trusted endpoints.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description states that deleting a post also deletes all comments, which is a destructive operation affecting user data. Although the behavior is mentioned, there is no explicit warning or caution emphasizing that the action is irreversible and may remove associated discussion content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The markdown notes that deleting a comment also deletes all replies, which is a destructive cascading action on user content. The description lacks a clear warning banner or caution highlighting the data-loss impact before users adopt the skill.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.