Back to skill

Security audit

Artwar

Security checks for vulnerabilities and agentic risk

Overview

This skill matches its ArtWar purpose, but it asks agents to use an unsecured HTTP API with reusable credentials and perform blockchain betting actions without enough safeguards.

Review before installing. Only use this with disposable/test wallets and non-sensitive artwork, verify the Monad testnet chain ID and contract address independently, and do not let an agent sign or broadcast transactions without explicit user approval. Treat the API key as a secret. The HTTP raw-IP API means wallet addresses, API keys, uploads, comments, and bet records may be exposed or tampered with on the network.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:10
Finding

API Credentials and Authenticated Requests Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–106
Vulnerability Type: Plaintext transmission of sensitive authentication data
Risk Level: High

The Skill configures its remote API with an unencrypted HTTP URL and instructs users to transmit API keys and authenticated requests to that endpoint.

markdown
**Base URL:** `http://54.162.153.8:3000`

Representative registration and authenticated request examples include:

bash
curl -X POST http://54.162.153.8:3000/api/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YourAgent", "role": "artist", "walletAddress": "0xYourWallet"}'
bash
curl http://54.162.153.8:3000/api/rounds/current/state \
  -H "X-API-Key: YOUR_API_KEY"
bash
curl -X POST http://54.162.153.8:3000/api/upload-image \
  -H "X-API-Key: YOUR_API_KEY" \
  -F "image=@artwork.png"
bash
curl -X POST http://54.162.153.8:3000/api/bet \
  -H "X-API-Key: YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"roundId": 1, "submissionId": 1, "amount": "0.001", "txHash": "0x..."}'

Technical Analysis

HTTP does not provide transport encryption, message integrity, or cryptographic server authentication. The registration response containing the API key and all subsequent X-API-Key headers are therefore exposed to any attacker capable of observing or manipulating traffic between the agent and the server.

A network-positioned attacker could capture a reusable API key through passive inspection. An active attacker could also modify API responses, uploaded artwork, submission metadata, round state, odds, submission identifiers, or transaction-recording requests. Using a raw IP address over HTTP provides no authenticated hostname or certificate identity through which the client can verify the intended server.

Although the documented blockchain RPC uses HTTPS and a network attacker cannot directly sign transactions ...[truncated 1800 chars]

Remediation
View remediation

Remediation Suggestions

  1. Host the API on a stable domain protected by HTTPS with a certificate issued by a trusted certificate authority.
  2. Replace every occurrence of http://54.162.153.8:3000 with the verified HTTPS origin.
  3. Reject plaintext HTTP connections at the server or network boundary. Do not rely solely on redirects because credentials may already be exposed in the initial HTTP request.
  4. Rotate all API keys that may previously have been returned or transmitted over plaintext HTTP.
  5. Use short-lived, revocable authentication tokens with narrowly scoped role permissions rather than indefinitely reusable credentials.
  6. Avoid logging API keys and redact the X-API-Key header from client, proxy, and server logs.
  7. Before requesting a blockchain signature, independently verify the chain ID, contract address, method arguments, submission identifier, recipient, and transaction value. Do not rely exclusively on data obtained from the off-chain API.
  8. Consider request signing or application-level integrity protection for security-sensitive API operations as defense in depth, while retaining HTTPS as the mandatory transport.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

External Transmission

Medium
Category
Data Exfiltration
Confidence
94% confidence
Finding

The skill directs the agent to transmit identifying data, including a wallet address, to an external service over plain HTTP to a raw IP address rather than HTTPS. This exposes registration traffic and API key issuance to interception or tampering by an on-path attacker, and the use of a non-domain endpoint reduces trust and provenance verification.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

1. Register

bash
curl -X POST http://54.162.153.8:3000/api/register \
  -H "Content-Type: application/json" \
  -d '{"name": "YourAgent", "role": "artist", "walletAddress": "0xYourWallet"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to place on-chain bets and claim winnings but provides no explicit warning that these actions spend cryptocurrency, are irreversible once broadcast, and may target the wrong chain or contract if misconfigured. In an autonomous-agent context, this is dangerous because it can normalize sending real value to a contract address based solely on unverified skill instructions, increasing risk of financial loss from mistakes, spoofed infrastructure, or maliciously substituted addresses.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells users to save and reuse an API key but gives no guidance to treat it as a secret or avoid logging, sharing, or embedding it in prompts and scripts. If exposed, the key could be used to impersonate the agent for submissions, comments, reactions, or other authenticated actions against the service.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.