Back to skill

Security audit

Memelord

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but it has unsafe credential/config handling and webhook helper behaviors that deserve manual review before installation.

Install only if you trust this publisher and memelord.com with the prompts, template data, generated media metadata, and API-backed requests you send. Do not use a `.env` file from an untrusted source, avoid putting webhook secrets directly on the command line, and treat downloaded media URLs and output paths as untrusted unless you control them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
_env.sh:4
Finding

Arbitrary Shell Execution Through Unsafe .env Loading

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/ai-video-meme.sh:46
Finding

Webhook Secrets Exposed Through Process Arguments

Content
View full analysis
"$TMP_BODY" const prompt = process.argv[2]; const count = process.argv[3]; const webhookUrl = process.argv[4]; const webhookSecret = process.argv[5]; const category = process.argv[6]; const templateId = process.argv[7]; const body = { prompt }; if (count) body.count = Number(count); if (webhookUrl) body.webhookUrl = webhookUrl; if (webhookSecret) body.webhookSecret = webhookSecret; ``` From `scripts/verify-webhook.sh`: ```bash --secret) SECRET="$2"; shift 2;; --body-file) BODY_FILE="$2"; shift 2;; --signature) SIG="$2"; shift 2;; ``` ```bash COMPUTED=$(node - <<'NODE' "$SECRET" "$BODY_FILE" const fs = require('fs'); const crypto = require('crypto'); const secret = process.argv[2]; const bodyPath = process.argv[3]; const raw = fs.readFileSync(bodyPath); const h = crypto.createHmac('sha256', secret).update(raw).digest('hex'); ``` The documentation also recommends placing the secret directly on the command line: ```bash ./scripts/ai-video-meme.sh "ship it" \ --webhook-url https://example.com/webhook \ --webhook-secret supersecret ``` ### Technical Analysis Webhook secrets are accepted directly as shell command-line arguments. They are then passed a second time through the Node.js process argument vector. Depending on operating-system process visibility and monitoring configuration, command arguments can be observed by other local users or processes, process-monitoring agents, diagnostic tools, audit systems, a ...[truncated 1269 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/verify-webhook.sh:61
Finding

Failed Webhook Verification Reveals the Correct HMAC

Content
View full analysis
` for the attacker-controlled body. 5. The attacker observes the response or obtains the corresponding log entry. 6. The attacker resubmits the same body with the disclosed HMAC. 7. Any system relying on the same secret and payload format accepts the forged request as authentic. ### Impact Assessment An attacker with access to this oracle can obtain a valid signature for each chosen body submitted to it. This can defeat webhook authenticity checks and enable forged authenticated ev ...[truncated 249 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (26)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The documented behavior and declared metadata do not cleanly match the operational capabilities described in the markdown, especially around external API use and helper operations. When a skill understates or misstates what it can do, users and policy layers may approve it under false assumptions, increasing the chance of unexpected network access, credential use, or file operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding

The documented behavior and declared metadata do not cleanly match the operational capabilities described in the markdown, especially around external API use and helper operations. When a skill understates or misstates what it can do, users and policy layers may approve it under false assumptions, increasing the chance of unexpected network access, credential use, or file operations.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The documented behavior and declared metadata do not cleanly match the operational capabilities described in the markdown, especially around external API use and helper operations. When a skill understates or misstates what it can do, users and policy layers may approve it under false assumptions, increasing the chance of unexpected network access, credential use, or file operations.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 98)May include surrounding context.

md
| `scripts/ai-meme.sh` | `POST /api/v1/ai-meme` | Generate fresh image memes |

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · _env.sh (reported line 4)May include surrounding context.

sh
# shellcheck shell=bash

# Auto-loads local environment overrides for the Memelord skill.
ENV_FILE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)/.env"
if [[ -f "$ENV_FILE" ]]; then
  # Export everything defined in .env so child processes inherit the values.
  set -a

Credential Access

High
Category
Privilege Escalation
Confidence
90% confidence
Finding

At this point the script enables automatic export and sources the .env file, causing any credentials or sensitive values in that file to become environment variables for child processes. In an agent skill, this increases the chance of unintended credential exposure to invoked tools, logs, plugins, or remote services, and also lets a tampered .env alter execution through environment-driven behavior.

Content

Scanner excerpt · _env.sh (reported line 6)May include surrounding context.

sh
# Auto-loads local environment overrides for the Memelord skill.
ENV_FILE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)/.env"
if [[ -f "$ENV_FILE" ]]; then
  # Export everything defined in .env so child processes inherit the values.
  set -a
  # shellcheck disable=SC1090
  source "$ENV_FILE"

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding

The skill explicitly instructs use of shell commands and networked helper scripts but does not declare any tool scope such as permissions or allowed-tools. This creates a trust and enforcement gap: a host may allow broader execution than users expect, including external API calls and file writes, which is risky for a skill that handles API keys and downloads remote content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill encourages webhook callbacks to arbitrary external URLs without warning users about data exposure, request forgery risks, or the sensitivity of job metadata sent off-platform. In contexts where prompts, asset URLs, or identifiers may be sensitive, silent exfiltration to third-party endpoints is a meaningful privacy and security risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script automatically sources a local .env file and exports all variables to child processes without any validation, scoping, or user disclosure. This can expose secrets to downstream commands and allows a locally modified .env file to influence the behavior of any subprocess launched by the skill, which is risky in an agent context where external tools or networked commands may run.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ai-meme-edit.sh (reported line 119)May include surrounding context.

sh
process.stdout.write(JSON.stringify(body));
NODE

curl -sS -X POST 'https://www.memelord.com/api/v1/ai-meme/edit' \
  -H "Authorization: Bearer $MEMELORD_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-binary @"$TMP_BODY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ai-video-meme-edit.sh (reported line 91)May include surrounding context.

sh
process.stdout.write(JSON.stringify(body));
NODE

curl -sS -X POST 'https://www.memelord.com/api/v1/ai-video-meme/edit' \
  -H "Authorization: Bearer $MEMELORD_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-binary @"$TMP_BODY" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script explicitly supports a user-supplied webhook URL and states that generated results will be posted there, but it provides no warning, validation, or restriction around where those results may be sent. In an agent or automation context, this creates a real data egress risk because prompts, generated content, job metadata, or follow-up results could be transmitted to arbitrary third-party endpoints without meaningful user awareness.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
86% confidence
Finding

This script sends user-provided prompt data, optional webhook details, and authentication-backed requests to an external service at memelord.com. While external API calls are expected for this skill, it is still a true security-relevant data transmission finding because the script exports potentially sensitive input off-host and can initiate downstream delivery to attacker-controlled webhook infrastructure if those options are used.

Content

Scanner excerpt · scripts/ai-video-meme.sh (reported line 79)May include surrounding context.

sh
process.stdout.write(JSON.stringify(body));
NODE

curl -sS -X POST 'https://www.memelord.com/api/v1/ai-video-meme' \
  -H "Authorization: Bearer $MEMELORD_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-binary @"$TMP_BODY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/ai-meme.sh (reported line 77)May include surrounding context.

sh
node -p 'JSON.stringify({prompt: process.argv[1]})' "$PROMPT" > "$TMP_BODY"
fi

curl -sS -X POST 'https://www.memelord.com/api/v1/ai-meme' \
  -H "Authorization: Bearer $MEMELORD_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-binary @"$TMP_BODY" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/render.sh (reported line 65)May include surrounding context.

sh
node -p 'JSON.stringify({prompt: process.argv[1]})' "$PROMPT" > "$TMP_BODY"
fi

curl -sS -X POST 'https://www.memelord.com/api/v1/ai-meme' \
  -H "Authorization: Bearer $MEMELORD_API_KEY" \
  -H 'Content-Type: application/json' \
  --data-binary @"$TMP_BODY" \

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The fallback image retrieval logic performs an HTTPS GET to whatever URL the remote API returns, including one redirect hop, with no allowlist or host validation. This expands the skill from 'send prompt to meme API' into arbitrary outbound fetching directed by API-controlled data, which can be abused for SSRF-like network access, unexpected data egress, or downloading untrusted content to disk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This shell script performs a network call to a remote service with a bearer token from an environment variable, and optionally writes the returned JSON to a user-specified file. While the behavior is inferable from the script, there is no confirmation prompt or explicit user-facing warning in comments or usage text that sensitive credentials are used and that data is sent to an external service and may be saved locally.

Content

No source excerpt is available for this finding.

Vague Triggers

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This markdown skill description says the skill is for 'AI-powered meme generation, meme editing, meme video generation for your projects' but does not define any trigger phrases, scope boundaries, or negative examples. In a skill catalog, such broad natural-language descriptions can overlap with many casual meme-related requests and make invocation conditions unclear.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
78% confidence
Finding

The instructions tell users to download remote assets directly into the workspace with curl, but omit warnings about trusting the source URL, overwriting files, or handling untrusted content. While the downloaded files are expected media, this still introduces a path for bringing attacker-controlled content into the local environment without cautionary guidance.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This shell script sends the instruction, template data, and template identifier to an external HTTPS endpoint and authenticates with MEMELORD_API_KEY. Although comments describe the API call for readers of the source, there is no runtime warning, confirmation, or user-facing notice that local meme/template content is being uploaded to a remote service.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The manifest describes meme generation and editing functionality, but the script additionally sources a local _env.sh file, which can import arbitrary environment variables or shell-side configuration. While loading an API key is needed, executing a general environment bootstrap script is a broader capability than the stated meme-generation purpose itself justifies.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

This shell skill writes image data to a user-specified path via fs.writeFileSync when --png is used, but the code itself provides no confirmation prompt or runtime notice before creating files. The top-of-file comments describe the behavior, but there is no direct user-facing warning at the point of execution about local file creation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.