Back to skill

Security audit

Agent Selfie

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a coherent Gemini-based avatar generator, but its heartbeat guide under-scopes recurring public avatar changes and memory writes.

Install only if you are comfortable with a skill that can generate files locally and call Gemini with your API key. Do not allow heartbeat workflows to change Discord, Twitter/X, AgentGram, or other public avatars unless you have reviewed the image and explicitly approved the target account each time. Keep the Gemini key out of committed files, shell-history-heavy workflows, and inline cron entries where possible.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/selfie.py:149
Finding

Stored HTML Injection in the Generated Gallery

Content
View full analysis
None: thumbs = "\n".join( [ f'\n' f' \n' f' {it["prompt"]}\n' f'' for it in items ] ) ``` The injected value originates from personality data accepted by `load_personality()` and incorporated into the prompt by `build_prompt()`: ```python merged = dict(DEFAULT_PERSONALITY) merged.update({k: v for k, v in data.items() if v}) return merged ``` ### Technical Analysis The `name`, `style`, and `vibe` personality properties may come from an inline JSON argument or a user-supplied JSON file. These values are interpolated into the generated prompt without type validation or HTML output encoding. The resulting prompt is then inserted directly into a `` element. An attacker-controlled value containing HTML, such as a closing `figcaption` tag followed by a `script` element or an event-handler attribute, is therefore interpreted as markup when the gallery is opened. The generated `index.html` is a persistent artifact, making this a stored injection issue rather than a transient display problem. Exploitation requires the user or another application to open or host the generated gallery. ### Attack Path 1. An attacker supplies or convinces the user to use a personality JSON file containing malicious HTML in a personality field. 2. `load_personality()` accepts the value without restricting it to safe plain text. 3. `build_prompt()` incorporates the malicious value into the prompt. 4. Image generation completes, and the prompt is stored in the gallery item. 5. `write_gallery()` inserts the prom ...[truncated 715 chars]
Remediation
View remediation
`, ``, quotes, and event-handler attributes. - If galleries may be hosted, deploy a restrictive Content Security Policy that disallows inline scripts as defense in depth. ]]>

T08 · Insecure Dependencies

Warning
Location
INSTALL.md:3
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation
install agent-selfie ``` - Document the expected package publisher, version, and integrity digest. - Prefer a lockfile-backed installation process or a locally installed, verified CLI. - Avoid automatically updating to an unreviewed version. - Require package signature or checksum verification where the distribution platform supports it. - Document the registry expected to serve the package and warn users that custom registry configuration changes the trust boundary. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
INSTALL.md:28
Finding

Gemini API Key Stored in Plaintext Persistent Configuration

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (9)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The heartbeat instructions extend a selfie-generation skill into making external account changes and storing persistent memory state, which exceeds the narrowly described purpose of generating images. This creates unnecessary authority creep: a periodic task could modify third-party profiles or accumulate state without explicit per-action approval, increasing the risk of unwanted or abusive agent behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Directing the agent to update Discord, Twitter, or similar avatars is not necessary for producing a self-portrait and introduces account-impacting actions unrelated to the core skill. In the context of an automated heartbeat, this could lead to unauthorized or surprising public-facing profile changes across external services.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The instructions describe changing social-media avatars without any warning, approval requirement, or confirmation step for an account-affecting action. Because avatar updates alter public identity and may trigger downstream trust or branding consequences, allowing them silently from a recurring process is unsafe.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The install instruction uses npx clawhub install agent-selfie without pinning a specific package/version, which means users may execute whatever version is currently served at install time. This creates a supply-chain risk: a compromised or maliciously updated package, dependency, or distribution channel could run attacker-controlled code during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The update command npx clawhub update agent-selfie is also unpinned, so future updates may fetch and execute code that differs from what the user originally reviewed or trusted. If the upstream package or its dependencies are compromised, this can lead to arbitrary code execution in the user's environment during update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The README instructs users to run npx clawhub install agent-selfie without pinning a specific package version. This can expose users to supply-chain risk if the clawhub package or one of its transient dependencies is updated maliciously or unexpectedly, causing unreviewed code to execute during installation.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill requests and demonstrates capabilities that can access environment variables, read and write files, and make network requests, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates a transparency and least-privilege gap: a host agent may invoke the skill without clear restrictions, increasing the chance of unintended secret access (for example GEMINI_API_KEY), filesystem modification, or external data exfiltration if the implementation is changed or abused.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The quickstart uses npx clawhub install agent-selfie without pinning an exact package version, which can cause users to execute whatever version of clawhub is current at install time. If the upstream package is compromised, typosquatted, or updated with malicious behavior, the install path could execute attacker-controlled code on the user's machine.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README tells users to export GEMINI_API_KEY and use it immediately, but it provides no warning about secret handling, shell history, multi-user environments, or avoiding committing keys into files. While common in setup docs, this omission can lead to accidental credential exposure, especially for less experienced users following copy-paste instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.