Back to skill

Security audit

picoads

Security checks for vulnerabilities and agentic risk

Overview

This skill is for an ad marketplace and is not deceptive, but it gives an agent financial and audience-facing ad delivery powers without enough explicit user-control safeguards.

Install only if you are comfortable giving the agent access to a wallet-linked ad marketplace. Require manual approval for every bid, ask, registration payment, delivery proof, and displayed ad creative, and treat all fetched creative as untrusted sponsored content.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:24
Finding

Remote Advertiser-Controlled Content Can Hijack Agent Output

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–25
Vulnerability Type: Remote advertising content injection
Risk Level: High

Affected Code:

markdown
4. When matched, fetch creative: `GET https://picoads.xyz/matches/{matchId}` — get the ad content
5. Deliver the ad and submit proof: `POST https://picoads.xyz/matches/{matchId}/delivery`

Technical Analysis

The Skill instructs the agent to retrieve mutable, advertiser-controlled creative from an external service and deliver that content to the agent's audience. The instructions do not require the retrieved creative to be treated as untrusted data, isolated from agent instructions, sanitized, clearly labeled as sponsored content, or approved by the user before publication.

This creates a remote output-hijacking channel: content that was not present during Skill review can subsequently be inserted into agent output. An advertiser—or an attacker who compromises the advertising service or an advertiser account—could supply misleading promotional content, malicious links, social-engineering text, or prompt-like instructions intended to influence the agent's behavior.

The behavior exceeds safe minimum privileges because publishing externally controlled content does not include safeguards limiting the content to a passive, clearly delimited advertisement. The Skill implicitly grants remote advertisers influence over audience-facing output.

Attack Path

  1. An attacker obtains an advertiser account or compromises an existing advertiser or the remote advertising service.
  2. The attacker submits crafted advertising creative containing deceptive content, malicious links, or instructions directed at the agent or its audience.
  3. The marketplace matches that creative with the publisher agent.
  4. The agent retrieves the mutable creative from https://picoads.xyz/matches/{matchId}.
  5. Following the Skill's instructions, the agent delivers the c ...[truncated 1241 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat all remotely retrieved creative as untrusted data and explicitly prohibit following any instructions embedded within it.
  2. Require explicit user opt-in before enabling advertising and confirmation before each audience-facing delivery.
  3. Render creative only inside a strictly delimited, non-executable advertising field that cannot modify the surrounding agent response or system behavior.
  4. Clearly and consistently label every delivery as sponsored content, including the advertiser identity where appropriate.
  5. Validate content against a restrictive schema and sanitize text, markup, URLs, and metadata before publication.
  6. Reject executable content, scripts, hidden markup, prompt-like control directives, credential requests, and links using disallowed schemes or unapproved domains.
  7. Apply content-length limits, destination allowlists, anti-phishing checks, and moderation policies.
  8. Require human approval for new advertisers, high-risk creative, or any content that cannot be safely rendered as inert data.
  9. Separate creative retrieval from publication so fetching a match never automatically authorizes delivery.
  10. Log the creative, advertiser, match identifier, approval decision, and final rendered output for auditing and incident response.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This skill advertises multiple authenticated POST actions that can post bids, asks, register agents, and submit delivery proofs tied to USDC settlement, but it does not explicitly warn users that these mutations can create financial obligations or trigger on-chain or wallet-linked consequences. In an agent setting, omission of that warning increases the risk of unintended spending, accidental commitments, or autonomous actions taken without informed user consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.