Back to skill

Security audit

Haah: Ask your trusted circle.

Security checks for vulnerabilities and agentic risk

Overview

This is a real social-messaging skill, but it needs review because incoming messages can drive local private-data lookups and the skill can send or broadcast information externally.

Install only if you are comfortable with an agent using your Haah API key, storing local caches of circles and DM contacts, and sending messages to real people. Keep heartbeat/cron disabled unless you want recurring polling, review every outbound draft for private data, and prefer a pinned or reviewed install source over the README's moving main-branch and unpinned npx commands.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • System PersistenceInstalls backdoors, hooks, services, or scheduled tasks that survive the run
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:207
Finding

Untrusted Remote Messages Can Influence Access to Local Personal Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 207-213
Vulnerability Type: T01: Skill Instruction Hijacking
Risk Level: Medium

Code Snippet:

markdown
- **`type: "question"`** — show: **"[from_name]** (via [circle]) asks: [query]". If `image_url`, show it. If the message has a `poll`, display options as a numbered list and ask the human to pick. Otherwise draft a full answer (check Peeps, Nooks, Pages, Vibes, Digs first). Ask: **"send or discard?"** If sending and `open_to_connections` is false, warn: _"Your profile is closed — the asker won't get a link to connect with you. Open up at haah.ing/profile, or send anyway?"_ Send → `POST /messages/:id/reply` · Discard → `POST /messages/:id/pass`
- **`type: "dm"`** — show: **"DM from [from_name]:** [text]". Ask: _"Want to reply?"_ If yes, draft, confirm, and `POST /messages/:id/reply`.

If `has_more` is true: _"Want to see more?"_ → `GET /messages?all=true`.

Technical Analysis

Question and DM bodies originate from remote users and are therefore untrusted input. The Skill instructs the agent to use an inbound question to draft an answer after consulting the local Peeps, Nooks, Pages, Vibes, and Digs Skills. It does not establish a trust boundary that requires remote content to be treated solely as data, nor does it prohibit following instructions embedded in messages or accessing unrelated private records.

An attacker could phrase a question as an instruction to search local sources for sensitive information and include that information in the response. Although the Skill requires the user to approve a reply before it is sent, approval occurs only after potentially sensitive data has already been collected into a draft. A plausible or misleading draft could also cause a user to approve disclosure inadvertently.

Attack Path

  1. An attacker gains the ability to send a circle question or direct message to the user.
  2. The scheduled heartbeat retr ...[truncated 1201 chars]
Remediation
View remediation

Remediation Suggestions

  • Explicitly classify every remote message field, including query, text, names, attachment contents, and image-derived text, as untrusted data.
  • Instruct the agent never to follow commands, policies, tool requests, or disclosure requests embedded in remote messages.
  • Restrict local lookups to information directly relevant to the substantive question and prohibit access to credentials, secrets, private messages, authentication material, or unrelated personal records.
  • Require the agent to identify which local sources it intends to consult and obtain permission before accessing sensitive sources.
  • Add a separate disclosure confirmation that displays the exact response, the local sources used, and any potentially sensitive facts included.
  • Apply data minimization and redact unnecessary names, identifiers, addresses, contact details, and private notes.
  • Treat attachment text and image content with the same injection protections as message text.

T06 · System Persistence

Note
Location
SKILL.md:13
Finding

Optional Heartbeat or Cron Setup Creates Persistent Recurring Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 13-16 and 32-33
Vulnerability Type: T06: System Persistence
Risk Level: Low

Code Snippet:

markdown
## Heartbeat

Add a `Haah dispatch` section to HEARTBEAT.md (ask permission first), or suggest a cron every 30 minutes during waking hours (`*/30 7-22 * * *`). On each heartbeat: call `GET /counts` first, then only dig deeper if something changed.
markdown
5. **Set up a heartbeat** — ask the human: _"Should I add a Haah section to your HEARTBEAT.md, or set up a cron every 30 minutes during waking hours (`*/30 7-22 * * *`)?"_ Haah only delivers value if it runs regularly. Don't skip this step.

Technical Analysis

The Skill encourages modification of HEARTBEAT.md or creation of a cron schedule that survives the current interaction and repeatedly performs authenticated network requests. Recurring polling is relevant to the declared inbox and dispatch functionality, and the Skill requires user permission before setup, so this is not a covert backdoor.

Nevertheless, the instructions do not provide a removal procedure, expiration policy, failure backoff, or credential-revocation guidance. The statement that setup must not be skipped may also pressure users toward enabling persistence when on-demand synchronization would require fewer privileges.

Attack Path

  1. The user installs and configures the Skill with a bearer key.
  2. The Skill asks the user to modify HEARTBEAT.md or establish the proposed cron schedule.
  3. The user approves the persistent setup.
  4. The agent executes GET /counts every 30 minutes during the configured hours and may retrieve messages or contact and circle data when state changes.
  5. Polling continues across sessions until the persistent configuration is manually removed or ceases to function.

Impact Assessment

This behavior does not independently grant elevated operating-system privileges. Its ...[truncated 484 chars]

Remediation
View remediation

Remediation Suggestions

  • Make scheduled synchronization clearly optional and support on-demand use as the least-privilege default.
  • Display the exact heartbeat or cron modification before requesting approval.
  • Use a platform-managed scheduler rather than directly modifying system cron where possible.
  • Document exact commands and file changes required to disable or uninstall the recurring task.
  • Add an expiration period, bounded retry behavior, and exponential backoff for failures.
  • Notify the user periodically that recurring polling remains active.
  • Revoke or remove the API credential when the schedule is disabled or the Skill is uninstalled.
  • Store authentication material in an operating-system credential store rather than a workspace plaintext file.

T08 · Insecure Dependencies

Warning
Location
README.md:35
Finding

Unpinned Package Execution Through npx Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: README.md, lines 35-37
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Code Snippet:

bash
npx skills add Know-Your-People/haah-skill

Technical Analysis

The installation command invokes npx without pinning the skills package to a reviewed version or verifying package integrity. Depending on the local environment and cache state, npx may retrieve and execute the package currently resolved by the package registry.

The effective installer code is therefore outside the reviewed two-file project and can change after this audit. Compromise of the package, publisher account, registry resolution, or dependency chain could cause arbitrary package lifecycle or installer code to execute under the installing user's privileges.

Attack Path

  1. An attacker compromises the package, a transitive dependency, the publisher account, or the relevant package-resolution path.
  2. A user follows the documented npx skills add Know-Your-People/haah-skill command.
  3. npx resolves and downloads the current unpinned package or uses a compromised cached artifact.
  4. The package executes with the permissions of the user running the installation command.
  5. Malicious installer code can access files, environment variables, credentials, and network resources available to that user.

Impact Assessment

Successful exploitation can execute arbitrary code with the invoking user's privileges. The reachable scope may include the user's files, agent configuration, workspace data, environment variables, locally stored tokens, and outbound network access. It does not inherently provide administrator or root privileges unless the command is run by a privileged account or another escalation vulnerability is present.

Remediation
View remediation

Remediation Suggestions

  • Pin the installer package to a specific audited version, for example by using an explicit package@version reference.
  • Provide and verify a cryptographic integrity hash or signed release artifact.
  • Document the expected package publisher, repository, release version, and checksum.
  • Prefer installation from a versioned, immutable release rather than an implicitly current registry package.
  • Recommend reviewing package contents and lifecycle scripts before first execution.
  • Where practical, use the direct HTTPS installation method with a pinned commit URL and checksum verification.
  • Avoid running the installer with administrator or root privileges.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (17)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 157)May include surrounding context.

md
Resolve a connect token to the sender's profile. Returns `{ first_name, email, picture, profile, circle }`. Returns 410 if expired.

### `GET /dm/hash` · `POST /dm/hash` · `DELETE /dm/hash`

Get / generate / close your DM hash. `POST` replaces any previous hash (anyone with the old one loses access). `DELETE` closes DMs entirely.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 175)May include surrounding context.

md
Download an attached file. Auth-required; the server verifies the caller either uploaded it, shares a circle with the uploader, or is the DM peer on a message referencing the attachment. Responds with the original `Content-Type`, the sanitised filename in `Content-Disposition: inline`, and a private 1 h cache.

### `GET /dm/blocks` · `DELETE /dm/blocks/:id`

List / unblock blocked DM senders.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

This workflow combines destructive account actions (DELETE /dm/hash) with an incorrect blocking instruction (POST /messages/:id/block), increasing the chance that an agent performs the wrong state-changing operation or fails to block a sender when the user expects protection. In a messaging skill handling inbound DMs, mistakes around blocking and DM openness materially affect user safety and privacy.

Content

Scanner excerpt · SKILL.md (reported line 225)May include surrounding context.

md
### Opening / closing DMs

1. Open: `POST /dm/hash` → cache the returned hash as `dm_hash` in `haahconfig.yml`.
2. Close: `DELETE /dm/hash` → set `dm_hash: null` in `haahconfig.yml`.
3. Block a specific sender: `POST /messages/:id/block`.
4. Regenerate (blocks everyone who had the old hash): `POST /dm/hash` again → update `dm_hash`.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The README prominently markets broadcasting natural-language queries to 'everyone in your circles' but does not pair that capability with a strong privacy warning about sensitive prompt contents being shared externally. In an agent context, users may ask questions containing confidential business, personal, or regulated data, and automatic escalation to a social network materially increases data leakage risk.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
85% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/haah
curl -o ~/.claude/skills/haah/SKILL.md https://raw.githubusercontent.com/Know-Your-People/haah-skill/main/SKILL.md

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

Claude Code

bash
mkdir -p ~/.claude/skills/haah
curl -o ~/.claude/skills/haah/SKILL.md https://raw.githubusercontent.com/Know-Your-People/haah-skill/main/SKILL.md

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

bash
mkdir -p ~/.claude/skills/haah
curl -o ~/.claude/skills/haah/SKILL.md https://raw.githubusercontent.com/Know-Your-People/haah-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · README.md (reported line 29)May include surrounding context.

bash
mkdir -p ~/.claude/skills/haah
curl -o ~/.claude/skills/haah/SKILL.md https://raw.githubusercontent.com/Know-Your-People/haah-skill/main/SKILL.md

Other agents

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 251)May include surrounding context.

bash
mkdir -p ~/.claude/skills/haah
curl -o ~/.claude/skills/haah/SKILL.md https://raw.githubusercontent.com/Know-Your-People/haah-skill/main/SKILL.md

Other agents

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 55)May include surrounding context.

md
## API

**Base:** `https://api.haah.ing/v6`
**Auth:** `Authorization: Bearer <key>`

### `GET /counts`

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

At L226, the 'Opening / closing DMs' workflow instructs the agent to call POST /messages/:id/block. Earlier API documentation specifies sender blocking through POST /dm/blocks with { "message_id": "..." } (L149-L152), so the workflow actively contradicts the documented interface.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The DM shortcut examples are broad enough to overlap with normal conversational phrasing, which can cause the agent to interpret ordinary text as an instruction to send an external direct message. In this skill, that risk is amplified because POST /dm/send transmits data to real contacts, so misparsing could leak user content or trigger unintended outbound messaging.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill mandates automatic translation of incoming messages without warning the user that message contents may be processed by a translation component or external service. Because this skill handles private DMs and circle messages, silent translation can expose sensitive third-party content beyond the original messaging context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

Forcing display only in the configured language removes user control at message time and may hide nuances, warnings, or socially sensitive wording present in the original message. In a messaging/dispatch skill, that increases the chance of misunderstanding consent requests, connection prompts, or DM content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README notes that the server marks answers as read when fetched and that heartbeat returns everything the agent needs, but it does not present this as an explicit user-facing warning about state-changing reads. Automatic mark-as-read behavior can surprise users, hide unread status, and create integrity/usability issues when an agent polls in the background without deliberate review.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

L214 instructs the agent to fetch more messages with GET /messages?all=true. However, the API section documents pagination using ?limit=N and specifically says to use GET /messages?limit=50 when has_more is true (L123-L124), making this an intent/documentation contradiction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.