Back to skill

Security audit

Aap Passport

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be an AI-agent verification toolkit, but its security claims are stronger than what the shipped protocol actually proves.

Review this before installing if you plan to rely on it for access control. It is reasonable as an experimental challenge/signature demo, but do not treat a successful AI_AGENT result as proof of a trusted AI agent unless you add enrollment, a trusted key registry or certificate authority, rate limits, bounded session storage, strict CORS, and clear disclosure of what verifier and LLM endpoints receive.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
packages/server/websocket.js:203
Finding

Self-Issued Keys and Deterministic Challenges Allow Attestation Bypass

Content
View full analysis
ws.close(), 300); return; } // Create proof data for verification const proofData = JSON.stringify({ nonce, answers, publicId, timestamp }); if (!verifySignature(proofData, signature, publicKey)) { const result = { type: 'result', verified: false, message: 'Invalid signature', code: 'INVALID_SIGNATURE', publicId }; if (onFailed) onFailed(result); send(ws, result); setTimeout(() => ws.close(), 300); return; } } // Too slow? if (elapsed > totalTimeMs) { / ...[truncated 3596 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
packages/server/websocket.js:295
Finding

Verified Session Tokens Accumulate Indefinitely in Process Memory

Content
View full analysis
ws.close(), 300); ``` The returned management API checks expiration without removing expired entries, and exposes raw sessions without an expiration check: ```javascript return { wss, verifiedTokens, close: () => wss.close(), isVerified: (token) => { const session = verifiedTokens.get(token); return session && Date.now() < session.expiresAt; }, getSession: (token) => verifiedTokens.get(token) }; ``` ### Technical Analysis Every successful verification inserts a new entry into `verifiedTokens`. Although each entry contains an `expiresAt` value, no timer, periodic cleanup routine, maximum size, eviction policy, or deletion-on-access behavior removes expired entries. Therefore, expiration affects the Boolean result of `isVerified()` but does not reclaim memory. The public `verifiedTokens` map continues to retain the token, public key, nonce, and session metadata for the lifetime of the server process. Additionally, `getSession()` returns expired sessions without checking `expiresAt`. While callers should use `isVerified()` for authorization, the API does not enforce that distinction and can facilitate accidental acceptance of expired session state. The attestation bypass described separately makes successful token generation available to arbitrary callers using locally generated keys and determinis ...[truncated 1723 chars]
Remediation
View remediation
= session.expiresAt) { verifiedTokens.delete(token); return null; } return session; } ``` 2. Use the same expiry-enforcing helper for both `isVerified()` and `getSession()`. 3. Add a periodic cleanup task that scans and removes expired entries, and clear that task when the server closes. 4. Enforce an upper bound on active sessions and apply a documented eviction policy when the limit is reached. 5. For production or multi-instance deployments, store sessions in a bounded external store with native TTL support, such as Redis. 6. Apply connection and successful-verification rate limits by IP address, trusted identity, and deployment-specific quota. 7. Avoid returning the internal mutable `verifiedTokens` map as part of the public API. 8. Add metrics and alerts for active token count, token issuance rate, heap usage, and rejected connections. 9. Add tests confirming that expired tokens are deleted, `getSession()` cannot return expired sessions, and sustained issuance cannot grow storage beyond the configured maximum. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Output HandlingUnvalidated Output Injection, Cross-Context Output, Unbounded Output
  • System Prompt LeakageDirect Leakage, Indirect Extraction, Tool-Based Exfiltration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (52)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill runs generic crypto or security tests and uses Node.js crypto operations without declared permissions while claiming to provide attestation enforcement, users may overtrust it as a security control. In this context, the danger comes from false assurance and undeclared capability use rather than the presence of cryptography itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

If the skill runs generic crypto or security tests and uses Node.js crypto operations without declared permissions while claiming to provide attestation enforcement, users may overtrust it as a security control. In this context, the danger comes from false assurance and undeclared capability use rather than the presence of cryptography itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill runs generic crypto or security tests and uses Node.js crypto operations without declared permissions while claiming to provide attestation enforcement, users may overtrust it as a security control. In this context, the danger comes from false assurance and undeclared capability use rather than the presence of cryptography itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

If the skill runs generic crypto or security tests and uses Node.js crypto operations without declared permissions while claiming to provide attestation enforcement, users may overtrust it as a security control. In this context, the danger comes from false assurance and undeclared capability use rather than the presence of cryptography itself.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

If the skill runs generic crypto or security tests and uses Node.js crypto operations without declared permissions while claiming to provide attestation enforcement, users may overtrust it as a security control. In this context, the danger comes from false assurance and undeclared capability use rather than the presence of cryptography itself.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: path-to-regexp==0.1.12 — 1 advisory(ies): CVE-2024-45296 (path-to-regexp vulnerable to Regular Expression Denial of Service via multiple r)

High
Category
Supply Chain
Confidence
96% confidence
Finding

The lockfile resolves path-to-regexp 0.1.12, which is associated with a Regular Expression Denial of Service issue. In an Express-based HTTP verifier, route matching is part of request processing, so malformed paths could potentially trigger excessive CPU use and make the service unavailable.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The verifier accepts a client-supplied publicKey and publicId, then checks only that the signature matches data signed by that same supplied key. This proves possession of a private key generated by the requester, but it does not bind the requester to any pre-established trusted agent identity, so any attacker can create a fresh keypair, solve the challenge, and be marked verified as an AI agent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The signature verification logic is cryptographically correct in isolation, but because the public key comes from the same untrusted request, it authenticates nothing beyond self-assertion. An attacker can generate any keypair, sign the proofData, submit the matching public key, and pass verification without being a known or authorized agent.

Content

No source excerpt is available for this finding.

Direct Prompt Extraction

High
Category
System Prompt Leakage
Confidence
85% confidence
Finding

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

Content

Scanner excerpt · lib/prover.js (reported line 146)May include surrounding context.

js
...
]`;

  return prompt;
}

/**

Unvalidated Output Injection

High
Category
Output Handling
Confidence
100% confidence
Finding

Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.

Content

Scanner excerpt · lib/prover.js (reported line 172)May include surrounding context.

js
const objects = [];
    const regex = /\{[^{}]*"salt"[^{}]*\}/g;
    let m;
    while ((m = regex.exec(response)) !== null) {
      objects.push(m[0]);
    }

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The function returns expected alongside the generated challenge despite claiming it is 'for debugging only', which can expose the correct answers to any caller of the API. If this object crosses a trust boundary or is logged, an attacker can bypass the challenge system entirely by reading and replaying the expected solution.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

generateBatch returns both validators and expected while the comment says they should stay on the server, creating a direct opportunity for challenge bypass and possible leakage of internal validation logic. In this attestation context, exposing either answers or validator behavior undermines the entire security control.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The protocol explicitly shows challenge content being forwarded to an external llmCallback for solving, but provides no warning, consent model, or data-handling constraints. If challenges contain sensitive, proprietary, or user-derived content, this design can cause unintended disclosure to third-party LLM providers and create compliance/privacy issues.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
84% confidence
Finding

The skill declares no explicit tool scope or permissions even though the described usage clearly relies on network access and the referenced implementation reportedly uses environment and filesystem-adjacent capabilities. Missing scope declarations weaken reviewability and can cause hosts to grant broader capabilities than users expect, increasing the chance of unintended data access or outbound communication.

Content

No source excerpt is available for this finding.

Unsafe Defaults

Medium
Category
Tool Misuse
Confidence
96% confidence
Finding

Setting CORS_ORIGIN=* allows any website origin to make cross-origin requests to this service. If the API exposes sensitive endpoints, uses browser-based authentication, or is embedded in other workflows, this broad trust boundary can enable unauthorized web origins to interact with the service and increase the risk of data exposure or abuse.

Content

Scanner excerpt · docker-compose.yml (reported line 11)May include surrounding context.

yaml
environment:
      - NODE_ENV=production
      - PORT=3000
      - CORS_ORIGIN=*
    restart: unless-stopped
    healthcheck:
      test: ["CMD", "wget", "--spider", "-q", "http://localhost:3000/health"]

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The startup hook silently creates a new cryptographic identity and persists local state without any user-facing notice or consent flow. In an agent skill, hidden key generation can surprise operators, create unmanaged secrets on disk, and make it harder to reason about identity, rotation, and data retention.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This tool accepts an arbitrary server URL and performs the full verification flow against it, which likely sends challenge/response material and metadata to an external endpoint without prominent disclosure. In an agent environment this can enable unintended outbound requests, data exfiltration to attacker-controlled servers, or SSRF-style access to internal services if URL destinations are not restricted.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This code persists an object containing the private key to a filesystem path in the user's home directory. Although comments and logs describe creation and permission-setting, there is no explicit user-facing warning that sensitive cryptographic key material will be stored locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The deleteIdentity function irreversibly removes the identity file with unlinkSync, which can break access to the existing cryptographic identity. While the doc comment says 'use with caution,' there is no runtime confirmation prompt or stronger user disclosure before deletion occurs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The code forwards full challenge contents to an external llmCallback with no consent, minimization, or trust-boundary enforcement. If challenges contain secrets, internal prompts, or sensitive attestation material, this can leak data to third-party model providers or logs, which is especially risky in a verifier/attestation context.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The README encourages verify() and proof submission to a remote serverUrl but does not clearly warn that challenge/response data and identifying material will be transmitted off-host. In a security-sensitive attestation client, this omission can mislead integrators into sending prompts, model outputs, and identity-linked metadata to third-party infrastructure without informed consent or privacy review.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code opens a WebSocket connection and sends the client's public key plus signed challenge-response data to a server, but there is no confirmation prompt, logging, or user-facing notice around that network transmission. Because the module handles identity material and transmits proof-related data off-box, users of the skill are not warned about the privacy and network effects of verification.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README explicitly encourages use of an identity manager with a storagePath and notes that initialization loads or generates identity material, but it provides no warning that this likely includes private key material persisted to disk. In a cryptographic identity library, omission of storage-safety guidance can lead users to place sensitive keys in insecure locations, commit them to source control, or deploy them with overly broad filesystem permissions, increasing the chance of key compromise and impersonation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The code generates a new identity and persists both the public and private key material to a file in the user's home directory. Although the comment notes secure permissions, there is no user-facing disclosure, prompt, or warning that sensitive credentials are being stored locally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The delete method performs a destructive file deletion of the stored identity, including private key material, with no prompt, log, or warning to the user. Even though the comment says 'for testing', the operation is irreversible from the user's perspective and lacks disclosure in the code.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/llm-batch-test-internal.mjs:140

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/llm-batch-test.mjs:10