Back to skill

Security audit

IssueBadge

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward IssueBadge integration guide with disclosed credential handling and user-confirmation rules for issuing credentials.

Before installing, users should understand that this skill can help an agent issue or revoke real public credentials through IssueBadge when connected with read/write access. Prefer OAuth where available, do not paste secrets into chat, and confirm recipient, template, and revocation details before allowing changes.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 25)May include surrounding context.

md
| **Viktor (viktor.com)** | Viktor workspaces | Integrations, Add Custom, MCP Server, paste the MCP URL and sign in; or Add Custom, API with base URL `https://app.issuebadge.com/api/v1` and a bearer token. See the `issuebadge-viktor` skill. |
| **Agent CLI** | Shell-based agents | `pip install cli-anything-issuebadge`, set `ISSUEBADGE_API_KEY`, run `cli-anything-issuebadge --json <group> <command>` |

OAuth discovery, if you implement a client yourself: an unauthenticated call to the MCP URL returns 401 with a `WWW-Authenticate` header pointing at `/.well-known/oauth-protected-resource`; that names `https://app.issuebadge.com` as the authorization server; read `/.well-known/oauth-authorization-server` there; register with `POST /oauth/register` (dynamic client registration); run the authorization-code flow with PKCE S256; exchange at `/oauth/token`. Access tokens last one year.

Never ask the user to paste an API key into a chat when an OAuth-capable client is available. Never print, log or echo a key or token back to the user.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 27)May include surrounding context.

md
OAuth discovery, if you implement a client yourself: an unauthenticated call to the MCP URL returns 401 with a `WWW-Authenticate` header pointing at `/.well-known/oauth-protected-resource`; that names `https://app.issuebadge.com` as the authorization server; read `/.well-known/oauth-authorization-server` there; register with `POST /oauth/register` (dynamic client registration); run the authorization-code flow with PKCE S256; exchange at `/oauth/token`. Access tokens last one year.

Never ask the user to paste an API key into a chat when an OAuth-capable client is available. Never print, log or echo a key or token back to the user.

## 2. Check the connection

Static analysis

No suspicious patterns detected.