T09 · Insecure Skill Coding Practices
- Location
scripts/lnbits_cli.py:17- Finding
LNbits administrator API key may be exposed through insecure endpoints or cross-origin redirects
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent LNbits wallet helper, but it can send real Lightning payments with only prompt-level confirmation and weak endpoint scoping for an admin key.
Install only if you are comfortable giving the assistant an LNbits admin key and you will supervise every payment. Use a dedicated wallet with limited funds, configure only a trusted HTTPS LNbits URL, avoid pasting secrets into chat, and treat payment approval prompts as mandatory because the CLI itself does not enforce confirmation.
scripts/lnbits_cli.py:17LNbits administrator API key may be exposed through insecure endpoints or cross-origin redirects
SKILL.md:5Unpinned QR-code dependency creates avoidable supply-chain exposure
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
req = urllib.request.Request(url, method=method, headers=headers, data=body)
try:
with urllib.request.urlopen(req, timeout=20) as resp:
return json.loads(resp.read().decode("utf-8"))
except urllib.error.HTTPError as e:
error_body = e.read().decode("utf-8", errors="replace")
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
req = urllib.request.Request(url, method=method, headers=headers, data=body)
try:
with urllib.request.urlopen(req, timeout=20) as resp:
return json.loads(resp.read().decode("utf-8"))
except urllib.error.HTTPError as e:
error_body = e.read().decode("utf-8", errors="replace")
The declared description says the skill manages balance, paying, and invoice creation, but the content also supports wallet creation, invoice decoding, and local QR generation/storage. This mismatch is risky because reviewers and policy engines may approve the skill for narrower wallet operations while overlooking account provisioning and extra data-handling behaviors that affect secrets, local files, and payment metadata.
The pay command sends funds immediately when provided a BOLT11 invoice, with no built-in confirmation step, amount preview, or recipient verification. In an agent setting this is especially dangerous because prompt injection, tool misuse, or operator error could cause irreversible Lightning payments.
The skill invokes shell commands, reads environment-provided secrets, accesses the network, and writes local QR image files, yet it does not declare any explicit tool scope or allowed-tools policy. In a wallet-management skill, this omission is dangerous because it leaves a high-risk payment and secret-handling workflow under-bounded, increasing the chance an agent can use broader capabilities than intended or execute sensitive actions without clear sandboxing.
The skill description says it manages an LNbits wallet via balance, pay, and invoice operations, but the code also exposes account/wallet creation. This hidden capability expands the trust boundary and can trigger unexpected remote-side actions, making it easier for an agent or user to invoke functionality they were not informed the skill possessed.
The create command performs a remote account/wallet creation action without any visible disclosure or confirmation in the tool flow. While less severe than direct payment, it still causes external side effects and transmits user-supplied data to a third-party LNbits instance, which may be unexpected given the stated skill scope.
The code supports standalone QR generation and writes PNG files to disk, but this behavior is not disclosed in the skill description. Undisclosed filesystem writes are risky in agent environments because they create side effects and artifacts that users may not expect or approve.
No suspicious patterns detected.