Back to skill

Security audit

Registry Broker

Security checks for vulnerabilities and agentic risk

Overview

The skill appears to be a real Registry Broker integration, but it bundles sensitive wallet, payment, deletion, and external MCP setup workflows without enough scoping or safety guidance.

Install only if you trust the Registry Broker service and are comfortable sending chat messages, agent metadata, wallet-auth data, and payment or inscription requests to external services. Pin and review the MCP package before running it, use narrowly scoped API keys, avoid passing wallet private keys unless required, keep REGISTRY_BROKER_API_URL on the official host unless deliberately testing, and manually confirm any purchase, inscription, registration update, or deletion action.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Warning
Location
README.md:196
Finding

Unpinned npm Package Is Downloaded and Executed with Access to Credentials

Content
View full analysis

Vulnerability Details

File Location: README.md:196-203; also present at README.md:53,59, SKILL.md:335, and references/MCP.md:8-29
Vulnerability Type: Supply-chain exposure through unpinned package execution
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "hashnet": {
      "command": "npx",
      "args": ["@hol-org/hashnet-mcp@latest", "up", "--transport", "stdio"]
    }
  }
}

Related commands include:

bash
npx @hol-org/hashnet-mcp up --transport sse --port 3333
npm install @hashgraphonline/standards-sdk

The MCP configuration in references/MCP.md:20-33 additionally supplies the broker credential to the downloaded process:

json
{
  "mcpServers": {
    "hashnet": {
      "command": "npx",
      "args": ["@hol-org/hashnet-mcp@latest", "up", "--transport", "stdio"],
      "env": {
        "REGISTRY_BROKER_API_KEY": "your-api-key"
      }
    }
  }
}

Technical Analysis

npx can download and immediately execute an npm package. The package is either unversioned or explicitly uses @latest, so the code executed by a future user can differ from the code available when this Skill was audited.

The MCP process is designed to receive REGISTRY_BROKER_API_KEY. The documentation also identifies HEDERA_PRIVATE_KEY as an optional MCP environment variable. Consequently, compromise of the package, its publisher account, or one of its transitive dependencies could expose broker credentials or wallet material and execute arbitrary code with the user's operating-system privileges.

The local pnpm-lock.yaml pins @hashgraphonline/standards-sdk, but it does not constrain the separate npx @hol-org/hashnet-mcp@latest command.

Attack Path

  1. An attacker compromises the npm package, publisher account, or a dependency used by @hol-org/hashnet-mcp.
  2. A malicious release becomes the version resolved by @latest or by ...[truncated 920 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace @latest and unversioned package names with an exact, reviewed version.
  • Install the dependency through a committed manifest and integrity-protected lockfile rather than downloading it at MCP startup.
  • Review and pin transitive dependencies as part of release maintenance.
  • Run the MCP server under a dedicated, restricted operating-system account or sandbox.
  • Pass only the environment variables required for the selected workflow.
  • Do not expose HEDERA_PRIVATE_KEY to discovery-only or chat-only MCP sessions.
  • Document package provenance, expected integrity, and a controlled upgrade process.

T09 · Insecure Skill Coding Practices

Warning
Location
examples/search-and-chat.js:11
Finding

Authenticated Requests Can Be Redirected to an Arbitrary Base URL

Content
View full analysis

Vulnerability Details

File Location: examples/search-and-chat.js:11,41-47; equivalent behavior occurs in examples/register-agent.js:10,28-49, scripts/chat.sh:9,27-30,45-48, and scripts/balance.sh:7,18-19
Vulnerability Type: Unvalidated credential-bearing endpoint override
Risk Level: Medium

Vulnerable Code

javascript
const BASE_URL = process.env.REGISTRY_BROKER_API_URL || 'https://hol.org/registry/api/v1';
const API_KEY = process.env.REGISTRY_BROKER_API_KEY;
javascript
const sessionResponse = await fetch(`${BASE_URL}/chat/session`, {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'x-api-key': API_KEY,
  },
  body: JSON.stringify({ uaid: agent.uaid }),
});

The shell helpers follow the same pattern:

bash
BASE_URL="${REGISTRY_BROKER_API_URL:-https://hol.org/registry/api/v1}"

SESSION_RESPONSE=$(curl -s -X POST "${BASE_URL}/chat/session" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $API_KEY" \
  -d "{\"uaid\": \"$UAID\"}")

Technical Analysis

The helpers allow REGISTRY_BROKER_API_URL to select any URL and then attach the user's API key to requests sent to that URL. They do not require HTTPS, verify that the destination is an approved Registry Broker host, reject URL credentials, or define restrictive redirect behavior.

A base-URL override can be legitimate for testing or self-hosted deployments. However, combining an unrestricted override with automatic transmission of a bearer-equivalent API key exceeds the minimum safe behavior for the default hosted service. An inherited environment variable, poisoned development configuration, or copied setup command can silently change the credential recipient.

Wallet-authentication requests can similarly be redirected, exposing the account identifier, challenge response, signature, and public key. Chat helpers additionally transmit conversation content, while regist ...[truncated 1167 chars]

Remediation
View remediation

Remediation Suggestions

  • Parse the configured URL with a standard URL parser before making any request.
  • Require https: whenever credentials or wallet signatures are transmitted.
  • Default to an explicit allowlist containing the official Registry Broker host.
  • Require a deliberate opt-in flag for custom hosts and display the validated destination before sending credentials.
  • Reject URLs containing embedded usernames or passwords.
  • Disable cross-origin redirects for credential-bearing requests, or remove sensitive headers whenever the redirect origin changes.
  • Separate unauthenticated discovery configuration from authenticated endpoint configuration.
  • Use narrowly scoped, short-lived API keys for automation and testing.

T09 · Insecure Skill Coding Practices

Note
Location
examples/ledger-auth.js:64
Finding

Temporary API Key Is Printed to Standard Output

Content
View full analysis

Vulnerability Details

File Location: examples/ledger-auth.js:64-68
Vulnerability Type: Plaintext credential disclosure through logging
Risk Level: Low

Vulnerable Code

javascript
if (result.apiKey) {
  console.log('Authentication successful!');
  console.log(`API Key: ${result.apiKey.key}`);
  console.log(`Expires: ${result.apiKey.expiresAt}`);
} else {
  console.log('Authentication failed:', result);
}

Technical Analysis

After successful wallet authentication, the example prints the complete temporary API key to standard output. Standard output is frequently retained by CI systems, terminal recorders, IDE consoles, container logging drivers, and shell wrappers. This converts a secret returned directly by the authentication service into persistent plaintext log data.

Although the credential is described as temporary, its complete value remains reusable until expiration or revocation. Printing it is not required to demonstrate successful authentication.

Attack Path

  1. A user replaces the placeholder signature and public key and runs the ledger-authentication example.
  2. The Registry Broker verifies the signature and returns a temporary API key.
  3. The script prints the complete key to standard output.
  4. A CI collector, terminal logger, shared console, support transcript, or another process captures that output.
  5. A person with access to the captured output extracts and reuses the key before it expires.

Impact Assessment

An attacker can perform any Registry Broker operations authorized by the temporary API key until expiration or revocation. The issue does not disclose the wallet private key, and the available code does not sign automatically. The principal exposure is the newly issued API credential and its associated broker permissions.

Remediation
View remediation

Remediation Suggestions

  • Do not print the complete API key.
  • Return the key directly to the caller or place it into an approved secret manager.
  • If interactive export is necessary, write it to a file created with restrictive permissions and clearly warn the user.
  • Display only a masked identifier or the final few characters for confirmation.
  • Ensure error handling does not print complete authentication responses that may contain credentials.
  • Keep temporary credentials short-lived, narrowly scoped, and revocable.

T09 · Insecure Skill Coding Practices

Note
Location
scripts/chat.sh:27
Finding

Chat Script Constructs JSON by Directly Interpolating Unescaped User Input

Content
View full analysis

Vulnerability Details

File Location: scripts/chat.sh:27-30,45-48
Vulnerability Type: JSON injection and malformed request construction
Risk Level: Low

Vulnerable Code

bash
SESSION_RESPONSE=$(curl -s -X POST "${BASE_URL}/chat/session" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $API_KEY" \
  -d "{\"uaid\": \"$UAID\"}")
bash
curl -s -X POST "${BASE_URL}/chat/message" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $API_KEY" \
  -d "{\"sessionId\": \"$SESSION_ID\", \"message\": \"$MESSAGE\"}" | jq .

Technical Analysis

UAID, MESSAGE, and the server-provided SESSION_ID are inserted directly into JSON string literals. Shell quoting prevents these values from becoming local shell commands, but it does not perform JSON escaping. Quotes, backslashes, newlines, and control characters can terminate or alter the intended JSON value.

A crafted argument can therefore produce malformed JSON or inject additional properties accepted by the remote API. The exact effect depends on server-side schema validation and duplicate-property handling. No local command-execution path was identified from this interpolation.

Attack Path

  1. An attacker provides a crafted UAID or message to a user, automation job, or wrapper that invokes scripts/chat.sh.
  2. The value contains JSON syntax such as a quote followed by an additional property.
  3. The script embeds the value without JSON encoding.
  4. The Registry Broker receives malformed JSON or a body whose structure differs from the script's intended structure.
  5. If the server accepts the injected structure, request fields may be changed; otherwise, the operation fails.

Impact Assessment

Likely impact includes denial of the requested operation, message corruption, or unintended request-field manipulation. The affected request is authenticated with the user's API key, so accepted injected fields execute w ...[truncated 150 chars]

Remediation
View remediation

Remediation Suggestions

  • Construct request bodies with a JSON-aware tool instead of string interpolation.
  • For example:
bash
SESSION_PAYLOAD=$(jq -n --arg uaid "$UAID" '{uaid: $uaid}')
MESSAGE_PAYLOAD=$(jq -n \
  --arg sessionId "$SESSION_ID" \
  --arg message "$MESSAGE" \
  '{sessionId: $sessionId, message: $message}')

SESSION_RESPONSE=$(curl -sS --fail-with-body \
  -X POST "${BASE_URL}/chat/session" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $API_KEY" \
  --data-binary "$SESSION_PAYLOAD")

curl -sS --fail-with-body \
  -X POST "${BASE_URL}/chat/message" \
  -H "Content-Type: application/json" \
  -H "x-api-key: $API_KEY" \
  --data-binary "$MESSAGE_PAYLOAD"
  • Validate UAID and session-ID formats before use.
  • Add request timeouts and curl --fail-with-body so HTTP failures are handled explicitly.
  • Test quotes, backslashes, Unicode, newlines, and control characters.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
Findings (29)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description emphasizes agent discovery, chatting, and registration through the Hashgraph Online Registry Broker API. The actual code only retrieves credit balance information from a credits endpoint. That is a materially different primary purpose and accesses a different resource domain (billing/usage rather than agent operations). While both relate to the same API ecosystem, balance checking is an undeclared capability and the advertised core capabilities are not present in this code chunk.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description presents a broader skill that can search, chat with agents, and register new agents across registries. The supplied code chunk only performs a search request against a registry API endpoint (/search) and formats the returned results. It does not initiate conversations, send messages, register agents, or implement other broker operations. While the search portion aligns with part of the description, the actual code behavior is substantially narrower than the declared purpose, so this is a description/behavior mismatch for this code chunk.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The documented DELETE session endpoint is a state-changing action that could terminate active conversations if invoked with attacker-controlled or mistaken parameters. In an agentic environment, parameter abuse becomes more dangerous because the system may act on ambiguous references without a human realizing the consequence.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

curl "https://hol.org/registry/api/v1/chat/session/sess_.../encryption"
-H "x-api-key: $REGISTRY_BROKER_API_KEY"

DELETE /chat/session/{sessionId} - End session

curl -X DELETE "https://hol.org/registry/api/v1/chat/session/sess_..."
-H "x-api-key: $REGISTRY_BROKER_API_KEY"

text

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
93% confidence
Finding

The unregister endpoint is destructive and may remove an agent record if an attacker or confused workflow supplies a target UAID. Because this skill is framed as a broad broker client, exposing deletion alongside discovery increases the chance of unintended or unauthorized removal actions.

Content

Scanner excerpt · SKILL.md (reported line 218)May include surrounding context.

-H "x-api-key: $REGISTRY_BROKER_API_KEY"
-d '{"profile": {"name": "Updated Name"}}'

DELETE /register/{uaid} - Unregister agent

curl -X DELETE "https://hol.org/registry/api/v1/register/uaid:..."
-H "x-api-key: $REGISTRY_BROKER_API_KEY"

text

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

Content inscription is unrelated to ordinary agent discovery or chat and may incur permanent publication and billing consequences. Bundling this feature into the same skill increases the risk of accidental irreversible actions or misuse of user-provided content and credits.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
80% confidence
Finding

The connection-close DELETE endpoint can disrupt active routing sessions if misused with attacker-selected UAIDs. While less severe than account deletion, it is still a state-changing action that can be abused for denial of service or workflow interruption.

Content

Scanner excerpt · SKILL.md (reported line 323)May include surrounding context.

-H "x-api-key: $REGISTRY_BROKER_API_KEY"
-d '{"message": "Hello", "metadata": {}}'

DELETE /uaids/connections/{uaid} - Close active connection

curl -X DELETE "https://hol.org/registry/api/v1/uaids/connections/uaid:..."
-H "x-api-key: $REGISTRY_BROKER_API_KEY"

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · pnpm-lock.yaml (reported line 704)May include surrounding context.

yaml
resolution: {integrity: sha512-6xx/NmEc84HX7QmsjSC3hHredQYjHv4Dkf4G27adAPf+qN+vnPxmQ7gaTnk243a0++DOFTbZ2gKX/15G2B6SRg==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

  '@libp2p/interface-keychain@2.0.5':
    resolution: {integrity: sha512-mb7QNgn9fIvC7CaJCi06GJ+a6DN6RVT9TmEi0NmedZGATeCArPeWWG7r7IfxNVXb9cVOOE1RzV1swK0ZxEJF9Q==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · pnpm-lock.yaml (reported line 5402)May include surrounding context.

yaml
resolution: {integrity: sha512-6xx/NmEc84HX7QmsjSC3hHredQYjHv4Dkf4G27adAPf+qN+vnPxmQ7gaTnk243a0++DOFTbZ2gKX/15G2B6SRg==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

  '@libp2p/interface-keychain@2.0.5':
    resolution: {integrity: sha512-mb7QNgn9fIvC7CaJCi06GJ+a6DN6RVT9TmEi0NmedZGATeCArPeWWG7r7IfxNVXb9cVOOE1RzV1swK0ZxEJF9Q==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · pnpm-lock.yaml (reported line 9148)May include surrounding context.

yaml
resolution: {integrity: sha512-6xx/NmEc84HX7QmsjSC3hHredQYjHv4Dkf4G27adAPf+qN+vnPxmQ7gaTnk243a0++DOFTbZ2gKX/15G2B6SRg==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

  '@libp2p/interface-keychain@2.0.5':
    resolution: {integrity: sha512-mb7QNgn9fIvC7CaJCi06GJ+a6DN6RVT9TmEi0NmedZGATeCArPeWWG7r7IfxNVXb9cVOOE1RzV1swK0ZxEJF9Q==}
    engines: {node: '>=16.0.0', npm: '>=7.0.0'}

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

DELETE /register/{uaid} is a destructive operation that likely removes an agent from the registry, but the markdown does not warn about impact, reversibility, or service disruption. For markdown files, omission of warnings about actions affecting data or system integrity is in scope.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The README instructs users to run an MCP server via npx @hol-org/hashnet-mcp without pinning an exact version. This creates a supply-chain risk because future or compromised package versions could be fetched and executed automatically, and the skill context targets AI assistants and developer tools where such commands may be run with high trust.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · README.md (reported line 85)May include surrounding context.

md
export REGISTRY_BROKER_API_KEY="your-key"

# Search for agents
curl "https://hol.org/registry/api/v1/search?q=trading+bot&limit=5"

# Create chat session
curl -X POST "https://hol.org/registry/api/v1/chat/session" \

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The README promotes chat, registration, and discovery workflows but does not clearly warn that user prompts, agent identifiers, metadata, and possibly registration details are sent to an external service. In an AI skill context, users may assume local-only assistance, so omission of data-flow disclosure can lead to unintended disclosure of sensitive prompts or proprietary agent information.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill documents use of environment variables, network access, and shell commands but does not declare an explicit tool scope such as allowed-tools or permissions. That weakens least-privilege controls and makes it easier for a host agent to grant broader capabilities than are actually needed, especially given the large API surface including state-changing endpoints.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The stated purpose emphasizes discovery, chat, and registration, but the skill also exposes payments, wallet authentication, encryption key registration, and content inscription. This scope expansion increases attack surface and the chance that a user or agent invokes sensitive financial or identity-related operations without understanding they are outside the core broker use case.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

bash
# GET /search with query params
curl "https://hol.org/registry/api/v1/search?q=trading+bot&limit=5"

# With filters: registries, adapters, capabilities, protocols, minTrust, verified, online, sortBy, type
curl "https://hol.org/registry/api/v1/search?q=defi&registries=agentverse,nanda&verified=true&limit=10"

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The chat and routing features send user messages, metadata, and conversation history to an external service, but the skill provides no prominent privacy or data-handling warning. In a conversational agent context, users may unintentionally disclose sensitive prompts, secrets, or personal data to third-party systems.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The registration, update, unregistration, and payment endpoints can create charges or make consequential changes to agent records, yet the skill lacks clear warnings about billing impact, reversibility, and authorization expectations. That makes accidental or socially engineered destructive/account-impacting actions more likely.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Wallet-based ledger authentication is a sensitive capability that can trigger signing flows and issuance of temporary API keys. Including it in a general discovery/chat skill makes phishing-style abuse and unintended credential issuance more plausible, especially when an agent may guide users through wallet interactions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The skill recommends running an MCP server via unpinned npx, which fetches the latest package version at execution time. This creates a supply-chain risk where a compromised upstream package or unexpected breaking change could execute arbitrary code in the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This example logs a returned API key directly to stdout, which can expose credentials through terminal history, CI logs, shell recording, shared consoles, or log aggregation systems. Because the file is an authentication example, users are likely to copy it into real workflows, increasing the chance that live temporary credentials are unintentionally disclosed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file documents destructive endpoints such as closing a connection without any warning about the irreversible or state-changing effect. Under the markdown criteria, descriptions should warn about behaviors that could affect user data or system integrity, and the current endpoint list presents the action neutrally.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The markdown lists an endpoint to end a chat session but does not disclose whether this action is destructive, irreversible, or impacts stored history and active communication. A user-facing warning is expected for behavior that could affect user data or workflow continuity.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The installation command uses npx @hol-org/hashnet-mcp without pinning a specific version, which causes users to fetch and execute whatever package version is current at install time. In an MCP/server context this is especially risky because the package is executed locally and may receive API keys or other secrets, so a compromised or malicious update could immediately lead to code execution and credential theft.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
98% confidence
Finding

The Claude Desktop example again relies on npx @hol-org/hashnet-mcp up --transport stdio without an exact version, so every fresh setup may execute newly published code from the package registry. Because this configuration is intended for persistent desktop integration and includes access to an API key in the same setup flow, exploitation could expose credentials and enable arbitrary code execution on the user's machine.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
examples/ledger-auth.js:10

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
examples/register-agent.js:10

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
examples/search-and-chat.js:11