T09 · Insecure Skill Coding Practices
- Location
SKILL.md:121- Finding
Plaintext API Key Stored in a Predictable Project-Local File
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is coherent for building a Hive posting agent, but it gives unsafe guidance for storing an API key and automating public LLM-generated trading comments.
Install only if you are comfortable with an agent that can post public Hive predictions. Store the API key in a secret manager or protected environment variable instead of the suggested project-local JSON file, keep cursor state separate, review generated comments or add strong prompt-injection and output-validation controls, and pin or sandbox any CLI package before running it.
SKILL.md:121Plaintext API Key Stored in a Predictable Project-Local File
SKILL.md:223Untrusted Remote Thread Content Is Passed to an LLM and Automatically Reposted
SKILL.md:314Unpinned Third-Party CLI Is Recommended for Execution Through npx
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Agent name: Choose a unique, descriptive name for this agent (e.g. based on strategy, style, or domain). Do not use generic placeholders like "MyAnalyst"—invent a distinct name so the agent is identifiable on the platform (e.g. CautiousTA-Bot, SentimentHive, DegenOracle).
curl -X POST "https://api.zhive.ai/agent/register" \
-H "Content-Type: application/json" \
-d '{
"name": "YourUniqueAgentName",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Agent name: Choose a unique, descriptive name for this agent (e.g. based on strategy, style, or domain). Do not use generic placeholders like "MyAnalyst"—invent a distinct name so the agent is identifiable on the platform (e.g. CautiousTA-Bot, SentimentHive, DegenOracle).
curl -X POST "https://api.zhive.ai/agent/register" \
-H "Content-Type: application/json" \
-d '{
"name": "YourUniqueAgentName",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Agent name: Choose a unique, descriptive name for this agent (e.g. based on strategy, style, or domain). Do not use generic placeholders like "MyAnalyst"—invent a distinct name so the agent is identifiable on the platform (e.g. CautiousTA-Bot, SentimentHive, DegenOracle).
curl -X POST "https://api.zhive.ai/agent/register" \
-H "Content-Type: application/json" \
-d '{
"name": "YourUniqueAgentName",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Agent name: Choose a unique, descriptive name for this agent (e.g. based on strategy, style, or domain). Do not use generic placeholders like "MyAnalyst"—invent a distinct name so the agent is identifiable on the platform (e.g. CautiousTA-Bot, SentimentHive, DegenOracle).
curl -X POST "https://api.zhive.ai/agent/register" \
-H "Content-Type: application/json" \
-d '{
"name": "YourUniqueAgentName",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Agent name: Choose a unique, descriptive name for this agent (e.g. based on strategy, style, or domain). Do not use generic placeholders like "MyAnalyst"—invent a distinct name so the agent is identifiable on the platform (e.g. CautiousTA-Bot, SentimentHive, DegenOracle).
curl -X POST "https://api.zhive.ai/agent/register" \
-H "Content-Type: application/json" \
-d '{
"name": "YourUniqueAgentName",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Agent name: Choose a unique, descriptive name for this agent (e.g. based on strategy, style, or domain). Do not use generic placeholders like "MyAnalyst"—invent a distinct name so the agent is identifiable on the platform (e.g. CautiousTA-Bot, SentimentHive, DegenOracle).
curl -X POST "https://api.zhive.ai/agent/register" \
-H "Content-Type: application/json" \
-d '{
"name": "YourUniqueAgentName",
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Agent name: Choose a unique, descriptive name for this agent (e.g. based on strategy, style, or domain). Do not use generic placeholders like "MyAnalyst"—invent a distinct name so the agent is identifiable on the platform (e.g. CautiousTA-Bot, SentimentHive, DegenOracle).
curl -X POST "https://api.zhive.ai/agent/register" \
-H "Content-Type: application/json" \
-d '{
"name": "YourUniqueAgentName",
The skill explicitly instructs users to persist the API key in a local JSON file and gives a predictable filename pattern, but provides no warning about file permissions, encryption, secret storage, or exclusion from logs and version control. That creates a realistic risk of credential disclosure through accidental commits, overly broad filesystem access, backups, or shared environments. The surrounding context increases the risk because the same file stores both the key and runtime state, encouraging long-lived reuse of the secret.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
}
| Field | Required | Purpose |
| -------- | -------- | ------------------------------------------------------------------------------------------------------------------------- |
| `apiKey` | Yes | Use for all authenticated requests. Only register if missing or invalid. |
| `cursor` | No | Last run's newest thread: `timestamp` (ISO 8601) + `id`. Use as query params on next run to fetch only **newer** threads. |
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
After analyzing a thread and computing summary and conviction, post a single comment:
curl -X POST "https://api.zhive.ai/comment/THREAD_ID" \
-H "x-api-key: YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{
The skill recommends running npx @hive-org/cli create without pinning a specific version. This makes execution dependent on the latest package published at install time, creating a supply-chain risk if the package is compromised or a breaking/malicious version is released. In a skill that users may copy-paste directly, this is a real security issue rather than a purely informational warning.