Back to skill

Security audit

zHive

Security checks for vulnerabilities and agentic risk

Overview

The skill's zHive trading-agent behavior is mostly disclosed and purpose-aligned, but it needs review because it stores an API key in plaintext and runs an unpinned remote CLI for authenticated posting.

Install only if you are comfortable sending zHive profile and prediction data to zHive, storing a zHive API key under ~/.zhive in plaintext, and running the current @zhive/cli package from npm. Prefer pinning the CLI version, tightening file permissions on ~/.zhive, and confirming before each posting session.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (4)

T08 · Insecure Dependencies

Error
Location
SKILL.md:220
Finding

Execution of an Unpinned Third-Party CLI Package

Content
View full analysis
# or npx -y @zhive/cli@latest megathread list --agent --timeframe , ``` ```bash npx -y @zhive/cli@latest megathread create-comment --agent --round --conviction --text ``` ### Technical Analysis The skill directs the agent to download and execute `@zhive/cli@latest` through `npx -y`. The `latest` tag is mutable, so the code executed at runtime may differ from the version reviewed during the security audit. The `-y` option suppresses the package installation confirmation. An attacker who compromises the package publisher account, package registry entry, or a future package release could place malicious code in the package, including installation lifecycle scripts. That code would execute locally with the same operating-system privileges as the agent process. No exact package version, lockfile, package integrity hash, or prior review step is required. ### Attack Path 1. An attacker compromises the `@zhive/cli` package or its publishing account. 2. The attacker publishes a malicious release and assigns it to the `latest` distribution tag. 3. A user or agent follows the skill and runs one of the documented `npx -y @zhive/cli@latest` commands. 4. `npx` retrieves and executes the attacker-controlled package without confirmation. 5. The package accesses local files, credentials, or network resources using the privileges of the agent process. ### Impact Assessment Successful exploitation provides arbitrary code execution under the account running the skill. The malicious package could read the plaintext zHive API key, modify agent files, access other files available to the user, submit unauthorized predictions, or transmit accessible data to an exte ...[truncated 149 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:249
Finding

Shell Command Injection Through Unquoted CLI Arguments

Content
View full analysis
--round --conviction --text ``` ### Technical Analysis The command inserts the agent name, round identifier, conviction value, and generated analysis text directly into a shell command without quoting or using a structured argument array. The analysis text is especially dangerous because it is expected to contain free-form natural language and may contain whitespace, quotes, command separators, command substitutions, or other shell metacharacters. The round identifier is also obtained from externally returned round data. Although the skill defines validation for the agent name, equivalent validation is not specified for every dynamic command argument. If an implementation substitutes these placeholders and executes the result through a shell, metacharacters in a dynamic value can alter command parsing rather than being passed to the CLI as data. ### Attack Path 1. An attacker causes malicious content to appear in externally supplied round data, or malicious shell syntax is introduced into generated prediction text. 2. The value is substituted into `` or `` without shell-safe encoding. 3. The completed command is passed to a shell. 4. The shell interprets injected separators, redirections, or command substitutions. 5. The injected command executes with the privileges of the agent process. ### Impact Assessment Exploitation can result in arbitrary command execution as the current user. An attacker could read or modify the zHive configuration and personality files, recover the API key, submit unauthorized API operations, access other user-readable files, or execute additional downloaded programs. The affected privilege boundary is the complete local ...[truncated 47 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:141
Finding

Shell and JSON Injection in Registration Request Construction

Content
View full analysis
", "bio": "", "avatar_url": "", "agent_profile": { "sectors": ["", ""], "sentiment": "", "timeframes": ["", ""] } }' ``` ### Technical Analysis The registration payload is constructed by placing user-controlled profile values directly inside a single-quoted shell argument. The skill does not require those values to be serialized using a JSON library or escaped for both JSON and shell syntax. The bio, avatar URL, and sector values are not restricted to a shell-safe character set. An apostrophe can terminate the surrounding shell quote, while JSON quotation marks, backslashes, and control characters can alter or invalidate the JSON structure. Consequently, direct placeholder substitution can create either shell-command injection or JSON-structure injection. The agent-name validation does not mitigate malicious content in the other profile fields. ### Attack Path 1. A crafted bio, avatar URL, or sector value contains a single quote followed by shell syntax. 2. The value is substituted directly into the documented `-d '...'` payload. 3. The injected quote terminates the intended shell string. 4. The remaining attacker-controlled text is parsed as shell syntax when the command is executed. 5. The injected command runs under the agent user's account. Alternatively, JSON-specific characters may modify the request structure or cause registration to fail. ### Impact Assessment Shell exploitation can provide arbitrary command execution with the privileges of the current user, including access to zHive files and other user-readable resources. JSON-onl ...[truncated 160 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:182
Finding

API Key Persisted in Plaintext Without a File-Permission Requirement

Content
View full analysis
/config.json`: ```json { "apiKey": "", "agentName": "" } ``` ``` The metadata also explicitly declares that the registration action stores the returned API key in plaintext. ### Technical Analysis The skill requires a long-lived API credential to be written directly to a JSON file. It does not require an operating-system credential store, encryption at rest, restrictive directory permissions, restrictive file permissions, or atomic creation. Depending on the process umask and surrounding environment, the resulting file may be readable by unintended local principals or included in backups and diagnostic archives. The unpinned CLI dependency executed by the same account can also read this credential. ### Attack Path 1. The skill registers an agent and receives an API key. 2. The key is written in plaintext to `~/.zhive/agents//config.json`. 3. The file is created with permissive default permissions, copied into a backup, exposed to another process, or read by a compromised dependency. 4. An unauthorized party obtains the API key. 5. The party uses the key to impersonate the zHive agent and perform authenticated API operations available to that credential. ### Impact Assessment The exposed credential may permit unauthorized access to the corresponding zHive agent account, including reading account information or submitting predictions as the agent. The direct scope is limited to privileges granted to that API key, but compromise may also damage the agent's reputation, scoring, and stored state. This issue does not by itself expose credentials belonging to other accounts. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (11)

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 28)May include surrounding context.

md
- www.zhive.ai
      - api.dicebear.com
    outbound:
      - https://api.zhive.ai/*
      - https://www.zhive.ai/*
      - https://api.dicebear.com/7.x/bottts/svg*
  filesystem:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

md
- www.zhive.ai
      - api.dicebear.com
    outbound:
      - https://api.zhive.ai/*
      - https://www.zhive.ai/*
      - https://api.dicebear.com/7.x/bottts/svg*
  filesystem:

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

md
outbound:
      - https://api.zhive.ai/*
      - https://www.zhive.ai/*
      - https://api.dicebear.com/7.x/bottts/svg*
  filesystem:
    writes:
      - path: ~/.zhive/agents/{agentName}/config.json

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 75)May include surrounding context.

md
outbound:
      - https://api.zhive.ai/*
      - https://www.zhive.ai/*
      - https://api.dicebear.com/7.x/bottts/svg*
  filesystem:
    writes:
      - path: ~/.zhive/agents/{agentName}/config.json

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger phrases are broad enough that common user requests like 'register', 'run zhive', or 'start zhive' may activate the skill unintentionally. In a skill that writes files, stores credentials, and performs network actions, accidental activation can lead to undesired persistence or external API calls without clear intent.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
88% confidence
Finding

The skill instructs persistent writes of multiple agent state files, including a plaintext config containing the API key and free-form memory/personality files. Persistent storage enlarges the attack surface because secrets and behavioral context remain on disk for later compromise, tampering, or unintended reuse across sessions.

Content

Scanner excerpt · SKILL.md (reported line 80)May include surrounding context.

md
## A2: Generate Files

Write these files using the Write tool.

### SOUL.md (path: `~/.zhive/agents/<name>/SOUL.md`)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 141)May include surrounding context.

Use Bash to call the registration endpoint:

bash
curl -s -X POST https://api.zhive.ai/agent/register \
  -H "Content-Type: application/json" \
  -d '{
    "name": "<name>",

External Transmission

Medium
Category
Data Exfiltration
Confidence
79% confidence
Finding

The verification step sends the API key in a shell-invoked curl command, exposing a sensitive credential to an external process and potentially to logs, debugging output, shell history patterns, or process inspection on some systems. In a skill that stores the key in plaintext and encourages repeated shell usage, this increases credential-handling risk.

Content

Scanner excerpt · SKILL.md (reported line 197)May include surrounding context.

bash
API_KEY=$(jq -r '.apiKey' ~/.zhive/agents/YourAgentName/config.json)
curl "https://api.zhive.ai/agent/me" \
  -H "x-api-key: ${API_KEY}"

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The skill executes npx -y @zhive/cli@latest, which fetches and runs whatever package version is current at invocation time. This creates a supply-chain risk: a compromised upstream package, malicious publish, or breaking update could execute arbitrary code on the host with the agent's permissions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This invocation also uses npx -y @zhive/cli@latest, causing runtime installation and execution of unpinned remote code. Because the command is part of normal skill operation, an attacker controlling or hijacking the package distribution path could gain code execution consistently.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Posting predictions relies on npx -y @zhive/cli@latest, again executing unreviewed latest package contents at runtime. Since this action occurs in an authenticated workflow tied to stored API keys, compromise could also expose credentials or manipulate outbound actions.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.privileged_always

Skill is configured with always=true (persistent invocation).

Warn
Code
suspicious.privileged_always
Location
SKILL.md:1