T09 · Insecure Skill Coding Practices
- Location
scripts/test-agent.py:184- Finding
Bearer API Keys Can Be Transmitted over Plaintext HTTP
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly does what it says, but some copy-ready testing and deployment examples could leak API keys or expose agent services if used unchanged.
Install only if you are comfortable reviewing and hardening the generated agent before use. Use HTTPS whenever sending API keys, prefer environment or secret-manager injection over command-line keys, add authentication, rate limits, input validation, and restricted CORS before exposing an agent, replace default database/cache credentials, avoid public Redis ports, pin dependencies and container images, and use dedicated revocable keys for Warden Studio or LangSmith.
scripts/test-agent.py:184Bearer API Keys Can Be Transmitted over Plaintext HTTP
references/deployment-guide.md:478Production Agent Endpoints Lack Authentication and Use Unrestricted CORS
references/deployment-guide.md:591Sensitive User Prompts May Be Persisted in Application Logs
assets/example-configs.md:232Example Infrastructure Exposes Redis and Uses Predictable Database Credentials
scripts/init-agent.py:25Generated Projects Use Unbounded Dependency Version Ranges
The declared description focuses on agent creation, LangGraph/Warden development, deployment preparation, and Warden Studio publishing. The actual code does none of that: it does not generate agents, configure LangGraph, prepare deployment artifacts, or integrate with Warden Studio. Its primary purpose is operational testing of an already deployed agent API via /health, /invoke, and /stream endpoints. That is a materially different purpose, so this is a clear description-behavior mismatch.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"graphs": {
"agent": "./src/graph.ts"
},
"env": ".env"
}""",
".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"graphs": {
"agent": "./src/graph.ts"
},
"env": ".env"
}""",
".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"graphs": {
"agent": "./src/graph.ts"
},
"env": ".env"
}""",
".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"graphs": {
"agent": "./src/graph.ts"
},
"env": ".env"
}""",
".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
"graphs": {
"agent": "./src/graph.ts"
},
"env": ".env"
}""",
".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# WEATHER_API_KEY=""",
".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
"src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";
The trigger guidance includes broad phrases such as "LangGraph agent" and generic Warden-related requests, which can cause the skill to activate outside its narrow intended scope. In an agent framework, over-broad activation increases the chance of inappropriate context injection, unintended tool guidance, or the model following skill-specific workflows when the user only asked a general question.
The activation description says the skill triggers when users mention Warden or LangGraph agents, but it does not define exclusion boundaries. That ambiguity can cause the system to route ordinary LangGraph or crypto-agent requests into this skill, creating prompt-scope confusion and increasing the risk of irrelevant or unsafe operational instructions being applied in the wrong context.
The skill contains operational instructions that involve shell commands, network access, environment-variable handling, and file creation, but it does not declare any explicit tool scope or permission boundaries. That increases the chance an agent executing the skill could overreach and perform actions the user did not clearly authorize, especially in environments where tool access is gated by metadata.
The skill instructs users to place real API keys in a .env file and to send an API key in request headers, but it does not warn about secret handling, least privilege, rotation, or avoiding disclosure through logs, screenshots, shell history, and source control. This can lead to credential leakage and downstream compromise of deployment, LLM, or third-party service accounts.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Test your agent's API:
curl -X POST http://localhost:8000/invoke \
-H "Content-Type: application/json" \
-d '{"input": "test query"}'
The skill tells users to provide an API URL and API key to Warden Studio without warning that this grants a third-party platform delegated access to the agent backend. If users share broad or long-lived credentials, compromise of that platform account or misconfiguration could expose the agent, associated data, or connected services.
Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
apis: {
coingecko: {
key: process.env.COINGECKO_API_KEY,
baseUrl: 'https://api.coingecko.com/api/v3'
},
alchemy: {
key: process.env.ALCHEMY_API_KEY!,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
apis: {
coingecko: {
key: process.env.COINGECKO_API_KEY,
baseUrl: 'https://api.coingecko.com/api/v3'
},
alchemy: {
key: process.env.ALCHEMY_API_KEY!,
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
},
weather: {
key: process.env.WEATHER_API_KEY!,
baseUrl: 'https://api.weatherapi.com/v1'
}
},
server: {
No suspicious patterns detected.