Back to skill

Security audit

Build an Agent with Warden

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly does what it says, but some copy-ready testing and deployment examples could leak API keys or expose agent services if used unchanged.

Install only if you are comfortable reviewing and hardening the generated agent before use. Use HTTPS whenever sending API keys, prefer environment or secret-manager injection over command-line keys, add authentication, rate limits, input validation, and restricted CORS before exposing an agent, replace default database/cache credentials, avoid public Redis ports, pin dependencies and container images, and use dedicated revocable keys for Warden Studio or LangSmith.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/test-agent.py:184
Finding

Bearer API Keys Can Be Transmitted over Plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/deployment-guide.md:478
Finding

Production Agent Endpoints Lack Authentication and Use Unrestricted CORS

Content
View full analysis
{ console.log(`${new Date().toISOString()} ${req.method} ${req.path}`); next(); }); // Health check app.get('/health', (req, res) => { res.json({ status: 'healthy', timestamp: new Date().toISOString() }); }); // Readiness check app.get('/ready', async (req, res) => { try { // Check dependencies await checkDependencies(); res.json({ status: 'ready' }); } catch (error) { res.status(503).json({ status: 'not ready', error: error.message }); } }); // Main agent endpoint app.post('/invoke', async (req, res) => { try { const { input } = req.body; if (!input) { return res.status(400).json({ error: 'Input required' }); } const result = await agent.invoke({ input }); res.json(result); } catch (error) { console.error('Agent error:', error); res.status(500).json({ error: 'Internal error', message: error.message }); } }); // Streaming endpoint app.post('/stream', async (req, res) => { try { const { input } = req.body; res.setHeader('Content-Type', 'text/event-stream'); res.setHeader('Cache-Control', 'no-cache'); res.setHeader('Connection', 'keep-alive'); const stream = await agent.stream({ input }); for await (const chunk of stream) { res.write(`data: ${JSON.stringify(chunk)}\n\n`); } res.end(); } catch (error) { console.error('Streaming error:', error); res.write(`data: ${JSON.stringify({ error: error.message })}\n\n`); res.end(); } }); ``` The guide also shows direct public exposure: ```yaml apiVersion: v1 k ...[truncated 2108 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/deployment-guide.md:591
Finding

Sensitive User Prompts May Be Persisted in Application Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
assets/example-configs.md:232
Finding

Example Infrastructure Exposes Redis and Uses Predictable Database Credentials

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/init-agent.py:25
Finding

Generated Projects Use Unbounded Dependency Version Ranges

Content
View full analysis
=0.0.19 langchain-openai>=0.0.19 python-dotenv>=1.0.0 fastapi>=0.100.0 uvicorn>=0.23.0""" ``` ### Technical Analysis Generated TypeScript projects use caret ranges, while Python projects specify only minimum versions. The resulting installation is therefore dependent on whichever matching package versions are available when the user runs `npm install` or `pip install`. The Python constraints have no upper bounds and may resolve to substantially newer releases than those reviewed when the Skill was created. The generated project also does not include a lockfile or hash-locked requirements. This prevents reproducible builds and increases exposure to compromised package releases, malicious maintainer updates, and unexpected incompatible changes. The audit did not identify a known malicious package or typosquatted name in these lists. The risk comes from unconstrained future resolution and installation rather than a confirmed malicious dependency currently embedded in the repository. ### Attack Path 1. A user generates a project with `init-agent.py`. 2. The user follows the generated instructions and installs dependencies. 3. A future matching dependency version is ...[truncated 924 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (42)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description focuses on agent creation, LangGraph/Warden development, deployment preparation, and Warden Studio publishing. The actual code does none of that: it does not generate agents, configure LangGraph, prepare deployment artifacts, or integrate with Warden Studio. Its primary purpose is operational testing of an already deployed agent API via /health, /invoke, and /stream endpoints. That is a materially different purpose, so this is a clear description-behavior mismatch.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 244)May include surrounding context.

md
"graphs": {
    "agent": "./src/graph.ts"
  },
  "env": ".env"
}""",
            ".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/example-configs.md (reported line 191)May include surrounding context.

md
"graphs": {
    "agent": "./src/graph.ts"
  },
  "env": ".env"
}""",
            ".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/example-configs.md (reported line 206)May include surrounding context.

md
"graphs": {
    "agent": "./src/graph.ts"
  },
  "env": ".env"
}""",
            ".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init-agent.py (reported line 62)May include surrounding context.

python
"graphs": {
    "agent": "./src/graph.ts"
  },
  "env": ".env"
}""",
            ".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init-agent.py (reported line 191)May include surrounding context.

python
"graphs": {
    "agent": "./src/graph.ts"
  },
  "env": ".env"
}""",
            ".env.example": """# OpenAI Configuration
OPENAI_API_KEY=your_openai_key_here

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/example-configs.md (reported line 223)May include surrounding context.

md
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/example-configs.md (reported line 243)May include surrounding context.

md
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · assets/example-configs.md (reported line 273)May include surrounding context.

md
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/quick-reference.md (reported line 185)May include surrounding context.

md
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init-agent.py (reported line 81)May include surrounding context.

python
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init-agent.py (reported line 139)May include surrounding context.

python
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init-agent.py (reported line 209)May include surrounding context.

python
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init-agent.py (reported line 267)May include surrounding context.

python
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/init-agent.py (reported line 361)May include surrounding context.

python
# WEATHER_API_KEY=""",
            ".gitignore": """node_modules/
dist/
.env
*.log
.DS_Store""",
            "src/graph.ts": """import { StateGraph, END } from "@langchain/langgraph";

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger guidance includes broad phrases such as "LangGraph agent" and generic Warden-related requests, which can cause the skill to activate outside its narrow intended scope. In an agent framework, over-broad activation increases the chance of inappropriate context injection, unintended tool guidance, or the model following skill-specific workflows when the user only asked a general question.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The activation description says the skill triggers when users mention Warden or LangGraph agents, but it does not define exclusion boundaries. That ambiguity can cause the system to route ordinary LangGraph or crypto-agent requests into this skill, creating prompt-scope confusion and increasing the risk of irrelevant or unsafe operational instructions being applied in the wrong context.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill contains operational instructions that involve shell commands, network access, environment-variable handling, and file creation, but it does not declare any explicit tool scope or permission boundaries. That increases the chance an agent executing the skill could overreach and perform actions the user did not clearly authorize, especially in environments where tool access is gated by metadata.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to place real API keys in a .env file and to send an API key in request headers, but it does not warn about secret handling, least privilege, rotation, or avoiding disclosure through logs, screenshots, shell history, and source control. This can lead to credential leakage and downstream compromise of deployment, LLM, or third-party service accounts.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

Test your agent's API:

bash
curl -X POST http://localhost:8000/invoke \
  -H "Content-Type: application/json" \
  -d '{"input": "test query"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells users to provide an API URL and API key to Warden Studio without warning that this grants a third-party platform delegated access to the agent backend. If users share broad or long-lived credentials, compromise of that platform account or misconfiguration could expose the agent, associated data, or connected services.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
75% confidence
Finding

Docker image references without a specific tag (:latest is implicit) or digest (@sha256:...) can be silently replaced by a malicious image.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deployment-guide.md (reported line 24)May include surrounding context.

md
apis: {
    coingecko: {
      key: process.env.COINGECKO_API_KEY,
      baseUrl: 'https://api.coingecko.com/api/v3'
    },
    alchemy: {
      key: process.env.ALCHEMY_API_KEY!,

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/langgraph-patterns.md (reported line 135)May include surrounding context.

md
apis: {
    coingecko: {
      key: process.env.COINGECKO_API_KEY,
      baseUrl: 'https://api.coingecko.com/api/v3'
    },
    alchemy: {
      key: process.env.ALCHEMY_API_KEY!,

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deployment-guide.md (reported line 32)May include surrounding context.

md
},
    weather: {
      key: process.env.WEATHER_API_KEY!,
      baseUrl: 'https://api.weatherapi.com/v1'
    }
  },
  server: {

Static analysis

No suspicious patterns detected.