Back to skill

Security audit

MerkleMap OSINT

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent MerkleMap OSINT skill, but users should review it because it writes sensitive reconnaissance reports and its HTML report instructions do not require escaping untrusted certificate data.

Install only if you are comfortable sending investigation targets to MerkleMap and storing recon results locally. Treat generated reports as sensitive files, avoid saving them in synced or public folders, and review or modify report generation to HTML-escape all API-returned values before opening reports in a browser.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:464
Finding

Unescaped API Data in Generated HTML Reports

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 464–689 and 697–708
Vulnerability Type: HTML injection / stored cross-site scripting in generated reports
Risk Level: Medium

Vulnerable Code

html
<title>MerkleMap OSINT Report — {{target}}</title>
...
<div class="executive-summary">
  {{executive_summary_paragraph}}
</div>
...
<tr>
  <td>{{cn}}</td><td>{{issuer}}</td><td>{{not_before}}</td><td>{{not_after}}</td>
  <td><span class="badge valid">VALID</span></td>
  <td>{{algo}} {{size}}</td><td><code>{{sha256}}</code></td>
</tr>
...
<tr><td><strong>Subject</strong></td><td>{{common_name}} — {{organization}}, {{country}}</td></tr>
<tr><td><strong>Issuer</strong></td><td>{{issuer_cn}} — {{issuer_org}}, {{issuer_country}}</td></tr>
text
3. **Build the HTML.** Replace all `{{placeholders}}` with real data. **Only include sections relevant to the scan** — omit empty sections entirely.

Technical Analysis

The Skill instructs the agent to generate a self-contained HTML report by replacing template placeholders with data returned by the MerkleMap API. It does not require context-appropriate HTML escaping or sanitization before inserting remote values into element text, table cells, attributes, or the document title.

Certificate Transparency data can contain externally controlled certificate subject fields, including common names and organization information. Subdomain and certificate metadata must therefore be treated as untrusted. If a value contains HTML metacharacters or active markup, direct placeholder substitution can cause the browser to interpret the value as document structure rather than text.

Inline CSS and the absence of external dependencies do not prevent this issue. The supplied template also does not define a Content Security Policy that would constrain injected active content.

Attack Path

  1. An attacker obtains or submits a certificate whose exposed subject metadata contains crafted HTML or script-capa ...[truncated 1404 chars]
Remediation
View remediation

Remediation Suggestions

  1. Require HTML escaping for every dynamic value before template substitution. At minimum, encode:

    • & as &amp;
    • < as &lt;
    • > as &gt;
    • " as &quot;
    • ' as &#39;
  2. Use a templating system with automatic escaping enabled rather than direct string replacement.

  3. Apply output encoding according to context. Text-node encoding is insufficient for values inserted into HTML attributes, URLs, CSS, or JavaScript contexts.

  4. Validate fields with narrow expected formats:

    • Hostnames should conform to valid DNS-name rules.
    • SHA-256 fingerprints should contain only the expected hexadecimal characters and length.
    • Dates and numeric fields should be parsed and rendered from typed values.
    • URLs should use an explicit allowlist of permitted schemes and hosts.
  5. Avoid inserting API-returned content through innerHTML. If report generation uses DOM APIs, assign untrusted values using textContent.

  6. Add a restrictive Content Security Policy to generated reports, for example:

html
<meta http-equiv="Content-Security-Policy"
      content="default-src 'none'; style-src 'unsafe-inline'; img-src data:; base-uri 'none'; form-action 'none'; frame-ancestors 'none'">
  1. Add security tests using payloads in every remotely sourced field, including values such as:
text
&lt;img src=x onerror=alert(1)&gt;

The generated report should display the payload literally as text and must not create executable DOM elements.

  1. Document that all MerkleMap and Certificate Transparency data is untrusted, even when returned by an authenticated API.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The README instructs users to configure an API key and use external API and live CT-stream functionality without clearly warning that queried domains, hostnames, and scan activity are transmitted to the third-party MerkleMap service. For an OSINT reconnaissance skill, this can leak investigation targets, monitoring interests, or sensitive internal hostnames to an external provider, which is especially risky in corporate or incident-response use cases.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The README promotes automatic HTML/JSON report generation and saving reports to local disk, but it does not warn that reconnaissance outputs may contain sensitive infrastructure details such as subdomains, certificate metadata, and risk findings. In an OSINT/security context, silently persisting these artifacts can increase exposure if the workstation is shared, compromised, synced to cloud storage, or committed to source control.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 42)May include surrounding context.

md
| Detail | Value |
|--------|-------|
| Method | `GET` |
| URL | `https://api.merklemap.com/v1/search` |

### Parameters

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
| Detail | Value |
|--------|-------|
| Method | `GET` |
| URL | `https://api.merklemap.com/v1/search` |

### Parameters

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
| Detail | Value |
|--------|-------|
| Method | `GET` |
| URL | `https://api.merklemap.com/v1/search` |

### Parameters

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 181)May include surrounding context.

md
| Detail | Value |
|--------|-------|
| Method | `GET` |
| URL | `https://api.merklemap.com/v1/search` |

### Parameters

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to search the current directory for prior reports to implement diff mode, which expands behavior beyond the core MerkleMap API OSINT function into local filesystem discovery. Even though it is framed as convenience, scanning local files can expose unrelated sensitive artifacts, create privacy issues, and violate least-privilege expectations if the workspace contains other data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill says to always write HTML/JSON reports to disk when requested, but does not require warning the user about local file creation, location, or possible overwrite. Silent file writes reduce user control and can lead to data leakage, clutter, or accidental destruction of prior artifacts if filenames collide.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The report-generation triggers are broad and include vague phrases like 'or similar,' making it easy for normal conversation to unintentionally activate file-generation behavior. Over-broad trigger logic can cause the agent to perform higher-impact actions than the user intended, especially when those actions include writing to disk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill instructs the agent to write HTML and JSON files to disk, which introduces a local side effect not clearly declared in the skill metadata or bounded by explicit permissions. This can lead to unexpected artifact creation, overwriting of existing files, or persistence of reconnaissance data on the host without clear user consent.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.