other
- Location
SKILL.md:90- Finding
Untrusted Temporary External Service Used for Governance Results
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:90-93
Vulnerability Type: Untrusted External Service Interaction
Risk Level: Mediumbash curl -s https://boat-atlas-spa-flexible.trycloudflare.com/governance/health \ -H "X-Governance-Key: v19-e5d585e28439decc614f09f91c4caa8c"Technical Analysis
The Skill directs users to send governance requests to a temporary
trycloudflare.comtunnel. The identity and security controls of the service operator are not documented, and the project contains no local implementation that calculates or independently verifies the returned health and coherence values.Because the remote operator controls the endpoint, it can modify responses without changing the reviewed Skill. Requests also disclose connection metadata, including the caller's IP address, request timing, user-agent information, and the supplied governance key. The separate registration example at
SKILL.md:95-101additionally instructs callers to transmit an agent name to the same service.The embedded key is explicitly presented as public, so it is not treated as a leaked secret. No evidence of remote payload execution, local command injection, persistence, privilege escalation, dependency installation, or credential-file access was found.
Attack Path
- A user follows the Skill documentation and invokes one of the provided
curlcommands. - The request is sent to the externally controlled Cloudflare tunnel.
- The service operator receives network metadata, the public governance key, and, for registration requests, the supplied agent name.
- The operator can return fabricated or selectively manipulated health and coherence results.
- If those unverified results are used for governance decisions, the caller may incorrectly classify system health or architecture risks.
Impact Assessment
The external service can observe callers and influence the audit information presented to them. Th ...[truncated 415 chars]
- A user follows the Skill documentation and invokes one of the provided
- Remediation
View remediation
Remediation Suggestions
- Replace the temporary Cloudflare tunnel with a stable service domain owned and documented by the project operator.
- Publish the operator identity, privacy policy, retention period, transmitted-data inventory, and incident-response process.
- Avoid registration unless it is necessary; use a non-identifying random identifier instead of an agent name.
- Calculate coherence metrics locally where possible. If remote calculation is required, return signed results and verify the signature locally.
- Document the metric inputs and scoring algorithm so callers can independently validate returned values.
- Use scoped, revocable credentials rather than a shared public key for endpoints requiring authorization.
- Apply request minimization, rate limiting, server authentication monitoring, audit logging, and explicit user consent before transmitting data.
- Clearly warn users that invoking the examples contacts a third-party service and discloses network metadata.
