Back to skill

Security audit

V19 Coherence Auditor

Security checks for vulnerabilities and agentic risk

Overview

This skill does not install local code, but it asks users to send keys and agent names to an undocumented temporary web service, so it should be reviewed before use.

Install only if you trust the V19 service operator and are comfortable contacting the listed external endpoint. Do not send real secrets as governance keys, use non-identifying agent names for registration, and treat returned scores as unverified unless the operator documents ownership, privacy handling, and result integrity.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

other

Warning
Location
SKILL.md:90
Finding

Untrusted Temporary External Service Used for Governance Results

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:90-93
Vulnerability Type: Untrusted External Service Interaction
Risk Level: Medium

bash
curl -s https://boat-atlas-spa-flexible.trycloudflare.com/governance/health \
  -H "X-Governance-Key: v19-e5d585e28439decc614f09f91c4caa8c"

Technical Analysis

The Skill directs users to send governance requests to a temporary trycloudflare.com tunnel. The identity and security controls of the service operator are not documented, and the project contains no local implementation that calculates or independently verifies the returned health and coherence values.

Because the remote operator controls the endpoint, it can modify responses without changing the reviewed Skill. Requests also disclose connection metadata, including the caller's IP address, request timing, user-agent information, and the supplied governance key. The separate registration example at SKILL.md:95-101 additionally instructs callers to transmit an agent name to the same service.

The embedded key is explicitly presented as public, so it is not treated as a leaked secret. No evidence of remote payload execution, local command injection, persistence, privilege escalation, dependency installation, or credential-file access was found.

Attack Path

  1. A user follows the Skill documentation and invokes one of the provided curl commands.
  2. The request is sent to the externally controlled Cloudflare tunnel.
  3. The service operator receives network metadata, the public governance key, and, for registration requests, the supplied agent name.
  4. The operator can return fabricated or selectively manipulated health and coherence results.
  5. If those unverified results are used for governance decisions, the caller may incorrectly classify system health or architecture risks.

Impact Assessment

The external service can observe callers and influence the audit information presented to them. Th ...[truncated 415 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace the temporary Cloudflare tunnel with a stable service domain owned and documented by the project operator.
  • Publish the operator identity, privacy policy, retention period, transmitted-data inventory, and incident-response process.
  • Avoid registration unless it is necessary; use a non-identifying random identifier instead of an agent name.
  • Calculate coherence metrics locally where possible. If remote calculation is required, return signed results and verify the signature locally.
  • Document the metric inputs and scoring algorithm so callers can independently validate returned values.
  • Use scoped, revocable credentials rather than a shared public key for endpoints requiring authorization.
  • Apply request minimization, rate limiting, server authentication monitoring, audit logging, and explicit user consent before transmitting data.
  • Clearly warn users that invoking the examples contacts a third-party service and discloses network metadata.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The markdown instructs outbound requests to an external domain and transmission of identifiers such as governance keys and agent names without any warning about data sharing, operator identity, retention, or privacy implications. Users may unknowingly disclose sensitive metadata or credentials to a third-party endpoint while believing they are only using a local auditing skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The skill contains explicit instructions for making an outbound network call to a live external endpoint using a governance key. In context, this is more dangerous because the skill presents itself as an auditor, yet it encourages transmission of potentially sensitive operational metadata to a third-party service without adequate trust or privacy disclosure.

Content

Scanner excerpt · SKILL.md (reported line 67)May include surrounding context.

bash
# 获取全局协同指数
curl -s https://boat-atlas-spa-flexible.trycloudflare.com/governance/coherence \
  -H "X-Governance-Key: <你的专属密钥>"

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill is described as an auditing/documentation skill, but it includes live operational endpoints and a registration flow that enable users to interact with an external service. This expands the capability from passive analysis to active network interaction and account/service enrollment, which can cause unintended data disclosure and misuse of external infrastructure.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

A public self-registration endpoint is not necessary for a coherence-auditing skill and creates an unnecessary expansion of attack surface. It can be abused for unauthorized enrollment, spam, telemetry collection, or driving users to interact with an unvetted third-party service under the guise of analysis.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The description and operating instructions are written in Chinese, and the file does not indicate that this locale is optional or region-specific. This can constitute a language-policy issue when a skill effectively forces one language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.