Back to skill

Security audit

Immortal

Security checks for vulnerabilities and agentic risk

Overview

The skill’s crypto-risk purpose is clear, but it can be directed to make network requests to arbitrary API hosts without validation or domain limits.

Review before installing in environments with access to private networks or sensitive internal services. Use only the default or a trusted HTTPS API endpoint, avoid accepting coin/API arguments from untrusted prompts, and do not treat the generated classifications as financial advice.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/assess_vitality.py:103
Finding

Unrestricted API Endpoint and Unsafe URL Construction Enable SSRF

Content
View full analysis

Vulnerability Details

File Location: scripts/assess_vitality.py, lines 103-106 and 159-162
Vulnerability Type: Server-Side Request Forgery (SSRF) and unsafe URL construction
Risk Level: Medium

Vulnerable Code

python
for coin in coins:
    url = f"{api_base}/api/metrics/{coin}?days={days}"
    try:
        metrics = await _fetch_json(url)
python
parser.add_argument(
    "--api", default=DEFAULT_API_BASE,
    help=f"Base URL of the Majestify API (default: {DEFAULT_API_BASE})"
)

Technical Analysis

The command-line --api value is used as the request destination without validating its scheme, hostname, resolved IP address, or port. Consequently, a caller able to influence the script arguments can direct HTTP requests to loopback addresses, private networks, link-local services, or cloud metadata endpoints.

The coin value is also interpolated directly into the URL path without encoding or validation. Crafted values containing traversal sequences, query delimiters, or fragments may alter the intended /api/metrics/{coin} request path after processing by the client, proxy, or destination server.

The script also permits plaintext HTTP endpoints. An attacker with a suitable network position could tamper with metric responses and influence the resulting financial classification. Response data is trusted with only a minimal check for the sharpeRatio field; the remaining schema and numeric ranges are not validated.

Attack Path

  1. An attacker causes an agent or user to invoke the skill with an attacker-selected --api argument.
  2. The attacker supplies a destination such as a loopback, private-network, link-local, or other internal HTTP service.
  3. If needed, the attacker supplies a crafted --coins value containing path manipulation characters to change the effective internal resource path.
  4. The script constructs the URL directly from these values and _fetch_json sends the request from the agent's n ...[truncated 979 chars]
Remediation
View remediation

Remediation Suggestions

  1. Restrict API destinations to HTTPS and an explicit allowlist of trusted hostnames, using the documented Majestify endpoint as the default allowed destination.
  2. If custom endpoints are required, place them behind an explicit trusted configuration rather than accepting unrestricted runtime input.
  3. Parse URLs with urllib.parse.urlsplit and reject embedded credentials, fragments, unexpected ports, and unsupported schemes.
  4. Resolve destination hostnames and reject loopback, private, link-local, multicast, unspecified, reserved, and cloud-metadata address ranges for both IPv4 and IPv6.
  5. Revalidate the destination after every redirect, or disable redirects entirely. This is necessary to mitigate redirects and DNS-rebinding techniques that bypass an initial hostname check.
  6. Enforce a strict asset identifier pattern such as ^[a-z0-9-]+$ and URL-encode the accepted value before inserting it into the path.
  7. Validate days against a reasonable positive range to prevent malformed or abusive requests.
  8. Validate the complete response schema, require finite numeric values, and enforce plausible metric ranges before classification.
  9. Avoid plaintext HTTP so that metric responses cannot be modified in transit.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill explicitly relies on internet access and documents calls to an external API, but it does not declare any tool scope or permissions boundary for network use. In agent environments, this can cause silent or over-broad network capability, reducing user visibility and allowing the skill to transmit prompts or asset query data off-host without explicit authorization.

Content

No source excerpt is available for this finding.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 93)May include surrounding context.

md
## Related Skills

- [immortal-api](file:///.agent/skills/immortal-api/SKILL.md) — Full compute-budget survival API with ledger, optimizer, policy engine, and circuit breakers.
- [financial_analysis](file:///.agent/skills/financial_analysis/SKILL.md) — Coding standards and metric comparison guidelines.

Skill Enumeration

Medium
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

md
## Related Skills

- [immortal-api](file:///.agent/skills/immortal-api/SKILL.md) — Full compute-budget survival API with ledger, optimizer, policy engine, and circuit breakers.
- [financial_analysis](file:///.agent/skills/financial_analysis/SKILL.md) — Coding standards and metric comparison guidelines.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The usage/docs do not clearly warn users that asset identifiers and request metadata will be sent to a third-party API over the network. While the transmitted data appears limited, lack of disclosure can lead to unintentional data sharing and prevents informed consent in privacy-sensitive agent deployments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.