Back to skill

Security audit

Submit Directories

Security checks for vulnerabilities and agentic risk

Overview

This skill is not hidden malware, but it can automatically send credentials, contact details, and uploads to many third-party websites with insufficient safety checks.

Review before installing. Use only throwaway credentials, remove or disable plaintext HTTP and untrusted targets, inspect the generated submission_plan.json, and require manual confirmation before any password entry, OAuth flow, file upload, or final form submission. Run it in an isolated project with no unrelated secrets in the environment.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
submit_directories.py:125
Finding

Sensitive information and credentials may be submitted over plaintext HTTP

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
submit_directories.py:89
Finding

Untrusted form metadata controls sensitive-value routing and automatic submission

Content
View full analysis
{ const els = document.querySelectorAll('input, textarea, select'); return [...els].map(el => ({ tag: el.tagName.toLowerCase(), type: (el.type || '').toLowerCase(), name: el.name || '', id: el.id || '', placeholder: (el.placeholder || '').substring(0, 100), label: (el.labels?.[0]?.textContent?.trim() || el.getAttribute('aria-label') || '').substring(0, 100), visible: el.offsetParent !== null, })); }''') ``` `submit_directories.py:125-126` treats attacker-controlled field types and descriptions as sufficient authority to disclose credentials: ```python if ftype == 'password': return PRODUCT['password'] if ftype == 'email' or re.search(r'e-?mail|e_mail', c): return PRODUCT['email'] ``` `submit_directories.py:221-236` automatically selects and activates a submit-like control: ```python # --- Click submit --- submitted = False btn_text = '' async def try_click(locator): nonlocal submitted, btn_text try: if await locator.is_visible(timeout=1000): try: btn_text = (await locator.inner_text()).strip()[:50] except Exception: btn_text = (await locator.get_attribute('value') or '')[:50] await locator.cli ...[truncated 2730 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:1
Finding

Third-party dependency is installed using an open-ended version constraint without integrity locking

Content
View full analysis
=1.40.0 ``` `SKILL.md:16-21` instructs users to install the dynamically resolved package and browser: ```bash pip install -r requirements.txt playwright install chromium ``` ### Technical Analysis The dependency name is consistent with the official Playwright Python package, and the audit found no evidence of typosquatting or a deliberately malicious package source. However, the open-ended `>=` requirement means future installations may execute dependency code that was not part of this audit. No lockfile or package hash is provided, and the browser installation step also dynamically obtains a browser build associated with the resolved Playwright version. This prevents reproducible installation and weakens supply-chain integrity. This is a hardening issue rather than evidence that the current dependency is malicious. ### Attack Path 1. A user follows the documented installation instructions. 2. The package index resolves the newest Playwright version satisfying `>=1.40.0`. 3. A future compromised, malicious, or unexpectedly incompatible release is selected. 4. Package installation or later import executes code outside the version reviewed during this audit. 5. The dynamically selected browser component may also differ from the audited environment. Successful exploitation depends on compromise or malicious modification of an upstream distribution channel or future accepted release. ### Impact Assessment Python packages execute with the permissions of the user running `pip` or the Skill. A compromised dependency could therefore: - Read project files and environment variables. - Access configured submission credentials. - Make arbitr ...[truncated 228 chars]
Remediation
View remediation
`. 2. Generate a hash-locked requirements file and install with hash verification. 3. Use a lockfile produced by a dependency-management tool that records transitive dependencies. 4. Pin and document the corresponding Chromium revision. 5. Perform dependency review and testing before updating either Playwright or Chromium. 6. Install dependencies inside an isolated virtual environment using a non-privileged account. 7. Use a trusted package index and retain installation provenance or software-bill-of-materials data. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (32)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code’s primary purpose is narrow: it loads URLs from JSON, opens them in headless Chromium, classifies whether pages are active/not found/parked/Cloudflare-blocked, detects likely auth methods and captcha technologies, and saves these annotations back to directories.json. This aligns only with a small subset of the declared 'analyzing directories' functionality. The description claims a much broader submission automation pipeline—collecting product info, discovering forms, auto-submitting, handling captchas/OAuth/GitHub PRs, and checkpoint tracking—but none of those active submission or workflow features appear in this code chunk. Because the implemented behavior is materially narrower and lacks several specifically declared capabilities, this is a description-to-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents a comprehensive end-to-end submission automation skill. This code chunk is much narrower: it is a local data-cleanup and categorization utility for existing directory records. It does not browse sites, submit forms, handle authentication flows, solve captchas, create PRs, or track progress in checkpoint.md. While this script could be a supporting maintenance step within a larger directory-submission workflow, on its own it does not accurately represent the broad declared functionality, so the description materially overstates what the supplied code actually does.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The declared description presents a broad end-to-end submission system, but this code chunk is a narrower auto-submission executor. Its primary behavior is browser automation for filling and submitting forms on already-discovered directory pages. While this is consistent with part of the declared purpose, several prominently claimed capabilities are absent from the code: no directory analysis/discovery, no product-info collection, no captcha solving/handling beyond skipping matching fields, no OAuth or GitHub PR flow support, and no checkpoint.md tracking. The mismatch is therefore material because the description overstates what this supplied code chunk actually does.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
95% confidence
Finding

The skill instructs loading a local .env via source, and the workflow relies on sensitive values like submission email, usernames, and passwords. In an agent context with file-read/env access, this increases the chance of credential exposure through logs, accidental file reads, downstream writes, or misuse by other steps interacting with third-party sites.

Content

Scanner excerpt · SKILL.md (reported line 49)May include surrounding context.

Tip: save these to a local .env file (already in .gitignore) and load with:

bash
set -a && source .env && set +a

Place assets

YARA rule 'privilege_escalation_tools': Privilege escalation tools and techniques [hacktools]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a hack tool or exploit indicator (offensive tools, reconnaissance, privilege escalation, or exploit frameworks).

Content

Scanner excerpt · directories.json (reported line 416)May include surrounding context.

json
],
    "site_status": "domain_dead",
    "analysis_error": "<urlopen error [Errno -3] Temporary failure in name resolution>"
  },
  {
    "categories": [
      "General"
    ],
    "description": "Submit your product to App Spy to reach your target audience.",
    "is_active": true,
    "name": "App Spy",
    "pricing_type": "free",
    "slug": "app-spy",
    "submission_url": "https://www.appspy.com",
    "url": "https://www.appspy.com",
    "auth_type": "none",
    "captcha_type": "none",
    "requires_login": false,
    "pricing_signals": [
      "paid_signals"
    ],
    "site_status": "active"
  },
  {
    "categories": [
      "General"
    ],
    "description": "Submit your product to App Sumo to reach your target audience.",
    "is_active": true,
    "name": "App Sumo",
    "pricing_type": "free",
    "slug": "app-sumo",
    "submission_url": "https://appsumo.com/sell",
    "url": "https://appsumo.com/sell",
    "auth_type": "google_only",
    "captcha_type": "none",

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill clearly expects access to environment variables, local files, and external network targets, yet it declares no explicit tool scope or allowed-tools boundary. In an agent setting, that makes the operational blast radius ambiguous and can permit broader-than-necessary access when handling credentials, reading .env, writing tracking files, and browsing third-party submission sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script overwrites directories.json in place after processing without creating a backup, temporary file, or prompting the user. If execution is interrupted, results are malformed, or the input file was not meant to be mutated, this can cause data loss or corrupt workflow state, which is more concerning in a skill that tracks and transforms submission data across many sites.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The script reads URLs from JSON inputs and automatically launches a browser to visit them, which causes external network access to arbitrary third-party sites without any confirmation, allowlist, or safety gate. In the context of a submission automation skill, this increases risk of unintended contact with malicious or internal URLs, privacy leaks via browser fingerprinting/IP exposure, and possible SSRF-style access if an attacker can influence the URL list.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This code performs an in-place write to the primary data file, replacing its contents with modified data. Although the script prints a summary afterward, there is no user-facing warning or confirmation before the overwrite, and the module docstring does not disclose that it will modify the input file.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest describes a skill for submitting products to AI/startup directories, but this file includes many targets that are not plausibly AI/startup directories, such as generic social platforms, subreddits, media outlets, local business listings, and broad web directories. That materially broadens the operational scope from directory submission to general internet promotion/distribution.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 3055)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 3056)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 4772)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 4773)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 12389)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 12391)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 12392)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 12393)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 13695)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 13697)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 13698)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · directories.json (reported line 13699)May include surrounding context.

json
"name": "Open Startup List",
    "pricing_type": "free",
    "slug": "open-startup-list",
    "submission_url": "https://openstartuplist.com",
    "url": "https://openstartuplist.com",
    "auth_type": "none",
    "captcha_type": "none",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The description explicitly labels this as a "Chinese AI Tools Directory," which bakes a locale/language constraint into the listing metadata without any indication of user opt-in or why that restriction is required. Under the policy, forcing a specific language or locale without choice or documented justification is a natural-language policy issue.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The description says "A french directory," which declares a fixed language/locale scope but does not offer any user choice or explain why that locale restriction is necessary. This matches the policy's prohibition on language or locale constraints that are not opt-in or clearly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This code performs a file write that changes the existing submission_plan.json in place. Although the module docstring mentions updating the file, there is no runtime confirmation prompt or explicit user-facing warning immediately before the destructive overwrite, which can surprise users if they expected a read-only discovery pass.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal, suspicious.install_untrusted_source

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
submit_directories.py:17

Install source points to URL shortener or raw IP.

Warn
Code
suspicious.install_untrusted_source
Location
directories.json:6606