Back to skill

Security audit

CurlShip Directory Submission

Security checks for vulnerabilities and agentic risk

Overview

The skill is a documented CurlShip directory-submission helper that sends a public product URL and contact email to CurlShip, with no local persistence or hidden execution.

Install only if you intend to submit public product pages to CurlShip. Do not submit private, internal, embargoed, or sensitive URLs, and use a contact email you are comfortable sharing with the service. Treat paid-tier upgrades as user-confirmed actions because the skill only returns a checkout URL but may lead to payment outside the agent.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

External Transmission

Medium
Category
Data Exfiltration
Confidence
87% confidence
Finding

The skill is explicitly designed to transmit user-supplied data to an external service, but the top-level description does not surface that privacy-relevant behavior prominently. Because the skill advertises one-command submission and scraping functionality, an agent or user may invoke it without appreciating that URLs and email addresses are being disclosed to a third party.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: CurlShip Directory Submission
description: Submit products to CurlShip, the bot-friendly SaaS directory. One curl command to list your product with OG tag scraping, badge-based dofollow links, and tier upgrades.
version: 1.0.0
homepage: https://curlship.com
credentials_required: false

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill instructs users to send a product URL and contact email to a third-party service but does not clearly warn that this data will leave the local environment and be processed externally. This creates a privacy and consent risk, especially because the service also performs OG-tag scraping of the submitted URL, which may cause users or agents to transmit sensitive business contact data without explicit acknowledgment.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.