Back to skill

Security audit

Hippius Storage

Security checks for vulnerabilities and agentic risk

Overview

The skill is a real Hippius storage helper, but it needs Review because it under-warns about wallet seed storage, destructive or unencrypted storage actions, unpinned installs, and insecure RPC transport.

Install only if you are comfortable reviewing commands before execution. Use least-privilege Hippius credentials, avoid uploading sensitive files unless encryption and destination are explicit, do not use --no-encrypt for private data, confirm deletes manually, avoid putting wallet seed phrases in shell commands or plaintext config, and prefer pinned packages in an isolated environment. Treat RPC query results cautiously because the script defaults to plaintext HTTP.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/query_storage.py:129
Finding

Blockchain account queries use an unencrypted HTTP connection

Content
View full analysis

Vulnerability Details

File Location: scripts/query_storage.py, lines 129-141 and 279-281
Vulnerability Type: Plaintext transmission of account query data
Risk Level: Medium

python
def rpc_call(method: str, params: list, api_url: str = "http://api.hippius.io") -> Optional[Dict[str, Any]]:
    payload = {
        "jsonrpc": "2.0",
        "method": method,
        "params": params,
        "id": 1
    }
    headers = {"Content-Type": "application/json"}
    try:
        request = Request(
            api_url,
            data=json.dumps(payload).encode('utf-8'),
            headers=headers
        )
python
rpc_group.add_argument(
    "--api-url",
    default="http://api.hippius.io",
    help="Hippius RPC API URL (default: http://api.hippius.io)"
)

Technical Analysis

The default RPC endpoint uses plaintext HTTP. Calls to get_user_files, calculate_total_file_size, and get_free_credits_rpc transmit the supplied account address and requested operation without transport encryption or server authentication.

An on-path attacker can observe account identifiers and query activity, impersonate the RPC service, or modify returned file metadata, storage totals, and credit balances. Although the command-line parser exposes an --api-url option, args.api_url is never passed to rpc_call; therefore, this option does not allow users to replace the insecure default in the current implementation.

Sending an account address to an RPC service is relevant to the declared functionality, but sending it through plaintext HTTP exceeds the minimum risk necessary because authenticated HTTPS should be used.

Attack Path

  1. A user invokes the script with --account, optionally selecting file, storage, or credit queries.
  2. The script creates a JSON-RPC request containing the account address and query method.
  3. The request is sent to http://api.hippius.io over an unen ...[truncated 727 chars]
Remediation
View remediation

Remediation Suggestions

  • Change the default endpoint to a verified https:// URL.
  • Pass args.api_url through the query functions and into every rpc_call.
  • Parse and validate the configured URL before making a request.
  • Reject plaintext HTTP for non-loopback destinations.
  • If development over HTTP is necessary, restrict it to explicit loopback addresses such as 127.0.0.1 or localhost and require an opt-in flag.
  • Continue using standard certificate and hostname verification; do not add an option that silently disables TLS verification.
  • Add tests confirming that remote HTTP endpoints are rejected and the selected HTTPS endpoint is actually used.

T09 · Insecure Skill Coding Practices

Error
Location
references/cli_commands.md:14
Finding

Documentation exposes wallet seed phrases through command-line arguments and persistent configuration

Content
View full analysis

Vulnerability Details

File Location: references/cli_commands.md, lines 14-24
Vulnerability Type: Unsafe handling of blockchain wallet seed phrases
Risk Level: High

bash
## Configuration

Config stored at `~/.hippius/config.json`.

```bash
# View config
hippius config list

# Set HIPPIUS_KEY (API key from console.hippius.com)
hippius config set hippius hippius_key "your_hippius_key"

# Set seed phrase for blockchain operations
hippius config set substrate seed_phrase "your twelve word mnemonic"
text

### Technical Analysis

The documented command encourages users to place a blockchain wallet mnemonic directly in a command-line argument. A real mnemonic entered this way may be retained in shell history and captured by terminal recording, audit systems, process-monitoring tools, or diagnostic logs. Depending on the operating system and process visibility policy, another local user may also be able to inspect active command-line arguments.

The documentation states that the resulting configuration is stored in `~/.hippius/config.json`, but it does not require encryption or owner-only file permissions. Consequently, the seed phrase may also remain available as a reusable plaintext secret after the command exits.

A seed phrase is substantially more sensitive than an ordinary query credential because it can provide control over the associated blockchain identity and assets.

### Attack Path

1. A user follows the documentation and replaces the placeholder with a real wallet mnemonic.
2. The shell records the full command in history, or local monitoring captures the process arguments.
3. The CLI stores the mnemonic in `~/.hippius/config.json`.
4. A malicious local user, compromised process, backup reader, or log recipient obtains the command history or configuration file.
5. The attacker reconstructs the wallet using the mnemonic.
6. The attacker authenticates as the victim and performs blockch
...[truncated 503 chars]
Remediation
View remediation

Remediation Suggestions

  • Remove examples that pass seed phrases as command-line arguments.
  • Require hidden interactive entry using a no-echo secret prompt, or accept the value through a protected secret-management interface.
  • Avoid ordinary stdin pipelines when they could be logged or retained by shell tooling.
  • Store wallet secrets in an operating-system keychain, hardware wallet, or dedicated encrypted secret store instead of a plaintext JSON file.
  • If file-based storage is unavoidable, encrypt the secret and enforce owner-only permissions such as mode 0600.
  • Warn users not to place mnemonics in shell history, scripts, logs, environment variables, screenshots, or support messages.
  • Document seed revocation or wallet migration procedures for users who previously followed the unsafe example.

T08 · Insecure Dependencies

Warning
Location
references/cli_commands.md:7
Finding

Unpinned third-party package installation creates a supply-chain exposure

Content
View full analysis

Vulnerability Details

File Locations: references/cli_commands.md, lines 7-10; SKILL.md, line 21; references/storage_guide.md, line 129
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium

bash
## Installation

```bash
pip install hippius
text

The same unpinned installation instruction also appears in the other identified documentation locations.

### Technical Analysis

The instruction installs the latest package version resolved by the user's configured Python package index, together with unconstrained transitive dependencies. It provides no exact version, package hash, lock file, reviewed source revision, or package-source verification.

Python package installation can execute package build logic, and the installed CLI subsequently operates in an environment containing storage credentials, API keys, wallet configuration, and user-selected files. The audited Skill therefore cannot guarantee that code installed later will match the version or behavior considered during this review.

This is a supply-chain hardening failure rather than evidence that the current `hippius` package is malicious. The exposure arises if the package, its dependencies, the package index, or package-name resolution becomes compromised or changes unexpectedly.

### Attack Path

1. A user follows the documentation and runs `pip install hippius`.
2. The package installer resolves the current release and its transitive dependencies from the configured index.
3. A compromised publisher account, malicious package release, dependency compromise, index compromise, or unsafe alternate index supplies attacker-controlled code.
4. Attacker-controlled build or runtime code executes with the privileges of the installing user.
5. The package accesses files and secrets available to that user, potentially including Hippius credentials, wallet configuration, or files selected for upload.

### Impact Asses
...[truncated 400 chars]
Remediation
View remediation

Remediation Suggestions

  • Pin a specific reviewed package version, for example through a version-locked requirements file.
  • Provide cryptographic hashes and recommend installation with pip --require-hashes.
  • Lock and review transitive dependencies rather than constraining only the direct package.
  • Identify the authoritative package repository and expected publisher so users can verify package provenance.
  • Recommend installation in a dedicated, unprivileged virtual environment.
  • Do not recommend global or privileged installation.
  • Establish a dependency-update process that reviews new versions before changing the documented pin.
  • Where practical, publish and verify signed release artifacts or attestations.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (13)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The description partially matches the code in that it does support checking storage status and listing buckets/files on Hippius, including both S3 and blockchain-level queries. However, the declared purpose materially overstates capabilities: there is no implementation for uploading files, managing buckets in the broader sense, or setting up credentials. The script is specifically a query/reporting tool, not a general storage management utility. It also queries Hippius RPC endpoints for account files, total storage, and credits, which is narrower and more specific than the declared upload/manage framing. Therefore the description does not accurately represent what this code chunk actually does.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
88% confidence
Finding

The skill documents a raw deletion command that could be populated with user- or agent-supplied bucket/key values, enabling destructive misuse if an agent executes it without validation or confirmation. In a tool-using assistant context, parameterized destructive commands are especially risky because small substitutions can delete arbitrary objects.

Content

Scanner excerpt · references/storage_guide.md (reported line 54)May include surrounding context.

Delete file

aws --endpoint-url https://s3.hippius.com --region decentralized
s3 rm s3://my-bucket/file.txt

text

### Python (boto3)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documentation shows hippius store /path/to/file.txt --no-encrypt without warning that the data will be stored unencrypted on a decentralized system. That can expose sensitive content permanently or broadly, and the risk is elevated because the skill is specifically about storage operations users may apply to real files.

Content

No source excerpt is available for this finding.

Env Variable Harvesting

High
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.

Content

Scanner excerpt · scripts/query_storage.py (reported line 66)May include surrounding context.

python
secret_key = os.environ.get("HIPPIUS_S3_SECRET_KEY", "")
    if not access_key or not secret_key:
        return {}
    return {
        **os.environ,
        "AWS_ACCESS_KEY_ID": access_key,
        "AWS_SECRET_ACCESS_KEY": secret_key,

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents use of environment variables, shell commands, and networked S3 operations, but it does not declare any tool scope or allowed-tools restrictions. In an agent environment, that omission can let the skill be invoked with broader-than-expected capabilities, increasing the risk of unintended credential access, command execution, and remote data transfer.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation provides direct commands for upload, download, bucket creation, and sync without prominent warnings that these actions transfer data off-host, may overwrite local files, or create remote resources. In an agent-assisted setting, users may trigger destructive or exfiltrative operations without informed consent, especially with sync and download paths.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
90% confidence
Finding

The boto3 example includes direct file upload capability to a remote S3-compatible endpoint, which is a classic exfiltration primitive if an agent can substitute arbitrary local file paths or bucket destinations. In this storage-focused skill, the capability is contextually expected, but it still becomes dangerous when paired with environment credential access and automated execution.

Content

Scanner excerpt · SKILL.md (reported line 82)May include surrounding context.

md
)

# Upload
s3.upload_file('local.txt', 'my-bucket', 'remote.txt')

# Download
s3.download_file('my-bucket', 'remote.txt', 'downloaded.txt')

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation explicitly includes a --no-encrypt upload example without any warning that files may be stored without confidentiality protections. In a storage-focused skill, users are likely to copy commands verbatim, so this can lead to accidental exposure of sensitive data if they assume secure defaults or do not understand the privacy tradeoff.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The hippius delete <CID> command is presented without any warning that deletion is destructive and may be irreversible or operationally difficult to recover from. In a CLI reference intended for direct use, this increases the chance of accidental data loss, especially because users may execute commands mechanically from documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide includes a deletion command for object storage without any warning, confirmation pattern, or note about recovery limitations. In an agent skill context, examples are often copied verbatim, so this can lead users or downstream agents to perform destructive actions unintentionally against real buckets.

Content

No source excerpt is available for this finding.

Cloud Storage Exfiltration

Medium
Category
Data Exfiltration
Confidence
55% confidence
Finding

Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.

Content

Scanner excerpt · references/storage_guide.md (reported line 71)May include surrounding context.

md
)

# Upload
s3.upload_file('local_file.txt', 'my-bucket', 'remote_file.txt')

# Download
s3.download_file('my-bucket', 'remote_file.txt', 'downloaded_file.txt')

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/query_storage.py (reported line 80)May include surrounding context.

python
"--region", "decentralized",
    ] + args
    try:
        result = subprocess.run(cmd, capture_output=True, text=True, env=env)
        if result.returncode != 0:
            print_error(f"aws s3 command failed: {result.stderr.strip()}")
            return None

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The script sends JSON-RPC requests containing account identifiers to a default plain-HTTP endpoint, allowing network observers or intermediaries to read and tamper with responses. Even if the queried data is not highly secret, this weakens confidentiality and integrity and can mislead users with forged storage or credit information.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.