Back to skill

Security audit

Nyne Search

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says, but it needs review because it broadly exposes personal contact/profile data and handles enriched results unsafely.

Review before installing. Use this only for authorized people-search workflows, avoid enabling or displaying emails and phone numbers unless clearly needed, do not rely on gender or estimated age for sensitive decisions, and prefer redacted/minimal summaries. If used, replace the fixed /tmp output with a private mktemp file, delete results after use, and verify credentials without printing any part of the secret.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (3)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:83
Finding

Predictable Temporary File Exposes Sensitive Search Results

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 83-89, 102-106, 559-572
Vulnerability Type: Predictable temporary file with insecure handling of sensitive personal data
Risk Level: Medium

Vulnerable Code

bash
# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \
  -d '{"query": "Software engineers at Google in San Francisco", "limit": 10, "type": "premium", "show_emails": true}' | nyne_parse > /tmp/nyne_search.json

The same predictable file is overwritten during polling:

bash
curl -s "https://api.nyne.ai/person/search?request_id=$REQUEST_ID" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" | nyne_parse > /tmp/nyne_search.json

The documented commands subsequently extract sensitive data from that file:

bash
# All emails
jq '.data.results[] | {displayname, best_business_email, best_personal_email, altemails}' /tmp/nyne_search.json

# Phone numbers
jq '.data.results[] | {displayname, fullphone}' /tmp/nyne_search.json

Technical Analysis

The skill repeatedly stores complete API responses in the fixed path /tmp/nyne_search.json. These responses can contain business and personal email addresses, alternate email addresses, phone numbers, biographies, locations, employment histories, and other profile information.

The instructions do not:

  • Create the file atomically with a unique name.
  • Set a restrictive process umask or explicit file permissions.
  • Verify that the destination is a regular file owned by the current user.
  • Defend against pre-existing symbolic links.
  • Delete the file when processing finishes.

A shell redirection to a predictable path follows a pre-existing symbolic link. On a shared host, another local user may therefore be able to anticipate the path and cr ...[truncated 1842 chars]

Remediation
View remediation

Remediation Suggestions

  • Create a unique temporary file with mktemp rather than using a fixed filename.
  • Set umask 077 before creating files that may contain personal information.
  • Store the generated filename in a quoted variable and use it consistently.
  • Register a cleanup trap so the file is removed on normal completion, interruption, or failure.
  • Avoid writing the complete response to disk when in-memory processing or a protected pipe is sufficient.
  • If persistent storage is required, use an application-specific private directory with restrictive permissions and a documented retention period.

Example hardened pattern:

bash
umask 077
NYNE_RESULT_FILE=$(mktemp "${TMPDIR:-/tmp}/nyne_search.XXXXXX") || exit 1
trap 'rm -f "$NYNE_RESULT_FILE"' EXIT HUP INT TERM

curl -sS --fail-with-body -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \
  -d "$REQUEST_BODY" |
  nyne_parse > "$NYNE_RESULT_FILE"

The implementation should additionally validate API failures before treating the stored response as successful output.

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:15
Finding

Instructions Require Excessive Disclosure of Returned Personal Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 15-31
Vulnerability Type: Insecure handling and over-disclosure of sensitive personal information
Risk Level: Medium

Vulnerable Instructions

text
When presenting search results to the user, show **all returned data** for each person. Walk through:

1. **Result count** — total_stored, total_estimate, has_more, credits_charged
2. **Each person** — displayname, headline, bio, location, gender, estimated_age, total_experience_years, is_decision_maker
3. **Contact info** — best_business_email, best_personal_email, altemails, fullphone (if show_emails/show_phone_numbers were enabled)
4. **Social profiles** — LinkedIn URL, username, connections, followers
5. **Work history** — all organizations with title, dates, company details (industries, num_employees, funding, technologies)
6. **Education** — schools with degree, major, dates; note is_top_universities flag
7. **Interests** — work interests and certifications
8. **Patents** — title, date, reference, URL (if present)
9. **Languages** — spoken languages
10. **Score** — AI relevance score 0-1 (if profile_scoring was enabled)
11. **Insights** — AI-generated match reasoning (if insights were enabled)

Technical Analysis

The skill explicitly instructs the agent to reproduce all returned profile data. The required output includes direct contact information and potentially sensitive or privacy-relevant attributes such as personal email addresses, phone numbers, gender, estimated age, location, education, and detailed employment history.

No data-minimization policy, redaction rule, authorization check, purpose limitation, bulk-output threshold, or explicit confirmation requirement is provided. Consequently, information requested for one legitimate purpose may be unnecessarily copied into conversation transcripts, logs, monitoring systems, or downstream integrations.

This behavior is related t ...[truncated 1471 chars]

Remediation
View remediation

Remediation Suggestions

  • Replace “show all returned data” with a data-minimization policy.
  • Display only professional summary fields by default, such as name, headline, employer, and broad location.
  • Require explicit user confirmation before retrieving or displaying personal email addresses or phone numbers.
  • Mask contact data by default, for example j***@example.com and +1 ******1234.
  • Distinguish business contact details from personal contact details and apply stricter controls to personal data.
  • Limit the number of profiles containing contact information that can be displayed in one response.
  • Ask the user to confirm an authorized and legitimate purpose before bulk enrichment or export.
  • Warn users that output may be retained in conversation logs and should be handled according to applicable privacy and data-protection requirements.
  • Avoid repeating sensitive values in summaries when they have already been provided through a protected interface.
  • Add configurable retention, audit logging, and access-control requirements for systems that store agent responses.

T09 · Insecure Skill Coding Practices

Note
Location
SKILL.md:48
Finding

Credential Verification Command Discloses API Key and Secret Prefixes

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 48-51
Vulnerability Type: Partial credential disclosure through terminal and log output
Risk Level: Low

Vulnerable Code

bash
Verify they're set:
```bash
echo "Key: ${NYNE_API_KEY:0:8}... Secret: ${NYNE_API_SECRET:0:6}..."
text

### Technical Analysis

The recommended verification command prints the first eight characters of the API key and the first six characters of the API secret. Although it does not reveal the complete credentials, secret material should not be emitted merely to determine whether environment variables are configured.

Terminal output may be captured by CI/CD systems, shell-session recording, agent transcripts, support tooling, screen sharing, or centralized logging. Partial values can help identify and correlate credentials across systems, distinguish credential versions, or reduce uncertainty during targeted attacks. The command provides no meaningful security advantage over checking whether the variables are non-empty.

### Attack Path

1. An operator follows the setup documentation and runs the verification command.
2. The shell prints API key and secret prefixes to standard output.
3. A terminal recorder, CI job, agent transcript, centralized logger, or nearby observer captures the output.
4. A party with access to that output obtains partial credential material.
5. The prefixes may be used to correlate credentials with other leaks, identify which credential is deployed, or support targeted guessing and social-engineering attempts.

### Impact Assessment

This issue does not directly disclose a complete API key or secret and does not by itself provide authenticated access. The immediate impact is limited exposure of credential fragments.

Risk increases when the fragments can be combined with information from other leaks or when prefixes are used operationally to identify credential ownership or deployment. No add
...[truncated 81 chars]
Remediation
View remediation

Remediation Suggestions

  • Never print any part of an API secret.
  • Verify only that required variables are non-empty.
  • Send status messages that contain no credential-derived values.
  • Configure CI/CD systems and agent runtimes to mask the complete environment-variable values as an additional defense.
  • Rotate credentials if their fragments have already appeared in broadly accessible logs and organizational policy treats partial disclosure as a rotation event.

Example safe verification:

bash
if [ -n "$NYNE_API_KEY" ] && [ -n "$NYNE_API_SECRET" ]; then
  echo "Nyne credentials are configured."
else
  echo "Nyne credentials are not configured." >&2
  exit 1
fi
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (29)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

These instructions require disclosure of emails, phone numbers, gender, and estimated age without any warning, gating, or privacy review. This meaningfully increases the risk of doxxing, profiling, discrimination, and misuse of scraped or enriched contact data because the agent is told to disclose everything by default.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The agent is instructed to disclose all personal and contact data returned by the service, including detailed work history, education, contact enrichment, and profiling-related fields. In this context, the issue is especially dangerous because the tool is specifically built to aggregate person-level intelligence, so unrestricted disclosure materially amplifies privacy abuse and targeting risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill promotes email and phone enrichment features and provides examples that retrieve direct contact information, but gives no privacy, consent, or acceptable-use guidance. In context, this makes misuse easier by normalizing bulk retrieval of personal contact data for third parties without safeguards.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill explicitly instructs the agent to present all returned data for each person, including enriched contact details and sensitive inferred attributes like gender and estimated age. That goes beyond a narrow 'search for people' purpose and creates a clear privacy and data-minimization failure, especially because the API can return highly identifying and potentially regulated personal data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 358)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 373)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 85)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 200)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 211)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 220)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 240)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 249)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 258)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 267)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 299)May include surrounding context.

md
}

# Submit search request
curl -s -X POST "https://api.nyne.ai/person/search" \
  -H "Content-Type: application/json" \
  -H "X-API-Key: $NYNE_API_KEY" \
  -H "X-API-Secret: $NYNE_API_SECRET" \

Static analysis

No suspicious patterns detected.