Back to skill

Security audit

Know Your Agent (KYA) Implementation Playbook

Security checks for vulnerabilities and agentic risk

Overview

This is a non-executing guide, but it presents flawed live-production KYA/payment-governance code as deployable, which could leave real agents with unsafe authority or ineffective revocation controls.

Treat this skill as a high-risk reference document, not deployable production code. Do not run the examples against a live GreenHelix account or copy the KYAPipeline class into production without adding fail-closed identity checks, trusted operator verification, complete delegated-scope validation, confirmed revocation and escrow controls, explicit sandbox defaults, timeouts, rollback, and secret-management guidance.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:1959
Finding

Caller-Controlled Operator Tier Bypasses Identity Verification

Content
View full analysis
= 2, "operator_entity_verified": tier >= 3 } }) results["steps"]["operator_linkage"] = { "status": "pass", "tier": tier } self._log(agent_id, "kya_operator_linked", {"tier": tier}) except Exception as e: results["steps"]["operator_linkage"] = { "status": "fail", "error": str(e) } ``` The corresponding standalone example similarly derives the verification method from the supplied tier: ```python "verification_method": [ "self_declared", "domain_verified", "entity_verified" ][tier - 1] ``` ### Technical Analysis The pipeline accepts `operator_tier` directly from onboarding metadata and translates it into authoritative verification flags. No DNS proof, KYB provider result, beneficial-ownership evidence, sanctions-screening result, or cryptographically signed verification assertion is checked before setting `operator_verified` or `operator_entity_verified`. Although `operator_data` is described as operator verification data, the production pipeline does not use it to perform verification. The tier is also not constrained to the documented range of 1 through 3. This violates the fundamental rule that security assertions must be derived from trusted verification processes rather than caller-controlled input. ### Attack Path 1. An attacker prepares onboarding metadata for an agent they control. 2. The attacker sets `operator_tier` to `3`. 3. The pipeline writes `operator_verified=True` and `operator_entity_verified=True`. 4. The operator-linkage st ...[truncated 668 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:1928
Finding

Authority Is Provisioned After Failed Agent Identity Verification

Content
View full analysis
= 2, "operator_entity_verified": tier >= 3 } }) results["steps"]["operator_linkage"] = { "status": "pass", "tier": tier } self._log(agent_id, "kya_operator_linked", {"tier": tier}) except Exception as e: results["steps"]["operator_linkage"] = { "status": "fail", "error": str(e) } # Step 4: Authority scoping try: permissions = agent_metadata.get("permissions", {}) sla = self._execute("create_sla", { "provider_id": "platf ...[truncated 2282 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:561
Finding

Delegation Validation Does Not Constrain Aggregate Spending Authority

Content
View full analysis
delegator_terms.get("max_transaction_amount", 0): return {"authorized": False, "reason": "tx_limit_exceeds_delegator"} # Create the delegated authority scope delegated_scope = create_authority_scope(delegate_id, { **requested_scope, "validity_days": min( requested_scope.get("validity_days", 30), delegator_terms.get("remaining_validity_days", 30) ) }) # Update delegate metadata with delegation chain info session.post(f"{base_url}/v1", json={ "tool": "update_agent", "input": { "agent_id": delegate_id, "metadata": { "delegated_by": delegator_id, "delegation_depth": current_depth + 1, "delegation_chain": delegator_identity.get("metadata", {}).get( "delegation_chain", [] ) + [delegator_id] } } }) ``` ### Technical Analysis The delegation check verifies allowed tools and the per-transaction limit, but it does not compare the requested daily or monthly spending limits with those of the delegator. It also does not fully compare restricted counterparties, total budgets, delegation rights, or all validity constraints. After this incomplete validation, `requested_scope` is expanded directly into `create_authority_scope`. A delegate can consequently receive authority that is not a true subset of ...[truncated 1210 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:2270
Finding

Behavioral Enforcement Records Actions Without Applying Them

Content
View full analysis
dict: high = sum( 1 for a in anomalies.get("alerts", []) if a.get("severity") == "high" ) action = "suspend" if high >= 2 else "reduce_limits" if high == 1 else "flag" if action == "suspend": self._execute("update_agent", { "agent_id": agent_id, "metadata": { "kya_status": "suspended", "suspended_at": time.time() } }) self._log(agent_id, "kya_policy_enforced", {"action": action}) return {"action": action} ``` ### Technical Analysis When one high-severity anomaly is detected, the method selects `reduce_limits` but never updates the SLA or any financial limit. It only records a log entry claiming that policy was enforced. For suspension, the code changes metadata but does not invoke a demonstrated authorization or transaction-blocking operation. Unless every downstream tool treats this metadata field as an authoritative deny condition, the agent may remain operational. This creates a discrepancy between audit records and actual enforcement state. ### Attack Path 1. An agent triggers one high-severity anomaly, such as a transaction spike. 2. `_enforce_policy` selects `reduce_limits`. 3. No limit is modified. 4. The pipeline logs `kya_policy_enforced` with the `reduce_limits` action. 5. The agent continues transacting under its original SLA limits. 6. Reviewers may incorrectly believe the risk response was successfully applied. For suspension, an agent can similarly continue operating if transaction services enforce only the SLA and do not check `kya_status`. ### Impact Assessment An anomalous or potentially compromised agent may retain its original financial and operational permissions. Th ...[truncated 256 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:1861
Finding

Default API Configuration Produces an Invalid Versioned Endpoint

Content
View full analysis
dict: """Execute a GreenHelix tool and return the response.""" resp = self.session.post(f"{self.base_url}/v1", json={ "tool": tool, "input": input_data }) resp.raise_for_status() return resp.json() ``` ### Technical Analysis The default `base_url` already ends in `/v1`, while `_execute` appends another `/v1`. With the documented defaults, requests are sent to: ```text https://api.greenhelix.net/v1/v1 ``` The request also has no connect or read timeout. A malformed endpoint can make the advertised onboarding, monitoring, compliance, and emergency-revocation controls fail. A stalled remote endpoint can block the caller indefinitely. Because the same `_execute` method is used for security-critical operations, this is not merely a functional defect; it can prevent suspension or revocation during an incident. ### Attack Path 1. An operator deploys the class using its documented default configuration. 2. The class constructs requests to the duplicated `/v1/v1` path. 3. API operations fail, return unexpected responses, or are routed incorrectly. 4. Monitoring and enforcement actions cannot complete. 5. If an agent must be urgently suspended or revoked, the pipeline may be unable to apply the control. 6. Alternatively, a slow or unreachable endpoint causes the no-timeout request to hang and blocks the security workflow. ### Impact Assessment The vulnerability affects the availability and reliability of all remote KYA opera ...[truncated 258 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide claims the kill switch immediately cancels pending transactions and freezes escrow funds, but the implementation only revokes the agent and records state. Operators relying on this code may believe emergency containment exists when in fact harmful transactions or fund movements may continue after 'revocation.'

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
94% confidence
Finding

The guide markets the class as a complete production pipeline and 'the code you deploy,' but the implementation omits important controls described elsewhere, creating a dangerous false sense of completeness. In security-sensitive compliance code, overstating coverage can lead teams to ship incomplete protections and miss required enforcement paths.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The checklist states failed identity verification prevents the agent from transacting, but the onboarding flow continues into operator linkage, authority scoping, and can still reach non-failing final states. This can enable unverified agents to receive permissions or approval metadata, undermining the entire trust model of the KYA pipeline.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document makes contradictory claims about whether examples use a sandbox or the production endpoint, which can cause operators to run supposedly safe examples against a live service. In a security/compliance onboarding guide, this confusion materially increases the risk of unintended real transactions, data disclosure, and misuse of live credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The guide says examples run against a production endpoint but does not prominently warn that executing them may send live data and trigger real actions over the network. In a deployment-oriented playbook, this omission increases the chance that readers test with real identifiers, keys, and business data unintentionally.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 169)May include surrounding context.

md
import time
import hashlib

base_url = "https://api.greenhelix.net/v1"
api_key = "your_platform_api_key"

session = requests.Session()

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 1862)May include surrounding context.

md
import time
import hashlib

base_url = "https://api.greenhelix.net/v1"
api_key = "your_platform_api_key"

session = requests.Session()

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

The skill references a signing credential without guidance on secure generation, storage, rotation, or non-disclosure. Because the guide is positioned as production-ready, readers may mishandle a sensitive signing key and compromise agent identity assurances.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.