other
- Location
SKILL.md:34- Finding
Unsubstantiated Farcaster Identity Verification Claim
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 34
Vulnerability Type: Unverified identity assertion
Risk Level: Mediummd - **FID Sync**: Always mention that the interaction is verified via the user's Farcaster identity.Technical Analysis
The skill unconditionally instructs the agent to state that an interaction has been verified through the user's Farcaster identity. However, it defines no verification procedure, trusted API endpoint, validation criteria, or failure handling.
The package contains only
SKILL.md; therefore, the referenced Farcaster tool implementation and any identity-validation logic are unavailable for review. The instruction can consequently cause the agent to make an authentication claim regardless of whether verification actually occurred.Attack Path
- An unverified or impersonating user requests a Farcaster interaction.
- The skill handles the request without performing a documented FID ownership or session verification check.
- The agent follows the unconditional instruction and states that the interaction was verified through the user's Farcaster identity.
- Other users or downstream systems rely on that unsupported assertion as an authentication signal.
Impact Assessment
An attacker does not gain direct system privileges from this issue. However, the false trust signal could facilitate identity misrepresentation, social engineering, unauthorized attribution of casts, or misleading statements about account ownership. The scope includes users and downstream consumers that rely on the agent's verification language.
- Remediation
View remediation
Remediation Suggestions
- Replace the unconditional assertion with a conditional rule that permits verification language only after a trusted identity check succeeds.
- Define the authoritative verification endpoint, required inputs, expected response fields, and validation criteria.
- Verify that the authenticated session or signed proof controls the claimed FID.
- Specify secure failure behavior: if verification is unavailable, fails, or returns ambiguous results, explicitly describe the identity as unverified.
- Record sufficient non-sensitive evidence of successful verification for auditing without exposing tokens, signatures, or personal data.
- Include the referenced Farcaster integration and identity-verification implementation in the reviewable package so its authentication and error-handling behavior can be audited.
