Back to skill

Security audit

BrickEconomy

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent and read-only, but it can send your BrickEconomy API key to an arbitrary API host if the base URL is overridden.

Install only if you are comfortable giving the skill read-only access to your BrickEconomy account data, including collection values and sales ledger details. Avoid setting BRICKECONOMY_BASE_URL or using --base-url unless you fully trust the destination; the current CLI can send your API key to that host. Consider rotating the API key if you may have used an untrusted base URL.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/brickeconomy_cli.py:59
Finding

Unrestricted API Base URL Override Can Expose the API Key

Content
View full analysis

Vulnerability Details

File Location: scripts/brickeconomy_cli.py:59-65, 102, 145-146
Vulnerability Type: Arbitrary-origin credential disclosure
Risk Level: High

The CLI permits its API base URL to be supplied through either the --base-url argument or the BRICKECONOMY_BASE_URL environment variable. It then sends the BRICKECONOMY_API_KEY value in the x-apikey header to the selected URL without validating its scheme or origin.

Complete relevant code:

python
def get(self, path: str, params: dict[str, Any] | None = None) -> Any:
    query = urllib.parse.urlencode(clean_params(params or {}), doseq=True)
    url = f"{self.base_url}{path}"
    if query:
        url = f"{url}?{query}"
    headers = {"Accept": "application/json", "x-apikey": self.api_key}
    return self._request("GET", url, headers)
python
def add_common(parser: argparse.ArgumentParser) -> None:
    parser.add_argument("--base-url", default=os.getenv("BRICKECONOMY_BASE_URL", DEFAULT_BASE_URL), help="BrickEconomy API base URL")
    parser.add_argument("--timeout", type=int, default=READ_TIMEOUT_SECONDS, help="HTTP timeout in seconds")
    parser.add_argument("--dry-run", action="store_true", help="Print request shape without calling BrickEconomy")
python
def client_from_args(args: argparse.Namespace) -> BrickEconomyClient:
    return BrickEconomyClient(require_api_key(), args.base_url, args.timeout)

Technical Analysis

Header-based API authentication is necessary for the Skill's declared BrickEconomy functionality. However, sending that credential to an arbitrary user- or environment-controlled origin exceeds the minimum privileges required. The checked-in OpenAPI specification identifies the intended server as https://www.brickeconomy.com/api/v1, while the implementation accepts any URL without enforcing HTTPS or validating the hostname.

Consequently, a malicious command, compromised wrapper, ...[truncated 2032 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove the runtime base-URL override if alternate API deployments are not a functional requirement.
  2. If an override is required, parse it with urllib.parse.urlsplit() and enforce:
    • The https scheme only.
    • An explicit allowlist containing www.brickeconomy.com.
    • The expected /api/v1 path prefix.
    • No embedded username or password.
    • No fragments or malformed host components.
    • An approved port, normally 443.
  3. Reject IP literals, localhost, private-network addresses, link-local addresses, and non-HTTP schemes.
  4. Disable redirects for authenticated requests or implement redirect handling that strips x-apikey unless the destination has the exact same validated origin.
  5. Validate the destination immediately before constructing the authenticated request rather than relying only on argument parsing.
  6. Add tests proving that HTTP URLs, unapproved domains, embedded credentials, malformed URLs, and cross-origin redirects are rejected.
  7. Preserve --dry-run behavior without loading or displaying the actual API key.
  8. If exposure may already have occurred, revoke and rotate the BrickEconomy API key and review account/API activity.
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill uses both environment-based secrets and network access, but the manifest does not declare any tool scope restrictions such as allowed tools or permissions. That creates unnecessary ambient authority: a caller or runtime may permit broader execution than intended, increasing the risk of unauthorized outbound requests or unintended access to the BRICKECONOMY_API_KEY and private collection data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The OpenAPI spec exposes authenticated endpoints that return a user's full LEGO collection, including detailed item-level inventory, acquisition dates, paid prices, and historical value snapshots. That exceeds the skill's described purpose of reference-based valuation/analysis and creates unnecessary access to private user data, increasing the chance of over-collection and privacy misuse if the skill or downstream agent invokes these endpoints without clear consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The spec includes endpoints for private collection and sales-related data but provides no visible warning in the API descriptions that these operations access personal account data. In an agent-skill context, this makes accidental or opaque access more likely because users may assume the skill only uses public Brick Directory reference data described in the manifest.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The sales ledger endpoint returns raw transaction history, including sale prices, fees, notes, quantities, dates, and original purchase details. This is sensitive financial and behavioral data, and exposing it directly is riskier than the manifest's stated 'sales-ledger analysis' because an agent can access complete personal records rather than only derived insights.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/prompts/brickeconomy-tools.txt (reported line 92)May include surrounding context.

text
- Be efficient: Don't call APIs unnecessarily
- If user asks about multiple sets, consider batching questions
- Collection tools return ALL items in a single API call - use them instead of pagination
- Don't ask users to paginate through collection results - return everything sorted appropriately

Collection Sorting Best Practices:
- Default to 'growth' sort when user asks about "best performers" or "investments"

Static analysis

No suspicious patterns detected.