T09 · Insecure Skill Coding Practices
- Location
SKILL.md:38- Finding
Bearer Credential and Nutrition Data Exfiltration Through an Unvalidated API Base URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its OpenCal meal-tracking purpose, but it gives agents authenticated access to read and change nutrition data with weak destination scoping and limited confirmation guidance.
Review this skill before installing if your OpenCal data is sensitive. Use it only with a trusted OPENCAL_API_KEY environment, do not set OPENCAL_BASE_URL unless you control the endpoint, and require the agent to confirm exact goal changes or deletions before running them.
SKILL.md:38Bearer Credential and Nutrition Data Exfiltration Through an Unvalidated API Base URL
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
2. Scale to the actual amount and log:
curl -s -X POST "${OPENCAL_BASE_URL:-https://api.opencal.ai}/api/v1/food/log" \
-H "Authorization: Bearer $OPENCAL_API_KEY" \
-H "Content-Type: application/json" \
-d '{
This PUT request modifies the user's calorie and macro goals on a remote service, which is a state-changing operation with health-relevant consequences if triggered incorrectly. In an agent workflow, ambiguous phrasing or prompt manipulation could cause unauthorized goal changes without the user's informed confirmation.
-H "Authorization: Bearer $OPENCAL_API_KEY" | jq
# Update (only include fields to change)
curl -s -X PUT "${OPENCAL_BASE_URL:-https://api.opencal.ai}/api/v1/goals" \
-H "Authorization: Bearer $OPENCAL_API_KEY" \
-H "Content-Type: application/json" \
-d '{"calorieGoal": 1800, "proteinGrams": 160}'
The skill includes a destructive API operation that deletes food log entries but does not prominently warn that this action is irreversible or require an explicit user confirmation step. In an agent setting, this increases the chance of accidental or unauthorized data modification if the model misinterprets a request like 'remove that' or acts on ambiguous context.
No suspicious patterns detected.