Back to skill

Security audit

Hopkin – Paid Ads: Meta, TikTok, Google, LinkedIn, Reddit

Security checks for vulnerabilities and agentic risk

Overview

The skill is coherent and read-only, but it asks agents to install a mutable global CLI and handle API keys in a way that can expose sensitive advertising credentials.

Review before installing. Use a narrowly scoped Hopkin API key, avoid pasting secrets into normal chat or shell commands, rotate any key that may have been logged, and prefer a pinned or locally reviewed CLI install over automatic global latest updates.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:29
Finding

Unpinned Global npm Package Installation Creates a Supply-Chain Risk

Content
View full analysis
7 days ago) npm outdated -g @hopkin/cli && npm install -g @hopkin/cli@latest ``` The update instructions repeat the unsafe installation of the mutable latest release: ```bash npm install -g @hopkin/cli@latest ``` ### Technical Analysis The Skill instructs the Agent to install a third-party npm package globally without pinning it to an audited version. It also directs the Agent to periodically install the package's mutable `latest` release. No lockfile, exact version, integrity hash, package signature, provenance validation, or preinstallation review is required. Consequently, the package installed when the Skill runs may differ from the package that existed when the Skill was audited. npm packages can also define lifecycle scripts that execute during installation. Global installation expands the effect beyond the project directory by modifying the user's global npm environment. The instructions do not request elevated privileges, so execution with administrative privileges is not assumed; nevertheless, package code and lifecycle scripts can run with the privileges of the user executing npm. ### Attack Path 1. An attacker compromises the `@hopkin/cli` package, its publisher account, an upstream dependency, or a future release distributed through the configured npm registry. 2. The compromised release is published under the version selected by an unpinned install or assigned the `latest` distribution tag. 3. Following the Skill instructions, the Agent runs `npm install -g @hopkin/cli` or `npm install -g @hopkin/cli@latest`. 4. npm retrieves the mutable package release and its dependency graph. 5. Malicious package code or npm ...[truncated 873 chars]
Remediation
View remediation
``` 7. Execute the CLI in a restricted environment with access only to the credentials and files required for the requested advertising query. ]]>

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:42
Finding

API Key Is Supplied Through a Command-Line Argument

Content
View full analysis
``` ``` The troubleshooting instructions repeat the same credential-handling pattern: ```bash # Re-authenticate hopkin auth set-key ``` ### Technical Analysis The Skill directs the Agent to interpolate a sensitive API key directly into a command-line argument. Command-line secrets can be exposed through several channels, depending on the operating environment: - Shell command history. - Agent transcripts or tool-call records. - Terminal and debugging logs. - Process listings or process-monitoring software while the command is running. - Audit or telemetry systems that record process arguments. Although the key is intentionally provided to the Hopkin CLI for authentication, passing it through the command line unnecessarily broadens its exposure. The document also does not instruct the Agent to redact the key, disable command echoing, avoid persistent history, or verify secure storage after authentication. ### Attack Path 1. A user provides a valid Hopkin API key after the Agent requests authentication. 2. The Agent substitutes the key into `hopkin auth set-key `. 3. The full command, including the key, is captured by shell history, an Agent transcript, terminal logging, process telemetry, or process inspection. 4. A local user, administrator, monitoring-system operator, or party with access to retained logs obtains the exposed key. 5. The party uses the key against Hopkin services. 6. The party gains whatever advertising-data access and account scope the compromised key authorizes. This path depends on the relevant environment retaining or exposing command arguments, but the documented credential-handling method creates that avoidable opportu ...[truncated 680 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill instructs the operator to request and set an API key but does not warn that the key is a secret that must not be exposed in chat logs, shell history, screenshots, or persisted outputs. In an agent context, this omission can lead to credential disclosure through conversational collection, command echoing, or unsafe storage, which could grant unauthorized access to advertising data across connected platforms.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.