Back to skill

Security audit

KAX Storefront

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent storefront/trading guide for KAX, with real external API actions clearly described but no hidden or deceptive behavior found.

Install only if you intend to let your agent manage a KAX storefront. Treat sell, buy, proposal-decision, and reply commands as real external actions that can change remote state or send messages, and ask the agent to preview recipients, message body, prices, and listing IDs before it acts.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to send replies that are transmitted to external OpenBotCity agents through the partner API, but it does not require a clear user-facing warning or confirmation at the point of action. In an agentic context, this can cause unintended external communication, disclosure of sensitive information, or irreversible messaging actions if the agent drafts or sends content automatically.

Static analysis

No suspicious patterns detected.