Back to skill

Security audit

spacechild-research-ledger

Security checks for vulnerabilities and agentic risk

Overview

This skill is a clear client for a public research ledger; it uses network access and a ledger key, but those uses are disclosed, purpose-aligned, and user-controlled.

Install only if you intend to use the SpaceChild public ledger. Keep SPACECHILD_LEDGER_KEY private, use the default ledger URL unless you deliberately trust another endpoint, dry-run and review every record before --send, and do not file private or unverified content because ledger records cannot be edited or deleted.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Taint TrackingDirect Taint Flow, Variable-Mediated Taint Flow, Credential Exfiltration Chain
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tainted flow: 'req' from os.environ.get (line 133, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
90% confidence
Finding

The script fetches attacker-controlled evidence URLs with urllib.request.urlopen after only checking that they begin with https://. This creates a server-side request forgery risk: a user or upstream agent can make the tool contact arbitrary HTTPS endpoints, including internal services or cloud metadata-like endpoints exposed behind HTTPS, and can also cause large or slow downloads because there are no host allowlists or size limits.

Content

Scanner excerpt · scripts/ledger.py (reported line 71)May include surrounding context.

python
if not url.startswith("https://"):
        raise Refused(f"evidence must be an https URL: {url}")
    req = urllib.request.Request(url, headers={"User-Agent": UA})
    with urllib.request.urlopen(req, timeout=120) as r:
        return r.read()

Tainted flow: 'req' from os.environ.get (line 133, credential/environment) → urllib.request.urlopen (network output)

Critical
Category
Data Flow
Confidence
96% confidence
Finding

The destination base URL is taken from the SPACECHILD_LEDGER_URL environment variable and the request includes the Bearer secret from SPACECHILD_LEDGER_KEY. If an attacker can influence the environment or skill configuration, they can redirect authenticated requests to an arbitrary server and capture the ledger token, making this effectively credential exfiltration via untrusted endpoint selection.

Content

Scanner excerpt · scripts/ledger.py (reported line 139)May include surrounding context.

python
"User-Agent": UA,
    })
    try:
        with urllib.request.urlopen(req, timeout=60) as r:
            return r.status, json.loads(r.read() or b"{}")
    except urllib.error.HTTPError as e:
        try:

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding

The skill instructs the agent to use environment variables and make outbound network requests, but it declares no explicit tool scope or allowed-tools restrictions. That creates an authorization gap where a host agent may grant broader-than-intended capabilities, increasing the risk of unintended secret access or external data transmission during skill execution.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

This step sends an invite code and chosen username to an external service to onboard an account. Although consistent with the skill's purpose, it causes transmission of potentially sensitive enrollment material to a third-party domain and could create or bind an identity without sufficient host-level consent or policy controls.

Content

Scanner excerpt · SKILL.md (reported line 47)May include surrounding context.

a letter or digit) and make one call:

bash
curl -s -X POST https://research.spacechild.love/api/ledger/onboard \
  -H 'content-type: application/json' \
  -d '{"invite":"sci_...","username":"your-name"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
95% confidence
Finding

This command posts authenticated data to an external ledger using a bearer secret from the environment. Because the record is append-only and public by design, any accidental transmission of sensitive, incorrect, or unreviewed content is irreversible, and use of the env-backed token introduces credential exposure risk if execution or logging is not tightly controlled.

Content

Scanner excerpt · SKILL.md (reported line 106)May include surrounding context.

The same record with curl:

bash
curl -s -X POST https://research.spacechild.love/api/ledger/records \
  -H "Authorization: Bearer $SPACECHILD_LEDGER_KEY" -H 'Content-Type: application/json' -d '{
  "campaignId": "my-campaign", "kind": "result", "standing": "measured",
  "clientRef": "my-campaign-stage1-result",

Static analysis

No suspicious patterns detected.