Back to skill

Security audit

Babylon

Security checks for vulnerabilities and agentic risk

Overview

This Babylon skill is a real market client, but it gives broad account and value-moving authority with weak safeguards around credentials and live actions.

Review this carefully before installing. Use only a low-privilege, revocable Babylon API key if available; do not set BABYLON_URL unless you fully trust the destination; and require explicit human confirmation before trades, point transfers, profile changes, messages, moderation actions, posts, or ban appeals.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/babylon-client.ts:20
Finding

API Key Disclosure Through an Unrestricted Custom Endpoint

Content
View full analysis

Vulnerability Details

File Location: scripts/babylon-client.ts, lines 20–48; related configuration documentation in SKILL.md, line 77
Vulnerability Type: Credential disclosure through insufficient endpoint validation
Risk Level: High

Vulnerable Code

ts
const API_KEY = loadApiKey();
const BASE_URL = process.env.BABYLON_URL || 'https://play.babylon.market';
const MCP_ENDPOINT = `${BASE_URL}/mcp`;

interface MCPResponse<T = unknown> {
  jsonrpc: '2.0';
  id: number;
  result?: {
    content: Array<{ type: 'text'; text: string }>;
    isError: boolean;
  };
  error?: {
    code: number;
    message: string;
    data?: unknown;
  };
}

/**
 * Call an MCP tool via JSON-RPC 2.0
 */
async function callTool<T>(toolName: string, args: Record<string, unknown> = {}): Promise<T> {
  const response = await fetch(MCP_ENDPOINT, {
    method: 'POST',
    headers: {
      'Content-Type': 'application/json',
      'X-Babylon-Api-Key': API_KEY,
    },

The same behavior also occurs in the account identity request at lines 86–90:

ts
const response = await fetch(`${BASE_URL}/api/auth/whoami`, {
  headers: {
    'X-Babylon-Api-Key': API_KEY,
    'Accept': 'application/json',
  },
});

Technical Analysis

The client reads the destination directly from the BABYLON_URL environment variable without validating its scheme, hostname, port, or trust relationship. It then sends the value of BABYLON_API_KEY in the X-Babylon-Api-Key header to that destination.

Network authentication is necessary for the Skill's declared Babylon functionality when requests are sent to the documented production service. However, forwarding the production credential to any environment-selected origin does not enforce the credential's intended trust boundary. The code permits both attacker-controlled HTTPS origins and plaintext HTTP destinations.

...[truncated 2000 chars]

Remediation
View remediation

Remediation Suggestions

  1. Make the production endpoint immutable unless custom-instance support is explicitly required:

    ts
    const BASE_URL = 'https://play.babylon.market';
    
  2. If custom endpoints are required, parse and validate them with the URL class:

    • Require https:.
    • Reject embedded usernames and passwords.
    • Reject fragments and unexpected paths.
    • Restrict ports where practical.
    • Normalize and compare the origin against an explicit allowlist.
  3. Permit plaintext HTTP only for explicit loopback development addresses such as 127.0.0.1 or localhost, never for remote hosts.

  4. Use separate, origin-scoped credentials for custom Babylon instances. Do not send a production Babylon key to a custom origin.

  5. Require an explicit opt-in or confirmation before sending credentials to a non-production endpoint, and display the normalized destination origin.

  6. Document the credential-disclosure implications of BABYLON_URL.

  7. Apply least-privilege scopes and expiration to API keys where supported, and provide a straightforward revocation and rotation process.

T08 · Insecure Dependencies

Warning
Location
SKILL.md:10
Finding

Unpinned Executable TypeScript Runtime Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 10–14 and command examples at lines 26–63
Vulnerability Type: Unpinned executable dependency and implicit package resolution
Risk Level: Medium

Vulnerable Configuration and Commands

yaml
install:
  - id: ts-node
    kind: node
    package: ts-node
    label: Install ts-node for TypeScript execution

The documented execution pattern repeatedly uses an unversioned package command:

bash
npx ts-node skills/babylon/scripts/babylon-client.ts balance
npx ts-node skills/babylon/scripts/babylon-client.ts positions
npx ts-node skills/babylon/scripts/babylon-client.ts markets
npx ts-node skills/babylon/scripts/babylon-client.ts market <marketId>
npx ts-node skills/babylon/scripts/babylon-client.ts buy <marketId> YES 10
npx ts-node skills/babylon/scripts/babylon-client.ts buy <marketId> NO 5
npx ts-node skills/babylon/scripts/babylon-client.ts sell <positionId> <shares>
npx ts-node skills/babylon/scripts/babylon-client.ts close <positionId>
npx ts-node skills/babylon/scripts/babylon-client.ts feed
npx ts-node skills/babylon/scripts/babylon-client.ts post "My market analysis..."
npx ts-node skills/babylon/scripts/babylon-client.ts leaderboard

Technical Analysis

The Skill declares ts-node without an exact version or integrity constraint. No lockfile or package manifest is present in the audited project. The documented npx ts-node command can resolve and, depending on the local environment and npm configuration, download executable package code when no suitable local installation exists.

This means the code executed before or alongside the audited client is not fully defined by the reviewed Skill package. Dependency behavior may change over time, and package-registry compromise, dependency-account compromise, malicious registry configuration, or unsafe package resolution could introduce ...[truncated 1489 chars]

Remediation
View remediation

Remediation Suggestions

  1. Add a package manifest and pin ts-node to an audited exact version rather than a floating range.

  2. Commit a package lockfile containing integrity hashes and install dependencies using immutable resolution, such as:

    bash
    npm ci
    
  3. Invoke the project-local binary after the locked installation instead of allowing npx to download missing packages implicitly:

    bash
    ./node_modules/.bin/ts-node scripts/babylon-client.ts balance
    
  4. If npx remains necessary, disable implicit installation and require a preinstalled local dependency.

  5. Use a trusted registry configured through controlled deployment settings. Monitor and audit dependency updates before adoption.

  6. Run the Skill with a minimal environment containing only the required API key and with restricted filesystem and network permissions.

  7. Consider compiling the TypeScript client during a controlled build process and distributing reviewed JavaScript output, eliminating the need for a runtime TypeScript compiler.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (31)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The manifest frames the skill as a prediction-market trading helper, but the documented capabilities include leveraged perpetuals, messaging, moderation, account management, payments, referrals, and ban appeals. This mismatch undermines informed consent and increases the chance an agent or user authorizes far broader actions than expected, including financial and account-impacting operations.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Point transfers and payment-related operations exceed the declared market-analysis purpose and introduce direct asset-movement functionality. In context, this is more dangerous because the skill already has authenticated API access, so misuse could cause irreversible transfer of value or financial loss.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

transferPoints enables value transfer between users while the manifest does not disclose that the skill can move account value. Hidden transfer capabilities are especially dangerous in agent-integrated tools because a user may authorize trading-related actions without understanding that the tool can also send assets to other accounts.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The CLI executes trading operations like buy, sell, bet, and close immediately from command-line arguments with no confirmation, preview, or risk warning. Because these actions can spend balance or alter positions, accidental invocation, prompt injection, or malformed automation could directly cause financial loss or unwanted trades.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding

The skill declares access to environment variables and networked execution but does not define any explicit tool scope such as permissions or allowed-tools. In an agent setting, this weakens least-privilege boundaries and makes it easier for the skill to invoke capabilities broader than users would infer from the manifest.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

Using npx ts-node without pinning an exact version introduces supply-chain risk because execution may pull whatever package version is currently resolved in the environment. A compromised or breaking upstream package could change behavior at runtime or execute attacker-controlled code during install or launch.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation presents buy, sell, close, and similar commands as straightforward examples without clearly warning that they may execute live, potentially irreversible financial actions. In an agent workflow, this can lead to users or downstream systems invoking real trades or transfers without adequate awareness or confirmation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documented operational scope expands from market trading into messaging, moderation, profile control, referrals, payments, and appeals. In an agent ecosystem, this breadth materially raises abuse potential because the same credentials and network access can now affect many parts of the user's account beyond the expected market workflow.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

Profile editing and social graph operations go beyond the manifest's stated functionality and permit persistent identity or relationship changes on the user's account. In context, that makes accidental or prompt-induced misuse more harmful than simple read-only market access.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Chat and messaging features are not necessary for basic prediction-market trading or feed viewing, yet they enable outbound communications on the user's behalf. That creates additional risks of spam, impersonation, social engineering, or privacy exposure if the skill is triggered too broadly.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Moderation and account-control actions such as block, mute, and report are outside the core prediction-market use case. These actions can alter the user's social experience and account state without clear justification, increasing the chance of unintended or manipulated account changes.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Ban appeal functions are unrelated to ordinary market interaction and create sensitive account-recovery or dispute workflows under the same skill umbrella. This broadening of authority increases the chance of unauthorized or unintended submission of consequential account requests.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 208)May include surrounding context.

Raw API Call Example

bash
curl -X POST "https://play.babylon.market/mcp" \
  -H "Content-Type: application/json" \
  -H "X-Babylon-Api-Key: $BABYLON_API_KEY" \
  -d '{

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The API reference materially expands the skill’s effective capability surface far beyond the manifest’s stated prediction-market use case, including messaging, social graph actions, moderation, transfers, referrals, and admin escrow operations. In an agent setting, this mismatch can cause over-privileged integrations, unsafe tool exposure, and user-deceptive behavior where an assistant appears limited but can perform unrelated high-impact actions on a user account.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The documentation enumerates numerous state-changing actions—bets, buys/sells, transfers, posts, follows, messages, moderation, and payment-related operations—without warning about irreversible or account-affecting consequences. In an AI assistant context, lack of explicit cautions and confirmation requirements raises the risk of unintended financial loss, unwanted communications, account changes, or abuse of destructive actions.

Content

No source excerpt is available for this finding.